When Attacks Take Minutes, Not Days: The AI Speed Problem Defenders Now Face
Criminals using AI models can now write phishing bait, pick targets and hop between machines faster than most security teams can read the first alert.

Key points
- Attackers using AI tools like the Mythos model can now complete intrusions in minutes that once took days, according to reporting from The Hacker News.
- The speed gap comes from AI writing tailored phishing messages, choosing targets and testing what works, without waiting on a human.
- Most company security playbooks were written for attackers who worked at human pace, leaving a widening response gap.
- Defenders are turning to automated detection and faster automated responses to close that gap.
Criminals are moving faster. Work that used to take an attacker several days, picking a target, writing a convincing fake email, testing which trick lands, then jumping to the next machine inside the network, can now be done in minutes. The change is being driven by AI models built or repurposed for offensive work, including one known in criminal circles as Mythos.
We reported on 3 July that a machine carried out a multi-step ransomware intrusion without a human guiding every move; Mythos-style tools are the next iteration of the same pressure.
Think of it this way. A burglar who once had to case the neighbourhood and try each door one by one now has a machine that does all of that simultaneously, and moves to the next house before the alarm has finished ringing.
Why can't security teams keep up?
The playbooks they use were built for attackers who worked at human speed. Most incident response runbooks, the step-by-step guides that tell a security team what to do when something looks wrong, assume there's time to investigate and decide. AI-driven attacks collapse that timeline.
Phishing emails used to be written by hand. A criminal would draft one lure, send it to a batch of victims, and hope. AI writes hundreds of variations, each tuned to the recipient's role and recent activity, and learns which version gets clicked. Target selection speeds up too: instead of a human sifting through a stolen contact list, an AI ranks victims by likely payoff and moves on within seconds if one doesn't bite.
Once inside a network, the same automation applies. The attacker's software finds shared drives, hunts for stored passwords and hops to the next machine. By the time a human analyst opens the first alert, the intruder may already be three systems deep.
What does this mean for ordinary staff?
The frontline hasn't changed. Phishing is still how most attacks start. But the emails are harder to spot because AI removes the tells: the odd phrasing, the wrong logo, the generic greeting.
Slow down on any message that pushes urgency, whether it claims to be from the boss or from IT. If a link asks for a password, don't enter it. Go to the site directly through a browser instead.
What can companies actually do?
Human speed alone won't catch machine-speed attacks. Defenders are turning to their own automation: tools that watch for unusual logins, isolate a suspicious machine without waiting for human approval, and flag patterns across a network in seconds rather than hours.
That doesn't remove the human. It shifts the job from spotting each attack to designing the rules the machine follows and reviewing what it caught. As our earlier reporting on post-detection bottlenecks found, monitoring catches the spike fast enough; it's everything that happens after the alert that bleeds the clock.
The gap between attacker speed and defender speed is the defining story of this year in cybersecurity. Organisations that treat it as a purely technical problem will lose ground. Organisations that treat it as a question of process and tooling together stand a better chance. The honest watch item: whether defenders can automate response fast enough to matter, or whether the speed asymmetry keeps widening.



