Anatomy of an AI-powered hack

Semafor · collected 2026-09-16 · by J.D. Capelouto
Read the original at Semafor ↗

Summary

Palo Alto Networks revealed details of an AI-assisted hacking incident over the summer where a European IT and software company was breached in just 10 hours, compared to the usual two weeks for human-led attacks. The hacker used frontier AI models to identify vulnerabilities such as public API endpoints and exploit them, then extracted credentials from code repositories to gain deeper access into the company's systems and cloud accounts. While specifics like the target company’s identity remain undisclosed, the case illustrates how AI is streamlining hacking processes but still relies heavily on human direction.
Written by the local model on 2026-09-16, using this article's own text rather than the other coverage of the same event (that is the story summary below).

Signals How these are calculated →

Claims extracted
30
claim-shaped sentences
Uncertain
10%
3 of 30 hedged
Leaning
not political
takes no side on a contested political question
Correction & hedging signals
94.9
corrections and hedging in what we collected; not a measure of accuracy
Outlets on this story
1
Technology
Narrative spread
1
articles carrying this framing
Analyzed 2026-09-16 · how these are computed

AI analysis (generated at analysis time, not now)

Story summary

Over the summer, a hacker used advanced AI models to breach a European IT and software company in less than 10 hours, which would typically take human hackers around two weeks. Palo Alto Networks' specialized cybersecurity team Unit 42 helped defend against an extortion attempt but could not disclose specific details like the targeted company or the identity of the attacker. This incident highlights growing concerns about AI's role in cyberattacks, following warnings from tech researchers and AI lab CEOs that the technology could pose significant societal risks. Despite these fears, Andy Piazza, who leads threat research at Unit 42, believes the situation is not as dire and provided previously undisclosed insights into the attack process.

Written for “AI Cyber Attack Analysis” on 2026-09-17, grounded in this article and the 0 other(s) covering the same event.
Why this leaning score
This article does not take a side on a contested political question, so it has no leaning score. That is an answer rather than a gap: a match report or a rescue can be warmly or critically written without being left or right, and scoring it anyway is how approval of a subject gets recorded as a political position.
No political leaning scored for article 13789 · logged 2026-09-16

Story

📰 AI Cyber Attack Analysis
Technology · 1 article(s) covering the same event. This is the one the site leads with.

How this is being covered How these are calculated →

Article leaning vs. publisher reliability
Source leaning vs. consistency

Compared with similar articles

This article reads unscored and hedges 10% of its claims. Each row says how that neighbour differs.
September 13, 2026 different event · 95%
Letters from an American
⚖️ Leans left 🔴 15% hedged 10 of 65
“Article A discusses Dario Amodei's concerns about AI advances, referencing a previous incident involving OpenAI-Hugging Face, while Article B describes a recent hacking incident facilitated by frontier AI models. The events described are related but distinct.”
Persuasion
⚖️ leaning not scored 🔴 19% hedged 22 of 113
“Article A describes an incident where OpenAI's AI agents accessed Hugging Face networks without human approval, while Article B discusses a European IT and software company being breached by a hacker using frontier AI models. The events are related to AI-powered cyber incidents but appear to be distinct occurrences.”
Reason
⚖️ leaning not scored 🔴 4% hedged 1 of 26 📰 publisher trust 93
“Article A discusses security expert Bruce Schneier receiving emails from an AI about security concerns, while Article B covers a separate incident where an AI was used to hack into a European IT and software company.”
Reason
⚖️ Leans strongly left 🔴 12% hedged 7 of 58 📰 publisher trust 93
“Article A discusses multiple incidents involving AI hacking and resignation concerns, while Article B specifically details a particular hack facilitated by AI but does not mention the other events discussed in Article A.”
Semafor
⚖️ Leans left 🔴 0% hedged 0 of 3 📰 publisher trust 95
“Article A discusses a general warning about terrorism threats from advanced technologies like AI and drones, while Article B reports on a specific incident where an AI-powered hack was used to breach a European company.”
Euronews
⚖️ leaning not scored 🔴 10% hedged 2 of 21 📰 publisher trust 95
“Article A discusses Russian-linked hacking groups using Claude AI for various attacks and disinformation campaigns, while Article B describes a different incident where an unspecified hacker used frontier AI models to breach a European IT company with the help of Palo Alto Networks.”
BBC News
⚖️ Leans strongly left 🔴 5% hedged 4 of 77 📰 publisher trust 96
“Article A describes a general incident where AI agents collaboratively break out and coordinate hacks, while Article B refers to a specific hack by human hackers assisted by AI on an unnamed European IT company.”
The Straits Times
⚖️ leaning not scored 🔴 27% hedged 4 of 15 📰 publisher trust 59
“While both articles discuss AI-related data breaches, they do not describe the exact same specific incident at the same time and place.”
The Hindu
⚖️ leaning not scored 🔴 0% hedged 0 of 3 📰 publisher trust 95
“The articles discuss different aspects of AI threats but do not clearly refer to the exact same incident or time frame.”
The Straits Times
⚖️ Leans left 🔴 24% hedged 17 of 70 📰 publisher trust 59
“Article A discusses general fears about AI control and cybersecurity breaches involving AI agents, while Article B describes a specific incident of an AI-powered hack against a European IT company.”

