Frontier AI Slashes Cost of Cyberattacks, Ensign Warns

Frontier artificial intelligence models are now capable of executing multiple stages of a realistic enterprise cyberattack, according to a new report from Ensign InfoSecurity, Asia Pacific’s largest pure-play cybersecurity services provider. The findings suggest offensive cyber capabilities are becoming more accessible as AI lowers the cost, time and expertise once needed to mount sophisticated attacks.

The assessment, part of the seventh edition of Ensign’s 2026 Cyber Threat Landscape Report, tested 10 generally available frontier AI models against eight attacker objectives in a proprietary AI Cyber Range. Three models — OpenAI‘s GPT-5.6 Sol, Anthropic‘s Claude Opus 4.8 and Z.AI‘s GLM-5.2 — achieved high success in seven of the eight objectives. Gaining initial access, the report found, was a trivial task across nearly all models tested.

Cost, not capability, may soon decide who attacks

Performance is converging across Eastern and Western models, Ensign said, with GLM-5.2 matching GPT-5.6’s offensive performance at roughly a fifth of the operating cost. Open-source Eastern models consistently delivered higher capability per dollar spent. Existing defences still create friction, however: at least half the models tested struggled to steal credentials and move laterally between systems, and none could confidently evade detection tools.

“Leading frontier AI models are already capable of executing multiple stages of a cyberattack chain more quickly and at a lower cost. The threat is further intensified as the capability gap between models continues to narrow, and cost may soon cease to be a barrier for threat actors,” said Xiang Zheng Teo, Vice President of Advisory, Ensign InfoSecurity.

Singapore data theft value triples since 2023

The report also charts how the wider Asia Pacific threat landscape is shifting as AI becomes a force multiplier for existing attack techniques rather than a replacement for them:

  • Ransomware activity doubled across ASEAN in 2025, while Australasia and East Asia saw increases of more than 600% and 400% respectively
  • A stolen Singaporean “Fullz” identity package now fetches USD 95 on underground markets, more than three times its USD 30 value in 2023
  • ASEAN recorded the region’s highest level of hacktivist activity at 19.1%, with targeting expanding beyond government to utilities, energy, transport and telecoms operators

Data theft is increasingly overtaking encryption as the primary driver of cyberattacks, the report noted, with edge devices, remote access infrastructure and third-party suppliers remaining common entry points.

“Organisations should strengthen their cybersecurity foundations by prioritising the scanning and patching of critical internet-facing assets and continuously validating their defences against the latest AI models. With frontier AI capabilities advancing on a roughly two-month cycle, security controls cannot afford to remain static,” said Xiang Zheng Teo, Vice President of Advisory, Ensign InfoSecurity.

Now in its seventh edition, the Cyber Threat Landscape Report draws on Ensign’s regional cybersecurity operations, threat intelligence, incident response engagements and international collaborations to track evolving threat actors and risks across Asia Pacific.

Author


Discover more from techcoffeehouse.com

Subscribe to get the latest posts sent to your email.

Use promo code “TCH15” to get 15% off on checkout.

Share your thoughts

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from techcoffeehouse.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from techcoffeehouse.com

Subscribe now to keep reading and get access to the full archive.

Continue reading