- Premium Content It takes our newsroom weeks - if not months - to investigate and produce stories for our premium content. You can’t find them anywhere else.
‘Not how humans act’: how agentic AI is changing cyberattacks
Reuben Koh knows when he’s watching AI attack a network – the patterns look all wrong.
“We know that AI agents are being utilized in this manner because no human would do it that way,” he tells Tech in Asia.
For decades, coordinated cyberattacks have been slow and methodical, unfolding over days or weeks. An attacker would gain initial access then move carefully through the network, trying to avoid detection.

Image credit: Timmy Loen
But nowadays, AI agents are increasingly handling almost every aspect of a cyberattack, with humans only stepping in for strategic decisions, according to Koh. He is the director of security and technology strategy for Asia Pacific and Japan at cybersecurity firm Akamai Technologies.
In November 2025, US-based Anthropic published a report detailing what it called the first documented AI-orchestrated cyber espionage campaign. According to the report, a Chinese state-sponsored group used Claude Code to conduct attacks against roughly 30 organizations, with AI agents executing an estimated 80% to 90% of the work. Anthropic described the attacks as happening at “physically impossible request rates.”
The report sparked controversy, with critics saying it was vague and lacked evidence. But for cybersecurity professionals like Koh, the findings simply confirmed what they were already seeing.
The speed problem
Agentic attacks operate at what Koh calls “machine speed.” AI bots are not cautious or methodical; they move comprehensively and simultaneously. They can probe dozens of systems at once, try hundreds of usernames and passwords, and exploit multiple vulnerabilities in parallel.
Even the social engineering portions of cyberattacks – which used to require extensive research, careful targeting, and skilled writing to steal users’ names and passwords – have become automated.

Reuben Koh, director of security and technology strategy for Asia Pacific and Japan at Akamai / Photo credit: Akamai
“Most of the time, they can be successful even before you finish your coffee,” Koh says. Consequently, this has changed how companies need to defend their systems.
Sheetal Mehta, global head of cybersecurity services for NTT Data, explains how part of the problem is that agentic attacks blend seamlessly into enterprise environments, making detection significantly harder.
With AI, cybercriminals are not deploying obviously malicious software that triggers alerts. Instead, they have access to the same standard tools that legitimate businesses use.
Productivity of errors
What enterprises must do
Stay ahead in Asia’s tech landscape
This is premium content. Subscribe to read the full story.
As AI agents become the new cybersecurity threat, it’s time to learn how to defend against their attacks – and why they can be so devastating.
We know this is not ideal. ⌛ Sign up in 20 seconds. Cancel anytime.
Our subscriber community includes professionals from these companies:





Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.

