Cybersecurity Best Practices and Risk Management Blog | HITRUST

AI Isn't Changing Cyberattacks - It's Making Them Faster, Cheaper, and Harder to Detect

Written by HITRUST | Aug 11, 2026, 1:45:20 PM

AI Isn't Changing Cyberattacks - It's Making Them Faster, Cheaper, and Harder to Detect

What you need to know

  • Phishing remains the #1 threat across both traditional (MITRE ATT&CK) and AI-specific (MITRE ATLAS) datasets this quarter.
  • Attackers are using generative AI to run familiar techniques faster, cheaper, and at greater scale.

Through our Cyber Threat Adaptive (CTA) program, HITRUST analyzes current threat intelligence and maps it to the HITRUST CSF, keeping certifications aligned to the threats organizations are currently facing. This quarter's findings point to one clear theme: AI isn't fundamentally changing how attackers operate; it's changing how quickly they can do it.

In HITRUST's Q2 2026 analysis, the most prevalent threats weren't new AI-native attacks. Instead, attackers are using GenAI to scale familiar techniques such as phishing, malicious packages, and social engineering. The result is faster and more targeted campaigns that challenge security teams and controls. It also underscores a bigger point: point-in-time compliance is no longer enough. Control requirements must be continuously validated against real-world threat activity.

 

This quarter's findings

Phishing topped both frameworks and user-execution techniques like malicious packages rose alongside it. This indicates how AI is accelerating existing attack paths in ways many organizations may not expect or be prepared for.

Crucially, these techniques are a means to an end. AI-empowered spear-phishing campaigns are used in blended attacks aimed at implanting persistent threats such as malware and ransomware, gathering intelligence, or achieving financial gain. For example, Microsoft found AI-automated phishing achieved a 54% click-through rate versus 12% for standard attempts.

 

Analysis and control coverage

The analysis for this edition of the report covered almost 5,000 threat articles, over 400,000 ATT&CK/ATLAS indicators, and almost 150 real-world breaches. The resulting HITRUST control selections against attacker techniques are:

  • 100% coverage of adversarial techniques for i1 and r2 assessments

  • 98.59% for e1 assessments

  • over 97% for the AI Security assessment

 

Conclusion

Assurance must reflect the cyber threats organizations are most likely to face, not just the controls they've historically implemented. HITRUST's e1, i1, and r2 assessments and certifications use current threat and breach analysis to confirm that requirements continue to address relevant techniques, while the AI Security Assessment and Certification applies the same approach to AI-enabled services. As attackers use AI to make old tradecraft faster and cheaper, this continuous analysis helps organizations stay positioned to defend against today's threat landscape.

 

Read the Report

Download the Q2 2026 HITRUST CSF Threat and Mitigation Analysis report today to see how today's most common attacker techniques align to your security controls and assurance strategy.