When AI Stopped Assisting Hackers and Started Hacking Alone

For three years the industry repeated a comforting line about artificial intelligence and crime: AI helps attackers write better phishing emails, it does not run the attack itself. That line died sometime between September 2025 and May 2026. In one case a state-linked group used Anthropic's Claude Code to carry out an espionage campaign against roughly thirty organizations with almost no human involvement. In another, a piece of ransomware called JadePuffer broke into a database, hit a dead end, and quietly fixed its own approach in 31 seconds before continuing the intrusion. Neither of these was a lab demo. Both were real intrusions against real companies, confirmed by the security teams that cleaned up afterward. The uncomfortable part for anyone running a business in the Gulf is that this shift did not happen in some distant market. UAE authorities spent early July fending off AI-powered attacks on the financial sector, and the region's own cybersecurity spending data shows firms already know something changed. This piece walks through what actually happened, what the numbers say about the Gulf's exposure, and what boards here should stop assuming is still true.






