Cybersecurity in the Age of Bots: When Machines Start Attacking Machines

by Dr. Sean Stein Smith, CPA, DBA, CMA, CGMA, CFE, City University of New York – Lehman College – August 24, 2026
Cybersecurity in the Age of Bots: When Machines Start Attacking Machines

A finance executive receives a voice message from the CEO requesting an urgent wire transfer. The voice, cadence and business context all sound right. There is only one problem: the CEO never recorded that message. 

That scenario captures the new cybersecurity reality. The threat is no longer limited to human hackers using automated tools. Generative AI and agentic systems are giving those tools the ability to personalize, adapt and act with far less human direction. Cybercrime is becoming faster, cheaper and easier to scale.

Automation Can Improvise

Bots have been part of cyberattacks for decades. They scan networks, test passwords, scrape data, distribute spam and overwhelm websites. Most traditional bots, however, follow fixed scripts. They repeat the same actions until they succeed, fail or are blocked.

AI-enabled bots are different. They can analyze a response, generate new content, adjust their approach, and try again. A conventional phishing campaign might send the same awkward email to thousands of people. A GenAI-powered campaign can tailor each message to a target’s job, employer, recent activity, professional contacts, and writing style. The attack still operates at scale, but it no longer looks mass-produced.

Agentic AI pushes this further. Instead of waiting for a prompt, an AI agent can be assigned a goal and determine the steps, tools, and information needed to complete it. In business, an agent might collect data, prepare a report, schedule a meeting and send follow-ups. In the wrong hands, the same model could identify vulnerabilities, select employee targets, craft convincing outreach, test stolen credentials, and revise its tactics based on the results.

Fully autonomous cyberattacks are not suddenly everywhere. Technical limits, safeguards and human involvement still matter. But attackers can already automate more of the work. Less-skilled criminals gain access to better capabilities, while experienced attackers can run more campaigns at once.

Trust Is an Attack Surface

Deepfakes and synthetic identities make the problem harder because familiar signs of authenticity are losing value. A voice can be cloned. A video call can be manipulated. An email can match an executive’s tone. A fake employee or vendor can be supported by a convincing trail of messages, profiles and documents.

This changes what employees should trust. “It sounded like her” or “the message looked professional” can no longer count as verification. Requests involving money, credentials, sensitive data or system access need confirmation through a separate, established channel.

Many organizations still train employees to spot spelling errors, strange links and poorly written messages. Those clues are becoming less reliable. Modern training should focus on the process: pause, verify and treat urgency as a warning sign rather than a reason to bypass controls.

An Automated Defense

AI is also strengthening cyber defense. Security tools can sift through network activity, identify unusual behavior, summarize alerts, flag malicious code and help teams respond to incidents. Agentic systems may soon isolate compromised devices, block suspicious accounts, gather forensic evidence or recommend remediation steps.

For understaffed security teams, that speed is valuable. It is also dangerous when automation is wrong. A defensive agent that misclassifies normal activity could freeze operations, lock out employees or damage critical data. A compromised internal agent could be worse because it may already have access to email, cloud storage, financial systems, customer records and collaboration platforms.

Prompt injection, poisoned data, insecure integrations, exposed application programming interface (API)s and excessive permissions are not abstract technical concerns. They are potential routes into the center of an organization.

Controls Matter

The answer is not simply to buy another security product. Organizations need controls designed for systems that can act, not just advise.

AI agents should receive only the access required for a defined task. Financial transfers, password resets, data exports, software deployment and other high-risk actions should require independent approval. Agent activity should be logged and monitored. Systems should be tested against manipulation, and every organization should have a fast way to disable an agent that behaves unexpectedly.

The decisive question is not whether AI will be part of cybersecurity. It already is. The question is whether organizations set the boundaries before attackers exploit the gaps.

The next phase of cybersecurity will involve bots attacking bots, agents supervising agents and humans deciding where automation must stop. The advantage will not go to the organization with the most AI. It will go to the one with the clearest controls, the strongest verification habits and the discipline to keep humans accountable for the decisions that matter.