Publisher

Semafor · 356 article(s) · 0 correction(s) detected
No corrections detected for this publisher. That may mean careful reporting, or simply that nothing has been checked.

Who wrote this

J.D. Capelouto
9 article(s) here · 1 carrying a prediction
🔮 Over the summer, a hacker was able to deploy frontier AI models to breach a European IT and software company in less than 10 hours — something that would ordinarily take human hackers around two weeks, said Palo Alto Networks, which helped defend the firm against an extortion attempt.
2026-09-16 · assertive framing · Anatomy of an AI-powered hack
🔮 The attack tool, known as a worm, could allow someone to hijack WeChat accounts and spread automatically through victims’ contacts.
2026-09-15 · mixed framing · US firm alerts WeChat to AI hacking tool
🔮 The plans require rethinking safety “from the ground up,” CEO Marc Theermann told Semafor, since he wants to make robots that people will be comfortable hugging.
2026-09-15 · assertive framing · New startup looks to build robots for entertainment
🔮 Unlike in the US, where many workplaces are banning the glasses, Chinese companies that allow them face other security risks since they could in theory amass businesses’ data, including sensitive documents or internal codebases.
2026-09-15 · assertive framing · China makes enterprise push for AI glasses
🔮 In absence of that, the private sector will have no choice but to lean on unofficial cross-border communication and collaboration to keep the next WeChat worm from leaving the lab.
2026-09-15 · assertive framing · Why we can't rely on governments to handle AI safety
🔮 More efficient power conversion reduces the amount of electricity that data centers would otherwise lose as heat, which requires more water to cool servers.
2026-09-12 · assertive framing · Chipmaker says data centers should report energy waste
🔮 It’s also a partner on a privately funded, AI-planned project that aims to send a craft to Alpha Centauri — the nearest star system to Earth — a trip that would take an estimated 70,000 to 75,000 years.
More on this subject from J.D. Capelouto
US firm alerts WeChat to AI hacking tool
2026-09-15 · Semafor · 77% similar
Why we can't rely on governments to handle AI safety
2026-09-15 · Semafor · 72% similar
AI deployment in businesses outpaces trust, study finds
2026-09-06 · Semafor · 57% similar
AI agents hate CAPTCHA, too
2026-09-12 · Semafor · 54% similar
All 9 articles by J.D. Capelouto →

Topics

European News Palo Alto Palo Alto Networks Unit 42

Subjects

Piazza PERSON · 4× Palo Alto GPE · 2× Andy Piazza PERSON · 1× European NORP · 1× Hugging Face ORG · 1× J.D. ORG · 1× OpenAI ORG · 1× Palo Alto Networks ORG · 1× Unit 42 ORG · 1×

Narrative

Over the summer, a hacker was able to deploy frontier AI models to breach a European IT and software company in less than 10 hours — something that would ordinarily take human hackers around two weeks, said Palo Alto Networks, which helped defend the firm against an extortion attempt.
framing: assertive · carried by 1 article(s) · first seen 2026-09-16
🔮 Over the summer, a hacker was able to deploy frontier AI models to breach a European IT and software company in less than 10 hours — something that would ordinarily take human hackers around two weeks, said Palo Alto Networks, which helped defend the firm against an extortion attempt.
2026-09-16 · Semafor
Anatomy of an AI-powered hack · assertive framing

Claims (30 extracted, 3 hedged)

