There is narrative around AI-powered cyberattacks that deserves a closer look. Much of the news that is generated concerning cyberattacks frames AI as some kind of digital superweapon. A technology capable of crafting complex exploits, defeating sophisticated defenses, and outmaneuvering security teams. The reality is boring. In the majority of successful AI-assisted attacks publicly available, AI didn’t do anything exotic. It simply moved faster, worked cheaper, and required far less skill to operate, all while exploiting the same foundational failures that have plagued organizations for years.
THE UNCOMFORTABLE TRUTH
Systems missing patches, no MFA, stolen credentials, misconfigured cloud environments, and poor network segmentation – these are not zero-day vulnerabilities requiring nation-state resources to exploit. They are gaps that show up on AI risk and security assessments every week.
What AI has changed is the velocity of exploitation. It is now possible for low-skilled threat actors to operate at a scale and speed that once required organized and well-resourced teams. The takeaway is not that AI makes the problem unsolvable. It is that AI makes the cost of missing security fundamentals higher than it has ever been. Your AI security risk assessment should reveal these weaknesses.
Three Real-World Examples
1. Change Healthcare (2024)
Missing MFA, Maximum Damage
February 2024, the ALPHV/BlackCat ransomware group gained access to Change Healthcare’s network through a Citrix remote access portal that was not protected by multi-factor authentication. The entry point was a set of compromised credentials which are routinely available through initial access brokers and dark web markets. No sophisticated exploitation was required. The attackers authenticated directly to the portal, spent nine days moving laterally through the network, and ultimately deployed ransomware that took down one of the largest healthcare payment processing systems in the United States.
The breach affected an estimated 190 million individuals, making it the largest healthcare data breach in U.S. history. UnitedHealth Group paid a $22 million ransom. The downstream disruption delayed prescriptions, stalled insurance claims, and halted reimbursements. This reverberated across the entire U.S. healthcare system for months. When UnitedHealth’s CEO testified before Congress, he confirmed the root cause: a single remote access application that lacked MFA, combined with credentials that had been compromised prior to the attack.
THE AI ANGLE
BlackCat operates as Ransomware-as-a-Service (RaaS), with affiliates leveraging automated tooling and AI-assisted reconnaissance to identify exposed portals and validate stolen credentials at scale. The automation lowered the skill and effort required.to exploit. No advanced skill was needed to find and exploit the missing control which should be identified in your cybersecurity risk assessment.
The Fundamental Failure: No Multi-factor authentication on a remote access gateway. This is not an emerging best practice requirement. It appears in every major compliance framework — HIPAA, NIST, PCI DSS, SOC 2 and has been a baseline security expectation for over a decade.
2. The Snowflake Campaign (2024)
165 Organizations, One Missing Control
Between April and June 2024, a threat actor tracked as UNC5537 (also associated with the ShinyHunters group) compromised the Snowflake cloud data environments of approximately 165 organizations, including Ticketmaster, AT&T, Santander Bank, Advance Auto Parts, and Neiman Marcus. The campaign resulted in the theft of data belonging to hundreds of millions of individuals.
The method was simple. The attackers obtained login credentials harvested by infostealer malware from employee devices. Some of these credentials dated back to 2023. They then used those credentials to authenticate directly into Snowflake customer tenants. Most affected organizations had not enabled MFA. There was no vulnerability in Snowflake’s platform that was exploited. There was no zero-day either. Investigators confirmed the breach was entirely credential based. The attackers logged in as legitimate users because they had the passwords and nothing else stood in the way.
THE AI ANGLE
Infostealer malware campaigns are often powered and distributed through AI-assisted tooling which in turn harvested credentials at industrial scale. Automated credential validation tools allowed attackers to test thousands of stolen username/password combinations against Snowflake instances rapidly to identify valid sessions without manual effort. The breadth of the campaign, 165 organizations in weeks by a small group, is a direct consequence of AI automation.
The Fundamental Failure: Credential hygiene and MFA. Google’s Threat Horizons Report found that weak or absent credentials accounted for nearly half of all initial access vectors in the first half of 2024.
3. Medusa Ransomware & MOVEit (2025)
Known CVEs, Weaponized at Scale
In March 2025, CISA issued an advisory confirming that the Medusa ransomware group had been actively exploiting CVE-2023-34362, a critical SQL injection vulnerability in the MOVEit Transfer application, as part of a sustained campaign against critical infrastructure, healthcare, education, and government targets. MOVEit had a publicly available patch in May 2023. Medusa actors were still exploiting unpatched instances nearly two years later, striking an estimated 400+ organizations using this playbook.
