www.darkreading.com 9 Oct 2026, 13:00 UTC

AI Agents Could Become the Next Target for Business Email Compromise

CyberSIXT Evidence Panel Source marked as original reporting

THE piece warns that as AI agents are granted authority to act within core business systems, attackers could target those agents in a way that mirrors traditional business email compromise (BEC). In a BEC-like danger, an attacker might prompt a third‑party AI agent to change vendor details, redirect payments, or exfiltrate data by feeding malicious instructions into the agent’s input stream.

The consequence is that an action authorised by an AI agent—without a corresponding human intermediary—could be executed, with the attacker leveraging prompt injection and content manipulation to achieve financial or data‑theft goals.

Evidence cited includes industry observations and research indicating rising risk. Verizon’s 2026 Data Breach Investigations Report notes that third parties were involved in 48% of breaches, linked to increasing connections between AI applications and business platforms. The FBI IC3 reported roughly $3 billion in 2025 BEC losses, underscoring ongoing cost and frequency.

Security researchers from Palo Alto Networks Unit 42 identified 22 attacker techniques for AI‑agent payloads, while Check Point Research and OWASP GenAI Round‑up Report Q1 2026 describe a shift from theory to real‑world exploitation, focusing on agent identities, orchestration layers and supply chains.

The article emphasises that human awareness alone is insufficient; organisations must implement visibility, governance, and continuous monitoring of non‑human identities, plus guardrails, to reduce the risk of unauthorised or contextually inappropriate agent actions. It advocates tabletop exercises and a central inventory of agents, credentials, and access rights, with human verification for high‑risk actions and multi‑layer controls beyond mere authentication.

View full article

Article by CyberSIXT