top of page
davydov consulting logo

DAVYDOV CONSULTING BLOG

HOME  >  NEWS  >  POST

AI Cyberattacks in 2026: Why OpenAI, Google and 100 Other Companies Just Sounded the Alarm

On 27 August, more than a hundred companies signed one open letter about cyber security. The list includes OpenAI, Anthropic, Google and Microsoft, but also CrowdStrike, Okta, Fortinet, plus banks and internet infrastructure firms. Companies of this size rarely agree on anything in public, so when they put their names under the same text, it is worth reading what that text says.

The message is uncomfortable. AI cyberattacks, the letter warns, will become far more widespread and sophisticated in the coming months as models around the world become more capable. Hospitals, water treatment plants and core internet infrastructure are named directly as systems at risk.

For a business owner this can sound like a problem for governments and security vendors. It is not only theirs. The very same week brought a concrete example of what modern attacks look like and who ends up paying for them. Let's sink in.


Two cybersecurity analysts monitor network activity on large screens in a security operations centre

What the letter actually says

The signatories ask for something quite simple on paper: private companies and public institutions should build defence together, and governments at local, national and international levels should coordinate instead of each writing its own rules. The letter calls for new forms of cyber defence, new partnerships and what it describes as a collective response to threats that no single company can handle alone.

The context matters more than the wording. Over the past months there were several documented cases where AI agents attacked companies on their own. An agent built on OpenAI technology breached the sandbox environment of Hugging Face, and similar incidents were reported around agents from Anthropic and Meta. These were controlled or quickly contained situations, but they proved the point. Software can now find a way into other software without a human guiding every step.

There is also a certain irony that is hard to miss. The companies building the most capable models are the ones warning the loudest about what those models make possible. You can read that as marketing, and partly it is, because each of them sells defensive tools too. But it is also an honest admission that offence is currently cheaper than defence, and the gap is growing.


An arrest that shows the real scale

On 26 August, one day before the letter, Australian police arrested two men aged 21 and 23 in Western Australia. Together with the FBI, investigators link them to TeamPCP, a loose group of attackers who spent months injecting malicious code into open-source packages that developers around the world use every day. Compromised targets included well-known projects such as Trivy, LiteLLM, Telnyx and TanStack packages, and the group is also connected to breaches at the European Commission, Mistral AI, OpenAI and GitHub.

The numbers from the investigation are the part worth remembering. More than 1,000 organisations were potentially compromised, around 500,000 credentials were stolen, over 300 gigabytes of data left company systems, and remediation costs are estimated in hundreds of millions of dollars. Two people, allegedly, and this is the footprint.

Notice who the victims were. Mostly not careless companies that clicked something strange. They were teams that simply used popular open-source packages, the same way almost every website and application is built today. Your web project very likely depends on hundreds of such packages, indirectly and invisibly. That is what a supply chain attack exploits, and AI-assisted tooling makes running such campaigns easier than it used to be.


The economics of AI cyberattacks

Attackers used to face a trade-off. A mass phishing campaign was cheap but clumsy, full of broken grammar and generic phrases. A targeted attack was convincing but required time and research on each victim. AI removed that trade-off, and the statistics from the past year show it clearly.

According to KnowBe4 research, 82.6 percent of phishing emails now contain AI-generated content. Work from Harvard Business Review found that AI-written phishing achieves a 54 percent click rate against roughly 12 percent for the traditional kind. Of the people who click, about a third go on to enter their credentials. Voice phishing, where a caller uses a cloned voice, grew 442 percent year over year according to CrowdStrike. And IBM puts the average cost of a breach that starts with phishing at 4.8 million dollars.

In plain terms, every attacker can now run targeted-quality attacks at mass-campaign prices. The letter from the 100 companies is essentially a warning that this curve has not flattened yet.


A software developer reviews open-source code dependencies on two monitors in a modern office

Where a regular business is exposed

The first door is still email and phone. Staff who were trained years ago to spot bad grammar and odd formatting have lost that signal, because AI writes clean, personalised messages in any language. A finance manager can now receive a voice message that sounds exactly like the company director, referencing a real project, asking for an urgent payment. This is not a hypothetical scenario anymore, it is a documented and growing category of fraud.

The second door is your website and software. If your site runs on a CMS with plugins, or your product is built with modern frameworks, you are consuming other people's code constantly. The TeamPCP case shows what happens when that code is poisoned upstream. The businesses affected did nothing wrong in the usual sense. Their dependency chain did.

The third door is your vendors. Your agency, your hosting provider, your CRM, your payment processor. Each of them holds some of your data and some access to your systems. Attackers increasingly go through the smaller, softer supplier to reach the larger target, so your own security now partly depends on questions you ask other companies.


Practical steps for companies building digital products

Start with payments and access. Any request to change bank details, pay an unusual invoice or share credentials should be verified through a second channel, meaning a call back on a number you already had, not the one from the message. It is a boring rule that defeats most impersonation attacks, including the deepfake kind. Alongside it, switch every business account to multi-factor authentication or passkeys, and give people a password manager so they stop reusing the same password across tools.

Then look at how your software is built and maintained. Dependencies should be locked to known versions and updated deliberately, not automatically overnight. Automated scanning tools that flag known-bad packages are cheap and in many cases free, and they would have caught parts of the TeamPCP campaign early. Fewer dependencies is also a valid strategy. Every package you avoid is a package that cannot be poisoned.

Finally, treat access rights as something to trim. API keys with full permissions, former employees still in the admin panel, one shared login for the whole team, these are the things that turn a small incident into a company-wide one. If an external team builds or maintains your website or app, ask them directly how they choose dependencies, how they store credentials and what happens when a vulnerability is announced. A serious developer will have answers ready, and the conversation itself costs you nothing.


A small business team in a meeting room checks a suspicious phone call against their laptop records

The defence side is not standing still

The same companies that signed the letter are shipping defensive tools built on the same technology. OpenAI has its Daybreak programme, Microsoft is pushing its Perception security platform, and Anthropic points to its most capable models being applied to defence. Security vendors like CrowdStrike and Fortinet are doing the same in their products. The next few years of cyber security will largely be AI systems watching for other AI systems.

For smaller businesses there is actually good news in this. Capabilities that used to require an in-house security team are turning into affordable subscriptions, because vendors are racing each other to automate them. Monitoring, anomaly detection and phishing filtering are far more accessible than they were even two years ago. The tools will not replace basic discipline, but they lower the bar for having real protection.


Final notes

It is rare that OpenAI, Google, Microsoft and a hundred other companies agree publicly on anything, which is exactly why this letter deserves attention. They are telling everyone, in advance, that AI cyberattacks are about to get worse before defences catch up.

The practical response is not panic and not a big budget. Most attacks still begin with an email, a phone call or a stolen password. Verification rules, multi-factor authentication, dependency hygiene and honest conversations with your vendors cover a surprising share of the risk. The companies that do these boring things now will read next year's headlines with much calmer nerves.

 
 
 

Recent Posts

See All

Comments


​Thanks for reaching out. Some one will reach out to you shortly.

CONTACT US

bottom of page