06/26/2026
The automation built to scale became the breach.
2,388 organizations learned this recently.
The technique has a name now. Agentjacking.
No phishing link required. No credential theft. No social engineering.
The attack intercepts the AI agent itself.
The agent does what the agent was designed to do.
The attacker does the same.
Traditional defense assumes a human decision point exists somewhere in the chain. Someone hovers over a link. Someone reads an email. Someone approves a transfer.
The entire security model depends on human friction.
Agents eliminate all of those checkpoints.
The agent receives an instruction.
The instruction was poisoned upstream.
The agent executes at machine speed across every system with access.
The exposure scales with deployment. Every new integration expands the surface. Every new permission creates entry points. Every workflow handed to an agent multiplies access vectors.
Companies measured this as productivity gains. Attackers measured this as infrastructure access.
The agents were not hacked.
The agents worked correctly.
The instructions the agents followed were the breach.
Most AI deployments treat security as a configuration setting on a productivity tool. The framing is obsolete.
An agent with credentials, API access, and ex*****on authority is infrastructure. Govern the agent as infrastructure.
The 2,388 number will grow. Quietly.
Most of these breaches will not be announced for months. The affected organizations are still mapping what the agents touched.
Companies deployed agents in the last 18 months without auditing permission scope. Without logging instruction sources. Without tracking ex*****on patterns.
Those companies have live exposure right now.
Run the audit before the next deployment goes in.
Comment infrastructure if your team has stopped treating agents as tools.