AI cyber attacks in Australia are moving faster
Attackers still want passwords and a path through a weak website to valuable data. AI lets them do more of the work before a business notices. In July 2026, ASD's Australian Cyber Security Centre warned that attackers may use AI to find and exploit vulnerabilities quickly, target many victims at once and move from an initial compromise to theft or extortion faster. This brief keeps the Australian survey data separate from the threat intelligence and explains what each source can prove.
Josh · Published 10 August 2026
Small businesses hold the data but doubt their defences
92% of Australian small businesses surveyed hold personal or sensitive data, but only 26% felt confident they could protect it.
The clearest local baseline comes from auDA's Digital Lives of Australians 2026 study. SEC Newgate Research ran an online survey with 2,080 consumers and 408 small business owners or managers, then weighted the samples to reflect the Australian population.
The survey found that 92% of small businesses held personal or sensitive data, while only 26% felt confident they could protect it. One in three thought the business was too small to be targeted. That belief matters because attackers do not need a large target. They need a reachable one.
AI adoption is also running ahead of capability. The same survey found that 72% of small businesses had used AI, while only 24% reported high cyber security capability and 29% reported high AI capability. Those figures describe confidence and self assessed capability. They do not measure the technical strength of each business.
Data held versus confidence
auDA 2026What the Australian survey found
Measured survey- One in three felt too small to be targeted. That was a reported belief among the surveyed small businesses, not a measure of their exposure.
- 72% had used AI. Adoption rose eight percentage points year on year in the 2026 study.
- 24% reported high cyber capability. The equivalent self assessment for AI capability was 29%.
Malware first, then deeper inside
In Anthropic's selected enforcement dataset, 67.3% of the malicious accounts used AI to help write malware.
Anthropic reviewed 832 accounts banned for malicious cyber activity between March 2025 and March 2026. These were the cases where its investigators had enough detail to map the behaviour against MITRE ATT&CK. They were a subset of all banned accounts, so the figures show how this selected group used AI, not how common each technique is across cybercrime.
Of those 832 accounts, 560, or 67.3%, used AI to help write malware. Another 54, or 6.5%, used it for lateral movement, which means navigating further through a network after getting in. Anthropic also saw AI use move away from gaining initial access and towards account discovery, privilege escalation and other work carried out after compromise.
The risk scores moved with it. In the first six months, Anthropic classified 33% of the actors as medium risk or higher. In the second six months that share reached 56%, about 1.7 times the earlier rate. That increase belongs to Anthropic's risk model and this selected dataset. It is not a claim that global cyber risk rose by the same amount.
AI use in malicious accounts
Anthropic 2026The change inside the attack
Observed subset- 560 of 832 accounts wrote malware. AI supported the preparation stage in most of the selected cases.
- 54 of 832 moved laterally. Less skilled actors could use AI for work that once demanded deeper technical knowledge.
- The later stages grew. Account discovery rose while AI assisted phishing fell across the study period.
AI compresses the time between access and harm
AI cuts the work between finding a weak point and using it at scale.
ASD's ACSC says attackers may use AI to discover and exploit vulnerabilities rapidly, especially in websites, then target many victims at once and move from compromise to theft or extortion faster. It is a warning about compressed time, not a new category of victim.
Google Threat Intelligence Group reported in May 2026 that it had identified a threat actor using a zero day exploit that it believes was developed with AI. Google also documented AI supported malware development, research, command generation and attacks against AI software supply chains. The word believes matters. Google attributed the exploit's development to AI, but it did not present a controlled measurement of causation.
Microsoft's April 2026 assessment is the useful counterweight. It says a human is typically still directing these attacks. AI reduces friction across research, social engineering, malware development and stolen data triage. Fully autonomous campaigns remain the exception, not the working assumption.
What threat intelligence supports
Attributed- Faster discovery and exploitation. ASD's ACSC identifies websites as a particular concern for small business.
- One attributed AI developed zero day. Google says it believes AI was used to develop the exploit.
- A human is usually still in the loop. Microsoft says AI reduces friction rather than running most campaigns alone.
Familiar controls still do the work
The Australian guidance does not ask a small business to buy an AI defence platform. It asks the business to remove weak points and know who owns them.
The ACSC guidance is deliberately practical. Turn off websites you no longer need. Disable unnecessary features on the ones you keep. Use supported software and apply security updates automatically or soon after release. Check whether the companies holding your customer data take security seriously.
If the business develops software, the ACSC recommends a quality assurance process that includes vulnerability scanning. It also says someone must own website security and be able to explain how quickly the business would detect a compromise, evict an attacker and restore from a recent secure backup.
AI changes the speed of the attack, but it does not make an unused website, an old plug in or an exposed secret less relevant. It makes the delay in fixing them more expensive.
Small business response
ASD guidance- Reduce the attack surface. Turn off unused websites and features.
- Patch supported software quickly. Automate browser and operating system updates where possible.
- Scan software for vulnerabilities. Put the scan inside the quality assurance process, not after launch.
- Name the owner. Someone must maintain, detect, respond and restore.
Each dataset answers a different question
There is no single 2026 prevalence figure for AI enabled cyber attacks.
QBE surveyed 400 Australian decision makers in organisations with 100 to 2,000 employees. Half reported a cyber event in the previous 12 months and 26% said the incident was believed to involve AI. Among businesses affected by an incident, 60% reported lost revenue and 18% reported interruption lasting at least a day.
Those are self reported answers from mid sized and larger organisations. They do not prove that one in four Australian small businesses suffered an objectively verified AI enabled attack. The auDA figures measure small business attitudes and capability. Anthropic measures activity in a selected set of banned accounts. Google and Microsoft publish threat intelligence from their own visibility. Each source answers a different question.
Together, the sources support a narrow conclusion. Attackers are using AI across more of the attack cycle, and Australian small businesses hold valuable data with limited confidence in their protection. The evidence does not support adding every cybercrime loss to an AI total or treating every attack as autonomous.
How to read the numbers
Method- auDA is a weighted survey. It measures reported attitudes, use and capability among 408 small businesses.
- QBE is self reported attribution. Respondents said an incident was believed to involve AI.
- Anthropic is a selected platform dataset. It covers 832 banned accounts with enough evidence for assessment.
- Google and Microsoft are threat intelligence. They describe observed and attributed activity, not population prevalence.
Frequently asked questions
Every claim, in context
Related Field Notes
Read nextClose the reachable gaps