Palo Alto Networks’ Unit 42 threat intelligence team published its 2026 Global Incident Response Report on July 16, and the headline finding cuts against a year of AI-threat hype: artificial intelligence is not rewriting how attackers break in. It is making the same old techniques faster.

Unit 42 found that AI is “acting as a force multiplier to increase the speed and efficiency of attacks, but is not significantly redefining methods of compromise.” Credential theft, phishing, exploitation of known vulnerabilities, and ransomware remain the dominant paths into a network. AI mainly compresses the time attackers spend on reconnaissance, content generation, and malware development. The report does flag two AI-native additions to the threat model: agentic ransomware that manages multiple stages of an extortion operation while reducing operational complexity for the attacker, and “token jacking,” in which stolen credentials are used to access cloud AI services and run up unauthorized charges on LLM API accounts.

For CISOs weighing budget against a flood of AI-security vendor pitches, that distinction matters. Andy Piazza, Unit 42’s senior director of threat intelligence, said AI-assisted attacks “have still not yet reached a level that urges organizations to redesign their cyber defense strategy.” The fundamentals (patching, identity hygiene, credential monitoring) remain the highest-leverage investment, not a wholesale pivot toward AI-specific defense tooling.

The original wrinkle worth acting on now is token jacking. It turns LLM API keys and cloud AI billing into a fraud surface most incident response playbooks do not yet cover. Security teams that already monitor for stolen cloud credentials should extend that same detection logic to AI service tokens, before a finance team flags the anomaly first. That risk sits alongside growing scrutiny of AI agent session isolation, another emerging weak point in AI-enabled environments.

Source: Unit 42