If you require urgent support or when you just need to talk, our Service Team is available to receive your call. Currently based in East Perth, our phone support is manned weekdays from 6:30am – 5:00pm.

For any urgent issues, our dedicated ‘After-Hours’ phone service is available 24/7.

For regular service requests, please email us, this will automatically be logged into our ITSM Software which will be addressed in a timely manner in-line with our SLA.

If you have any questions or concerns regarding billing, we are here to assist you. Please don’t hesitate to reach out to us, as we are more than happy to provide you with additional information and address any queries you may have.

Edit Template

AI Hacking Is Anyone’s Game Now

The skills barrier is gone

AI hasn’t changed what attackers want. It has changed how many people can now try, and that changes the odds for every business.

For decades, cybercrime had a skills floor. Writing working malware, chaining exploits and moving quietly through a network took years to learn. AI has removed that floor.

It hasn’t just made experienced hackers faster. It has put real attacks within reach of people who have never written a line of code. In November 2025, a University of Queensland cyber security researcher warned that anyone could now be a hacker with AI. Almost a year on, that warning has become a running tally of real incidents.

For Australian businesses the stakes were already high. The Australian Signals Directorate (ASD) received a cybercrime report roughly every six minutes in 2024-25, and that was before most of the cases below.

When uni students can hack like a spy agency

In September 2026, Anthropic published a threat intelligence report on misuse of its Claude models between December 2025 and August 2026. One case shows the shift more clearly than any other.

Anthropic tracked a sustained espionage operation, run by Chinese-speaking operators in Hunan province. Some of its members were identified as undergraduate students.

Using Claude, the group ran intrusion attempts against live production systems. It probed foreign government networks across the Middle East, Europe and Southeast Asia, and researched weaknesses in major endpoint security products. Around 50 organisations were targeted across education, retail, energy, healthcare, finance, manufacturing and government.

The group also ran what Anthropic called an autonomous vulnerability research program. With little ongoing human direction, it produced working exploits for previously unknown flaws in network and security appliances.

Anthropic’s conclusion was blunt. AI has closed the labour and tooling gap that once separated well-funded state operations from individual operators.

The same report described dozens of other groups. At one end, AI acted as a chat assistant helping write malware or phishing kits. At the other, operations ran largely on their own, attacking several victims in parallel for hours or days at a time.

One hacker, 100 targets, five days

Two cases uncovered by Israeli security firm Gambit Security tell the same story with other AI tools.

In September 2026, a single Chinese-speaking hacker with no known crew combined the Chinese models DeepSeek and Kimi with an older version of Claude. Over five days the hacker targeted up to 100 organisations and compromised at least 27 of them, taking more than 600,000 credit card records. The total cost was reportedly around US$8,000.

Victims reportedly included a US hospitality group turning over more than US$10 billion a year, a major US airline and a billion-dollar online fashion retailer. What stood out to Gambit was volume rather than sophistication. The AI worked out a different attack path for each target, work that once took a skilled operator real time.

A few weeks earlier, Reuters reported that a Russian-speaking ransomware group called Aur0ra had used Cursor to breach at least seven companies across six countries. Cursor is the AI coding assistant now owned by SpaceX, and its agent was running Anthropic’s Claude Sonnet 4.5. Victims included a Belgian chemicals manufacturer and a German garage door maker.

The hackers told the agent the intrusions were a “security simulation”. That cover story was usually enough to get it to comply.

One detail matters for every business. In these cases the attackers already held stolen credentials or another way in. The AI didn’t break down the front door. It made the most of a door that was already open.

Neither case needed a nation-state’s level of resources. Each only needed a plausible story, a willing tool and a weak point to start from.

Eight hours for skilled people, less than an hour for AI

RAND Corporation put this to the test. In 2025, it gave human participants, some with real cyber security backgrounds, AI chatbots and eight hours to solve a set of security challenges. The chatbots made little real difference. Most participants struggled, and the harder challenges stayed out of reach.

RAND then re-ran the same challenges using Claude Code, an AI agent rather than a chatbot. Every challenge was solved in under an hour with little guidance, for a total cost under US$20. RAND concluded it is reasonable to assume “many unpatched systems can be exploited by unskilled novices very soon, if not now.”

