AI Agents Are Hacking Businesses on Autopilot: What SMBs Should Know
A single operator used AI to autonomously attack 460+ organizations. What the Unit 42 report means for SMBs and five steps to reduce your exposure.

A single person used an AI agent to scan, evaluate, and attempt to exploit vulnerabilities across more than 460 organizations. It was not a team or a government-backed APT group with a nine-figure budget. One operator with an open-source AI framework and a publicly available language model did in hours what used to take a skilled hacking crew weeks.
Palo Alto Networks’ Unit 42 published the details in early August 2026. This is the first well-documented case of AI-driven autonomous hacking at scale, and it changes the economics of cyberattacks in ways that matter for every business with internet-facing systems.
What Happened
The threat actor, identified as a Chinese-speaking individual, combined DeepSeek (a publicly available AI model) with the Hermes Agent framework, an open-source tool for building autonomous AI agents. The setup allowed a single operator to give the AI a high-level objective and step away.
The agent worked through a structured attack chain on its own:
- Scanned the internet for vulnerable services
- Identified specific CVEs in the targets it found
- Researched exploit code on GitHub
- Ranked targets by severity and exploitability
- Attempted exploitation against each target
When an initial exploit failed, the agent pivoted on its own. It researched alternative vulnerabilities and switched targets without waiting for human direction.
Out of 460+ organizations targeted, the campaign confirmed data exfiltration from three Citrix NetScaler systems and achieved command execution on 11 others. The remaining attacks failed, often because the targets had basic security controls in place. Authentication requirements, non-default configurations, and services that simply weren’t exposed to the internet stopped the majority of attempts.
Why This Changes the Math
Before AI agents entered the picture, running a campaign against 460 targets required significant time, money, and expertise. A human attacker needed to manually scan each target, research vulnerabilities, write or customize exploit code, and attempt each attack individually. That process naturally limited the number of targets any single attacker could pursue.
AI agents remove those constraints. The operator in this case did not manually research each of the 460+ targets. The AI did that work autonomously, compressing what would have been hundreds of hours of manual reconnaissance into a fraction of that time. The cost per target dropped to nearly zero.
This has three practical implications for your business.
Volume replaces precision. Attackers no longer need to carefully select high-value targets. When the cost of scanning and exploiting is essentially free, they can spray attacks across hundreds of organizations and see what sticks. SMBs that previously flew under the radar because they weren’t “worth” a sophisticated attacker’s time are now as easy to target as a Fortune 500 company.
Speed compresses your response window. When a new vulnerability is published, attackers with AI tools can research, generate exploit code, and begin targeting affected systems within hours. The traditional assumption that you have days or weeks to patch a critical vulnerability no longer holds. We wrote about why patching speed matters more than ever earlier this year, and this AI campaign makes that argument even more urgent.
The skill barrier has dropped. Building exploit tools used to require deep technical expertise. This campaign used an open-source framework and a publicly available AI model. The campaign required no zero-day research or custom malware development, only off-the-shelf components assembled to target known, unpatched vulnerabilities at a scale that previously required a well-funded team.
The Good News: Basic Controls Still Work
The most important finding in the Unit 42 report is also the most encouraging. The vast majority of the 460+ attacks failed, and they failed for straightforward reasons.
Targets that required authentication on their exposed services blocked the AI agent. Systems that weren’t directly exposed to the internet were invisible to the scanner entirely. Organizations that had patched known vulnerabilities left the AI agent with nothing to exploit. The margin between the three organizations that were breached and the hundreds that weren’t came down to fundamental security hygiene.
The three confirmed breaches all involved Citrix NetScaler systems with known vulnerabilities that had patches available but not applied. The attacker didn’t use some novel, undetectable technique. The AI simply found internet-facing systems running software with published vulnerabilities and exploited them using publicly available code.
The defenses your organization needs are not exotic or expensive. They are the same controls that security teams have been recommending for years. The difference now is that the speed and volume of attacks makes them non-optional.
Five Steps to Reduce Your Exposure
These are concrete actions you can take now. Each one directly addresses how the AI campaign in the Unit 42 report found and exploited its targets.
1. Find Out What’s Internet-Facing
Ask your IT provider for a complete inventory of every system, application, and service accessible from the internet. This includes remote access portals, admin panels, database consoles, and management interfaces. If you don’t know what’s exposed, you can’t protect it. The AI agent in this campaign started by scanning for exposed services, and anything it could see, it targeted.
2. Put Admin Panels Behind Authentication
Multiple attacks in this campaign failed because the target had authentication enabled on its management interfaces. That sounds basic, but Unit 42’s findings show that enough organizations leave admin panels open to the internet without requiring a login for it to be a viable attack strategy. Every management interface should require authentication at minimum, and sensitive systems should sit behind VPN or zero-trust network access.
3. Verify Your Patch Cadence
The successful breaches exploited known vulnerabilities with available patches. The targets simply hadn’t applied them. With AI agents able to weaponize a newly published CVE within hours, patching monthly or quarterly is not fast enough for critical vulnerabilities. Ask your IT provider what their target window is for critical patches and whether they can show you evidence that patches were applied. Our team has documented how we respond when a critical CVE drops, and the timeline is typically hours, not weeks.
4. Confirm Continuous Vulnerability Scanning
An annual penetration test is a snapshot. It tells you what was vulnerable on the day of the test. AI-driven attacks happen continuously, and new CVEs are published weekly. Your organization needs continuous vulnerability scanning that identifies new exposures as they appear, not a once-a-year report. If your current provider only does annual assessments, the gap between those assessments is exactly where attacks like this campaign succeed.
5. Monitor for Exploitation Attempts in Real Time
The Unit 42 report was possible because Palo Alto Networks had telemetry showing the attack patterns as they happened. Organizations with 24/7 SOC monitoring and proper logging in place can detect exploitation attempts as they occur, block attacking IP addresses, and trigger response procedures before an attacker achieves their objective. Without active monitoring, you won’t know you were targeted until the damage is done.
This Is Not a Future Threat
This campaign happened in 2026 using tools that are freely available today. The Hermes Agent framework is open source. DeepSeek is publicly accessible. It required no government lab, no classified exploits, and no million-dollar toolkit.
The organizations that were breached were not hit by some unstoppable new weapon. They were running unpatched software with known vulnerabilities on internet-facing systems. The AI just found them faster than a human would have.
For businesses across Dallas-Fort Worth and the rest of Texas, the takeaway is clear: the defensive fundamentals that security teams have been advocating for years are now your primary defense against a qualitatively different kind of threat. If you’ve been putting off patching, exposure auditing, or real-time monitoring because the risk felt abstract, this Unit 42 report makes it concrete.
We covered the broader trend of AI-powered attacks accelerating against SMBs earlier this year. This report is the first documented proof that autonomous AI hacking at scale is no longer theoretical.
Need Help Securing Your Attack Surface?
Our team can assess your internet-facing exposure, verify your patching process, and set up continuous monitoring so AI-driven attacks don't find the gaps first.
Get a Free AssessmentServing Businesses Across Texas & Oklahoma