Skip to content
DopeSwagYolo

AI & Cybersecurity

How Hackers Use AI, and How to Protect Your Accounts

Documented cases show attackers using AI to speed up phishing and the hunt for software flaws. US agency CISA rates phishing-resistant sign-ins such as passkeys as the most secure form of MFA.

By DopeSwagYolo4 min read

Researched and fact-checked by AI, with no human review. 12 sources listed below. How we verify

Publicly documented cases show attackers using AI to speed up familiar work. That means writing convincing phishing messages, hunting for software flaws and automating parts of a break-in. The US Cybersecurity and Infrastructure Security Agency (CISA) points to sign-in methods that resist phishing, the category that includes passkeys. It describes them as the most secure form of multi-factor authentication.

How are hackers using AI?

One documented effect is on phishing, the practice of tricking people into handing over passwords or clicking malicious links. Microsoft said in July 2026 that its threat intelligence team had seen AI-assisted phishing campaigns in which as many as 54% of recipients clicked. It put the rate for more conventional campaigns at roughly 12%.

AI is also speeding up technical work. A zero-day exploit is an attack on a flaw the software's maker does not yet know about. In May 2026, Google's Threat Intelligence Group reported a threat actor using one that Google believes was developed with AI. It was the first such case the group had identified. Google said the criminals planned to use it in a mass exploitation campaign. It said its discovery may have prevented that.

Some intrusions are now partly automated. Anthropic said in November 2025 that a group had manipulated its Claude Code tool into attempting to infiltrate roughly 30 targets worldwide. The company assessed with high confidence that the group was Chinese state-sponsored. It said the attempts succeeded in a small number of cases. It also said AI carried out 80% to 90% of the campaign. The company added that the model sometimes invented credentials or overstated what it had found.

Security vendors describe the same trend. Their figures rest on their own data and have not been independently verified. CrowdStrike's 2026 Global Threat Report was published in February 2026. It said operations by AI-enabled adversaries rose 89% year over year. It also said attackers injected malicious prompts into generative AI tools at more than 90 organizations.

Can AI hack my accounts?

AI can help a criminal get in, but most attacks on accounts target passwords. More than 97% of identity attacks are password attacks, Microsoft said in summarizing its 2025 Digital Defense Report. That report covered July 2024 through June 2025. Phishing and spoofing was the most common complaint type at the FBI's Internet Crime Complaint Center in 2025. It accounted for 191,561 reports among 1,008,597 complaints.

Verizon's 2026 Data Breach Investigations Report was released in May 2026. It found that 31% of breaches began with the exploitation of a software vulnerability. The report said that overtook stolen credentials for the first time in its 19 years. Verizon also said social engineering by text message and voice call succeeds 40% more often than traditional email phishing.

Can AI hack 2FA?

Two-factor authentication (2FA) is also called multi-factor authentication (MFA). It requires something besides a password, such as a one-time code or a fingerprint. Some forms can be bypassed, with or without AI.

A fact sheet that CISA published in October 2022 describes the main routes. A fake login page can collect a password and a six-digit code together. Attackers can flood a user with approval prompts until one is accepted, a tactic called push bombing. In a SIM swap, a criminal persuades a mobile carrier to move the victim's phone number to a SIM card the criminal controls.

AI can also help attackers find technical gaps. The exploit Google described in May 2026 bypassed 2FA on a popular open-source system administration tool. It still required a valid username and password.

CISA ranks text-message and voice codes as the weakest form of MFA but says any MFA is better than none.

How do passkeys protect accounts?

A passkey replaces the password with a pair of cryptographic keys. The FIDO Alliance is the industry group behind the standard. It says users approve a sign-in the same way they unlock their device, with a fingerprint, face scan or PIN. The alliance says the design relies on public key cryptography and resists phishing.

The CISA fact sheet calls the underlying technology, FIDO/WebAuthn, the only widely available phishing-resistant authentication. Guidelines published in 2025 come from the US National Institute of Standards and Technology (NIST). They say that methods relying on a manually entered code cannot be considered phishing-resistant.

Practical steps that follow from this guidance:

  • Turn on passkeys where they are offered, starting with email and financial accounts.
  • Elsewhere, prefer an authenticator app, or approval prompts that use number matching, over text-message codes.
  • Reject sign-in prompts you did not start. The FBI advises never giving a two-factor code to anyone by email, text or messaging app.
  • Where a password is the only protection, make it long. NIST's guidelines set a 15-character minimum in that case.
A passkey sign-in is approved the same way a device is unlocked, with a fingerprint, face scan or PIN, the FIDO Alliance says.

What to watch

The FIDO Alliance estimated in May 2026 that 5 billion passkeys were in use worldwide. Microsoft said in July 2026 that it would begin rolling out passkeys as the default sign-in experience in Entra ID on September 1, 2026. Entra ID is its identity service for organizations. Microsoft also said it would end its own text-message and voice codes on February 1, 2027.

The open question is whether AI helps defenders fix weaknesses as quickly as it helps attackers exploit them. CISA urges organizations to move to phishing-resistant sign-ins.

Sources

More from AI & Cybersecurity

See all in AI & Cybersecurity