AI Is Handing Anyone the Keys to Cyber Warfare. Companies Are Already Feeling It.
What once required a nation-state budget and years of specialist training can now be done by a single person with off-the-shelf AI tools. The evidence is no longer theoretical.

Key points
- In August 2024, researchers disclosed what they described as the first largely autonomous AI-enabled cyberattack, targeting Taiwan's government systems and compromising at least 85 accounts.
- Attackers stole more than 2,500 personnel records before expanding into Taiwan's nuclear safety agency and energy companies.
- In 2025, a likely China-linked espionage operation used an AI coding tool called Claude Code against roughly 30 organisations across the technology, financial, chemical and government sectors.
- AI is reducing both the cost and the skill required to run sophisticated cyberattacks, a shift security professionals compare to the invention of the firearm.
- Private companies are already being hit by capabilities that previously existed only in nation-state arsenals.
For most of recorded history, attacking a well-defended target required enormous resources. You needed money, trained people, and specialised tools. That barrier is collapsing, and it is collapsing fast.
Security researchers and commentators writing for CSO Online frame this as the "democratisation of warfare," borrowing a term from military history. The crossbow reduced the physical strength needed to kill at range. The firearm reduced it further. Each step brought lethal capability within reach of people who previously had none. AI is doing the same thing to cyberattacks.
What happened in Taiwan?
In August 2024, researchers disclosed what they called the first largely autonomous AI-powered cyberattack against government infrastructure. The attackers used publicly available AI tools and open-source "agent frameworks," meaning software that lets multiple AI programs work together without constant human direction, to build what functioned as an automated hacking team.
Up to eight AI agents ran at the same time. Each one mapped government systems, looked for weaknesses, and changed its approach when something failed. Before the operation expanded into Taiwan's nuclear safety agency and energy companies, at least 85 government accounts were broken into and more than 2,500 personnel records were taken.
This was not AI writing a convincing fake email. It was AI carrying out significant parts of the attack by itself.
Why does this matter for ordinary businesses?
Cyber capabilities have always filtered down from governments to criminals. Techniques spread, tools get cheaper, and skills that once required years of training become accessible. AI accelerates that process dramatically.
The evidence is already here. In 2025, an espionage group with likely links to China used a tool called Claude Code, an AI assistant built for writing and running software, against roughly 30 organisations. Victims included companies in technology, finance, chemicals and government contracting. According to the MITRE ATT&CK framework, a widely used catalogue of attacker techniques maintained by a US nonprofit research body, Claude Code agents handled reconnaissance (mapping the target), finding weaknesses, breaking in, moving through internal systems, harvesting passwords, and pulling out data, all with minimal human involvement.
One person, with the right AI tools, can now do the work that previously required a team.
| Event | Date | Scale |
|---|---|---|
| Taiwan government AI-autonomous attack | August 2024 | 85+ accounts, 2,500+ records stolen |
| Claude Code used against private sector | 2025 | ~30 organisations across four sectors |
| Kane Gamble (15-year-old) breached CIA Director's accounts | 2015 | Senior US intelligence officials targeted |
What should organisations watch for right now?
The immediate concern is speed and volume. Human attackers have a ceiling: one analyst can only investigate so many targets in a day. AI agents do not share that ceiling. A single operator can run multiple attacks in parallel, testing different methods simultaneously and adjusting when one fails.
For people whose data sits with employers, hospitals, energy providers or financial companies, the practical upshot is that even mid-sized organisations are now realistic targets for sophisticated, largely automated intrusions. If you receive a message asking you to confirm login details, reset a password, or click a link, treat it as suspicious regardless of how professional it looks.
Common questions
Does this mean my employer's systems are definitely at risk?
Not inevitably, but the pool of organisations that can be targeted is growing because the cost and skill required to attack them is falling. Size no longer offers much protection.
Can defenders use the same AI tools to protect systems?
Yes, and many security teams already do. The concern is that offence is moving faster than defence right now, partly because attackers have no compliance rules slowing them down.