This is not an isolated case. Mandiant’s M-Trends 2026 report found that the average time-to-exploit for newly disclosed CVEs has been reduced from over 700 days in 2020 to 44 days in 2025. 28.3% of CVEs are now being exploited within 24 hours of public disclosure. AI-assisted tooling is driving that reduction. Attackers use large language models and automated fuzzing tools to analyze vulnerability disclosures, generate working exploits, and scan for vulnerable targets faster than most organizations can test and deploy patches.
THE AI ANGLE
AI dramatically accelerates the vulnerability-to-exploit timeline. Attackers no longer need deep technical expertise to develop a working exploit for a known CVE. Instead, all they need is an LLM, a scanning tool, and a list of targets. The minimum skill for running a sophisticated-looking ransomware campaign has dropped dramatically.
The Fundamental Failure: Patch management and asset visibility. CVE-2023-34362 was widely publicized, covered in emergency CISA advisories, and actively exploited within days of disclosure. Organizations still running unpatched instances in 2025 had a vulnerability management process failure.
Bottom line on AI Risks
How exposed are you to these exploits? Conducting AI risk assessment is one important way to stay ahead. These three cases across different industries, different threat actors, and different attack chains share the same underlying lesson: AI is a force multiplier for attackers, not a replacement for opportunity. The opportunity still must exist. The unprotected portal. The missing MFA. The unpatched server. The credential that is residing in a breach database. AI finds these gaps faster, exploits them cheaper, and scales the attack further. However, it cannot exploit what isn’t there.
The cybersecurity controls that prevent AI-assisted attacks are not advanced. They are the same controls that appear in every framework, in every assessment finding, and in every post-incident investigation:
Fundamentals
- Multi-factor authentication (MFA) on every remote access point, privileged account, and cloud service
- Credential hygiene active monitoring for stolen credentials via threat intelligence feeds and regular password policy enforcement
- Patch management with prioritization based on exploitability and not just the CVSS score
- Asset inventory and attack surface visibility helps make the unknowns known. You cannot protect what you cannot see
- Network segmentation in place to limit lateral movement once an attacker gains initial access
- Security awareness training because AI-generated phishing now achieves click rates 3x higher than conventional attacks and bypasses most email security filters
The organizations that fared the best against these campaigns were not the ones with the largest security budgets. They were the ones the had MFA enforced, their credentials monitored, and patching of Critical and Highs vulnerabilities current. This is just basic security hygiene executed consistently.
AI has not changed what good security looks like. It has simply made the cost of not doing it even more damaging.
HALOCK Security Labs helps companies identify and close the fundamental security gaps that attackers are actively targeting. Contact us to learn more about our Risk Assessments (including AI), Continuous Threat Exposure Management (CTEM) Programs, and Risk Based Threat Assessment.
References
- BlackFog — The Change Healthcare Ransomware Attack: A Landmark Cybersecurity Breach
- Picus Security — ALPHV Ransomware: Analyzing the BlackCat After Change Healthcare Attack
- HIPAA Journal — Change Healthcare: Responding to Cyberattack
- IBM Think — Change Healthcare Discloses $22M Ransomware Payment
- IS Partners — Change Healthcare Data Breach 2024: What Happened and Key Takeaways
- Huntress — Snowflake Data Breach: What Happened, Impact, and Lessons
- Nightfall AI — What Happened in the Snowflake Data Breach?
- Hack The Box — Exploring the Snowflake Breach (Attack Anatomy)
- SecurityWeek — Snowflake Hack Impacts Ticketmaster, Other Organizations
- Pomerium — The Real Lessons from the Snowflake Breach
- Medium / Chetan Seripally — AI-Powered Cyber Threats in 2025: The Rise of Autonomous Attack Agents
- The Hacker News — 2026: The Year of AI-Assisted Attacks (cites Mandiant M-Trends 2026 data)
- MixMode — The Rise of AI-Driven Cyberattacks: Accelerated Threats Demand Predictive and Real-Time Defenses
- DeepStrike — AI Cyber Attack Statistics 2025, Trends, Costs, and Global Impact
- DeepStrike — AI Cybersecurity Threats 2026: Enterprise Risks and Defenses
- Zscaler ThreatLabz — 2025 Phishing Report: AI-Powered Threats & Zero Trust