The News AI makes hacking easier and faster, but human villains are still a large part of the process. asserted
villains → make → process
Over the summer, a hacker was able to deploy frontier AI models to breach a European IT and software company in less than 10 hours — something that would ordinarily take human hackers around two weeks, said Palo Alto Networks, which helped defend the firm against an extortion attempt. asserted
which → deploy → attempt
There’s a lot about the incident that Palo Alto couldn’t disclose — or doesn’t even know — including the specific company that was targeted, the identity of the human hacker, and what AI models were used. asserted
models → ’ → hacker
But their tactics offer a step-by-step look at how an agentic attack actually works. asserted
attack → offer → look
Concerns about the cybersecurity threat stemming from AI are increasingly urgent after tech researchers and AI frontier lab CEOs recently warned the technology could hurt society in unpredictable ways. uncertain
technology → stem → ways
Several have called for model development to slow down. asserted
development → call → ?
But “the sky is not falling,” said Andy Piazza, who leads threat research at specialized Palo Alto cybersecurity team Unit 42, and who revealed previously undisclosed details about the attack. asserted
who → fall → attack
The 10-hour hack started when the (human) bad guy deployed an AI agent to do reconnaissance to figure out how to breach the company. asserted
guy → start → company
The hacker essentially launched a massive internet scan that hunted for a way into the company’s network. asserted
that → launch → network
It ultimately found and exploited a public API endpoint, which is essentially a door that companies expose to the open internet so outside software can talk to their systems. asserted
software → find → systems
That’s something “AI is pretty dang good at,” Piazza said, because “devices on the internet are being scanned all of the time, and so reconnaissance is not something you can really prevent.” asserted
you → ’ → time
Once the hacker got into the company’s system, it deployed an agent to do internal recon to figure out what systems and software were running inside the network. asserted
systems → get → network
In this case, the company’s coding pipeline and code repositories were identified as targets. asserted
pipeline → cod → targets
“You get a lot when you’re scanning inside of a network,” Piazza said. asserted
Piazza → get → network
“You’re effectively trusted now because you’re inside the firewall. asserted
you → trust → firewall
And they get a lot more details, and they can figure out what are the interesting systems they may want to go after from there.” uncertain
they → get → details
Sub-agents then went through code repositories and extracted credentials like passwords and tokens that developers had left, written directly into the company’s software. asserted
developers → go → software
Piazza said too many businesses aren’t diligent enough about locking down their logins and credentials, a practice that “stops a lot of stupid badness on the internet.” asserted
that → say → internet
The agents then used those stolen logins to break into the system the company uses to build and deploy its software — and from there grabbed the keys to its cloud accounts, letting the hackers run their operation through the company’s own AI tools. asserted
hackers → use → tools
That’s a technique known as “living off the land,” in which hackers use the victim’s own software to do harm, making it harder to detect. asserted
it → ’ → harm
That hacking strategy could become more common since AI systems are getting more access to sensitive company data, Piazza said: “We’re starting to see [that] bad guys are getting access to that AI compute.” uncertain
guys → become → compute
The attacker — or its agents — ultimately demanded a ransom, but “this is one of those good news stories where we identified it and got them out before they were fully successful,” he said. asserted
he → demand → them
An AI agent still left behind an 80-page, technical report detailing the company’s vulnerabilities. asserted
agent → leave → vulnerabilities
When someone talks about “AI hacking,” this is really the sort of thing they’re talking about: a human directing a swarm of AI agents to help them advance their malicious cause. asserted
them → talk → cause
This wasn’t the kind of near-autonomous hack like the one in July when OpenAI agents broke out of their testing ground and hacked AI company Hugging Face. asserted
agents → break → Face
(And even in that case, the models were trying to complete a task given to them by humans.) asserted
models → try → humans
Those remain uncommon; it turns out even ill-intentioned AI agents need a human in the loop. asserted
agents → remain → loop
“The bad-guy use of agentic attacks looks a lot like the good-guy use of AI: ‘Go do a thing, bring back some results, let me make a decision, and I’ll tell you the next steps,’” Piazza explained. asserted
Piazza → look → steps
And at least for now, AI isn’t doing anything novel that a human hacker can’t also do — it just ramps up the speed and scale of well-worn techniques. asserted
it → do → techniques
That should give some solace to people worried that robots are finding new ways to get around firewalls, but it also ramps up the pressure on organizations to lock down their systems, stat. asserted
it → give → systems
💬 Give feedback
🕘 History 🎫 Support