Former senior FBI cyber official Cynthia Kaiser, now at security firm Halcyon, made the same point at the RSA Conference in March 2026. She argued the near-term threat isn’t sophisticated state use. It is the novice who uses AI to punch well above their skill level.

These attacks aren’t always competent. Kaiser described one ransomware group whose AI-built attack chain had no way to decrypt the files, locking the attackers out of their own ransom. Even half-broken attacks still do real damage, and she expects their volume to rise sharply.

When a security update becomes a hacker's guide

There is a second problem, and it matters for any business running everyday software such as WordPress. Once a flaw is disclosed, AI can turn that disclosure into a working attack faster than many defenders can patch. Once one working exploit exists, copying it takes no AI breakthrough at all.

In July 2026, Adam Kues of Searchlight Cyber pointed OpenAI’s GPT-5.6 Sol Ultra at a clean copy of the WordPress source code. He asked it to find a way to take full control of a site without logging in, then let it run for around ten hours.

The AI chained two flaws, CVE-2026-63030 and CVE-2026-60137, into a working exploit now known as wp2shell. It worked against a standard WordPress install with no plugins at all. Kues said no security researcher could have found and finished the chain in ten hours without AI.

WordPress forced automatic updates to get ahead of it. That is where the second half of the problem began. Researchers reverse engineered the patch, proof-of-concept code began circulating, and public exploit activity started within hours. Security firms then tracked waves of attacks against sites that hadn’t yet updated.

None of those follow-on attackers needed a frontier AI model or ten hours of compute. Once the details were public, copying the attack was far easier than discovering it. The hard part only had to happen once.

The lesson for business owners is simple. The moment a vendor advisory, patch or research write-up is published, the clock starts. AI can shrink the time from disclosure to working attack from weeks to hours, and less skilled attackers pick it up almost immediately.

A voice you trust is now an attack tool

For most Australian businesses, the most visible AI threat right now involves no exploit at all. It uses a voice you trust.

AI voice cloning has moved from novelty to everyday fraud tool. A few seconds of audio from a video, podcast or voicemail can be enough for a convincing clone. Paired with caller ID spoofing and an urgent story, it can push a finance team into an unauthorised transfer.

Australians reported $2.18 billion in scam losses in 2025, up 7.8 per cent on 2024. Payment redirection scams alone accounted for $166.8 million. The ACCC has named AI as one of the forces making scams more sophisticated.

The old tells, such as a robotic tone or awkward pauses, are no longer reliable. What still works is watching the behaviour around the call. Be wary of pressure to act now, requests for secrecy, unusual payment methods or instructions not to check with anyone else. The warning sign has moved from the voice to the pressure wrapped around it.

It’s not all bad, AI is on the defenders' side too

The same technology helping attackers is also making defence faster and smarter. Modern security tools use AI to spot unusual behaviour across networks, email and devices in real time, often before a person would notice anything wrong.

AI also helps defenders find and fix weaknesses sooner. The wp2shell flaw itself was found by a researcher using AI and reported responsibly so it could be fixed. WordPress then pushed forced updates that protected a very large number of sites before attackers reached them.

The difference is who is using it. Businesses with modern, well-managed defences get AI working for them around the clock.

What this means for your business

None of this makes skilled attackers less dangerous. The same tools that help a novice also make an expert faster. For most small and mid-sized organisations, though, the real shift is volume.

ASD’s Annual Cyber Threat Report 2024-25 recorded more than 84,700 cybercrime reports and over 1,200 incidents responded to, an 11 per cent rise. The average self-reported cost of a cybercrime for a small business rose 14 per cent to $56,600. Those figures largely predate the AI-driven cases above.

The threat for most businesses is no longer one skilled group targeting them by name. It is a much larger crowd, most without deep technical skill, who can now take a credible shot at any target. Some of them will get lucky.

Well-defended organisations still filter out most unsophisticated attempts. The ones caught out are usually still assuming an attacker needs real expertise to do real damage.

Be aware, not alarmed

You don’t need to become a security expert. You need the right basics in place and the right people in your corner.

The controls that mattered before AI still matter now. What has changed is the odds, not the fundamentals.

