Tired of ads? Enjoy an ad-free experience by signing up.
  • Premium Content
    It takes our newsroom weeks - if not months - to investigate and produce stories for our premium content. You can’t find them anywhere else.
Scott Shuey · · 5 min read

‘Not how humans act’: how agentic AI is changing cyberattacks

Reuben Koh knows when he’s watching AI attack a network – the patterns look all wrong.

“We know that AI agents are being utilized in this manner because no human would do it that way,” he tells Tech in Asia.

For decades, coordinated cyberattacks have been slow and methodical, unfolding over days or weeks. An attacker would gain initial access then move carefully through the network, trying to avoid detection.

Image credit: Timmy Loen

But nowadays, AI agents are increasingly handling almost every aspect of a cyberattack, with humans only stepping in for strategic decisions, according to Koh. He is the director of security and technology strategy for Asia Pacific and Japan at cybersecurity firm Akamai Technologies.

In November 2025, US-based Anthropic published a report detailing what it called the first documented AI-orchestrated cyber espionage campaign. According to the report, a Chinese state-sponsored group used Claude Code to conduct attacks against roughly 30 organizations, with AI agents executing an estimated 80% to 90% of the work. Anthropic described the attacks as happening at “physically impossible request rates.”

The report sparked controversy, with critics saying it was vague and lacked evidence. But for cybersecurity professionals like Koh, the findings simply confirmed what they were already seeing.

The speed problem

Agentic attacks operate at what Koh calls “machine speed.” AI bots are not cautious or methodical; they move comprehensively and simultaneously. They can probe dozens of systems at once, try hundreds of usernames and passwords, and exploit multiple vulnerabilities in parallel.

Even the social engineering portions of cyberattacks – which used to require extensive research, careful targeting, and skilled writing to steal users’ names and passwords – have become automated.

Reuben Koh, director of security and technology strategy for Asia Pacific and Japan at Akamai / Photo credit: Akamai

“Most of the time, they can be successful even before you finish your coffee,” Koh says. Consequently, this has changed how companies need to defend their systems.

Sheetal Mehta, global head of cybersecurity services for NTT Data, explains how part of the problem is that agentic attacks blend seamlessly into enterprise environments, making detection significantly harder.

With AI, cybercriminals are not deploying obviously malicious software that triggers alerts. Instead, they have access to the same standard tools that legitimate businesses use.

Productivity of errors

What enterprises must do

Stay ahead in Asia’s tech landscape

This is premium content. Subscribe to read the full story.

Why subscribe?

As AI agents become the new cybersecurity threat, it’s time to learn how to defend against their attacks – and why they can be so devastating.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

10

10 company database access

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

🧠 For professionals / ⭐ Best value

CoreBest value

US$16.58US$14.92/month

Billed annually at US$179.10 on the first year

Get instant access to this article and more every month

Unlimited premium content

Unlimited news briefs & articles

Unlimited company database access

Ad-free reading experience

Just US$0.55 per day

Save US$19.90 on the first year. Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.

TIA Writer

Scott Shuey

Scott has worked as a journalist for over 20 years, including 18 years working in Asia. He covers emerging technologies such as AI and Web3. You can reach him at scott.shuey@techinasia.