References

Anthropic. (2026, September). Disrupting malicious uses of AI: Threat intelligence report, September 2026. https://www.anthropic.com/threat-intelligence-report-september-2026

Australian Competition and Consumer Commission. (2026, March). Continued action critical to combat fraud as annual scam losses exceed $2 billion. https://www.accc.gov.au/media-release/continued-action-critical-to-combat-fraud-as-annual-scam-losses-exceed-2-billion

Australian Government, Minister for Defence. (2025, October 14). Annual Cyber Threat Report highlights persistent threat to individuals and across the Australian economy. https://www.minister.defence.gov.au/media-releases/2025-10-14/annual-cyber-threat-report-highlights-persistent-threat-individuals-across-australian-economy

Brewster, T. (2026, September 22). A Chinese hacker used AI to attack 100+ companies in one of largest AI hacks yet. Forbes. https://www.forbes.com/sites/thomasbrewster/2026/09/22/huge-cyberattack-uses-anthropic-and-deepseek-ai-to-target-100-companies/

CP24 (Reuters). (2026, August 27). Russian-speaking cybercriminals used SpaceX’s Cursor AI tool to hack seven companies. https://www.cp24.com/news/world/2026/08/27/russian-speaking-cybercriminals-used-spacexs-cursor-ai-tool-to-hack-seven-companies-reuters-exclusive/

Cybernews. (2026, September). Hacker steals 600,000 credit cards while barely lifting a finger. https://cybernews.com/security/ai-assisted-hacker-steals-thousands-credit-cards-compromises-companies/

Cybersecurity Dive. (2026, March 23). AI poised to help low-skilled hackers in the near term. https://www.cybersecuritydive.com/news/ai-cybercrime-ransomware-low-skilled-boost/815498/

eWeek. (2026, June 8). AI voice-cloning scams put Australian households and businesses on alert. https://www.eweek.com/news/ai-voice-cloning-scam-australia-apac/

Kues, A. (2026, July 17). WP2Shell: Pre-authentication RCE in WordPress core. Searchlight Cyber. https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core/

Kues, A. (2026, July 20). Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6. Searchlight Cyber. https://slcyber.io/research-center/exploit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6/

National Anti-Scam Centre. (2026, March). Targeting scams: Report of the National Anti-Scam Centre on scams data and activity 2025. https://www.nasc.gov.au/system/files/targeting-scams-report-2025.pdf

OODA Loop. (2026, August). Ransomware operator ran Cursor agent inside ten victim networks. https://oodaloop.com/briefs/cyber/ransomware-operator-ran-cursor-agent-inside-ten-victim-networks/

RAND Corporation. (2026, June 25). AI agents put offensive cyber within reach of novices: Comparing the performance of AI agents to humans in offensive cyber operations. https://www.rand.org/pubs/research_reports/RRA3892-2.html

The Hacker News. (2026, August). Aurora ransomware operators use Cursor. https://thehackernews.com/2026/08/aurora-ransomware-operators-use-cursor.html

The Hacker News. (2026, September 11). Claude used to automate exploitation and data theft across multiple victims. https://thehackernews.com/2026/09/claude-used-to-automate-exploitation.html

University of Queensland News. (2025, November 11). Anyone can be a hacker with AI, so what does that mean for the cyber defence industry? https://news.uq.edu.au/2025-11-anyone-can-be-hacker-ai-so-what-does-mean-cyber-defence-industry

Wiz Research. (2026, July 20). Exploitation in the wild of wp2shell. https://www.wiz.io/blog/wp2shell-cve-2026-63030-cve-2026-60137

Wordfence. (2026, July). wp2shell aftermath: The first critical unauthenticated WordPress core RCE in nearly a decade. https://www.wordfence.com/blog/2026/07/wp2shell-aftermath-the-first-critical-unauthenticated-wordpress-core-rce-in-nearly-a-decade/

Previous Post

Cyber can be complex, but fixing it doesn’t have to be.

Company

Payment Details

Financial Institution: NAB
Account Name: FocusNet Pty Ltd
BSB: 086 217
Account Number: 344061739

Credit Card and Direct Debit payments are available upon request.

If you have any questions or concerns, we are here to assist you. Please don’t hesitate to reach out to us, as we are more than happy to provide you with additional information and address any queries you may have.

Edit Template

© 2025 FocusNet Technology | ABN 30 606 250 006 

Payment Details

Financial Institution: NAB
Account Name: FocusNet Pty Ltd
BSB: 086 217
Account Number: 344061739

Credit Card and Direct Debit payments are available upon request.

If you have any questions, please don’t hesitate to contact us at [email protected] or call 1300 077 777.