AI vs. AI: The New Cybersecurity Arms Race

As organizations across the supply chain adopt artificial intelligence (AI) to boost reliability, performance and resilience, they face dramatically expanding threats from malicious actors leveraging the tech to increase the speed, scale and adaptability of cyberattacks. But AI is also equipping cybersecurity teams with powerful new defensive weapons to thwart the bad guys. Here’s how AI is rewriting the supply chain cybersecurity playbook.

BY DAVID H. COBURN

WHEN MAD MAGAZINE started publishing “Spy vs. Spy” in 1961, the Cold War‑inspired cartoon was black comedy at its best, featuring White Spy and Black Spy, identical but for their color and allegiance to the leaders who assigned them tasks involving outlandish schemes to maim, torture or kill the enemy.

White Spy once used a microchip to trick Black Spy’s superior into thinking Black Spy was a threat and killing him by firing squad. Another time, Black Spy impersonated a therapist to gaslight White Spy into believing his enemy wasn’t real and threw a knife into his back after convincing him to drop his weapons.

Agents performing hostile acts under the direction of ideologically motivated human leaders? Leveraging technology designed as a force for good to achieve dastardly ends? Exploiting human psychology to pull off clever and deadly acts of deception?

If it sounds eerily familiar, welcome to cyberwarfare in the age of AI, where malicious actors are turning AI tools intended for benign uses into potent weapons and impersonating executives with AI‑generated “deepfake” emails, phone calls and videos to attack organizations’ data lifeblood. It’s spawning an arms race with defenders adopting AI‑native security solutions to fend off attackers.

In this new era of cybersecurity—call it “AI vs. AI”—the battle will be waged less by humans and more by AI agents, albeit in most cases agents directed by human supervision on both sides, as organizations respond to the exponential increase in the speed, scalability and adaptability of AI‑driven attacks.

“The attackers are now moving at machine speed, so we defenders have to move at machine speed, too,” said Mike Zachman, vice president and chief security officer for MHI member Zebra Technologies, which is using AI to transform how it protects data in its handheld computers and other devices.

Indeed, companies that aren’t beginning to deploy AI tools to combat rising AI‑driven cyberat‑tacks may find themselves in the position of bringing a knife to a gunfight, as Gartner’s “Top Strategic Technology Trends for 2026,” released earlier this year, makes clear.

“AI security platforms are starting to emerge as a critical pillar to defend against AI‑native security risks,” Gartner wrote. “Existing security architectures built around endpoints, identities and networks were never designed to handle threats like prompt injection, data leakage through LLMs, shadow AI or rogue agents making unauthorized decisions.”

A few data points paint a sobering picture of the growing cyber risks—including AI‑related threats—facing supply chain:

  • Supply chain‑related data breaches increased nearly 40% from 2023 to 2025, according to Cybersecurity Ventures, and AI has made attacks faster, easier to scale and smarter—able to adapt more readily to changes in a target organization’s cyber defenses.
  • Cyberattacks targeting logistics companies were projected to double in 2026, following several years of sharp growth, according to a report from Everstream Analytics, which tracks incidents affecting carriers, ports, 3PLs and other logistics providers.
  • Ninety‑seven percent of organizations surveyed for IBM’s “Cost of a Data Breach Report 2025” reported an AI‑related security incident and said they lacked proper AI access controls.
  • A World Economic Forum survey found 87% of CEOs identified AI vulnerabilities as an increasing cyber‑crime risk, with attackers increasingly able to use AI to manipulate Internet of Things (IoT) devices, compromise autonomous systems and exploit systemic weaknesses across distributed networks.
  • AI‑assisted malicious emails have doubled in the past two years and “deepfake” incidents involving impersonations of targeted executives now affect 35% of organizations, according to Gartner’s “Top Trends in Cybersecurity 2026,” published earlier this year.
  • Nearly 30% of cyber threats identified by the European Union Agency for Cybersecurity (ENISA) targeted operational technology (OT), reflecting growing exposure of industrial and critical systems or third‑party providers, showing attackers seeking indirect access to targets as supply chains become more digitally interconnected.
  • “Shadow AI”—the unauthorized use of public GenAI tools by employees—is surging, with more than 57% of employees using personal GenAI accounts for work purposes, and 33% admitting they input sensitive company information into unapproved tools, according to Gartner.

MHI member Körber Group has seen the total number of cyberattacks against the company increasing, according to Andreas Gaetje, executive vice president and chief information security officer. While “it’s not always clear whether it’s AI‑driven or not,” he said, it’s safe to infer that increases in certain cyber threats such as phishing emails are likely AI‑assisted because a single threat actor using AI agents can now mount a large‑scale campaign at virtually no cost that once took teams of elite hackers to pull off.

Recent data confirm Gaetje’s view: Large language models (LLMs)—the engines of AI platforms—are being leveraged to craft ever more convincing scam emails, with more than 80% of phishing emails using AI to some extent, according to ENISA’s Threat Landscape 2025 report on cyber risks across the EU.

SUPPLY CHAINS UNIQUELY VULNERABLE

Supply chain leaders are just beginning to come to grips with the reality that adding AI‑driven platforms to automate and optimize workflows and build agile, responsive, resilient and high‑performing supply chains has added increased risks of cyberattacks and data exposure, including techniques such as model poisoning during training and prompt‑injection attacks that can disrupt production.

Even before AI emerged as a serious cybersecurity threat over the past few years, the post‑pandemic push by companies to digitize operations already had created what University of Tennessee supply chain expert Seongkyoon Jeong describes as interconnected “chained vulnerabilities” and led cybercriminals to shift from targeting employees to exploiting suppliers and digital infrastructure.

Now, as companies scramble to unlock the benefits of AI in enterprise operations—often without fully vetting the risks—they’re expanding what cybersecurity pros refer to as the “attack surface” or points of entry available to cybercriminals, said Erika Voss, Ph.D., chief security officer for MHI member Blue Yonder.

“Whether it’s a warehouse, a transportation management system, a 3PL, or the ecosystem as a whole, everyone is looking at ways to modernize their supply chain, and AI is helping drive that progress from a technology perspective,” Voss said. “(But) as much as I love to adopt AI, I also have to play devil’s advocate because now it’s a weapon that could be used against me.”

“Once upon a time our attack surface used to be just making sure an IT system or a system in general was secure inside a data center,” Voss said. “Now it’s all things in the cloud, and when you add AI onto it, your attack surface has become this massive footprint.”

Supply chains are uniquely vulnerable due to the proliferation of data‑collecting IoT devices, autonomous mobile robots and other forms of increasingly AI‑enabled automation, exchanging information with internal enterprise systems and sharing data externally with suppliers, customers and other value chain partners that may or may not have adequate controls to protect data security.

Adding to the vulnerability inherent in modern supply chains is the widespread distribution of systems containing an organization’s data, which could be located anywhere from trucks on the highway to warehouses and distribution centers to customer sites.

“That makes it even harder to understand where the potential attack vectors are that you need to be aware of,” said Körber’s Gaetje, who wistfully recalls his job with an insurance company a few decades ago when all of the company’s data was on mainframes in a single building. “That was easier to oversee.”

And as the pandemic drove home, the importance of smoothly functioning supply chains to the global economy makes them a natural focus for cybercriminals and particularly hostile nation‑states intent on using cyberwarfare as a means of destabilizing geopolitical foes.

“Supply chain is a very, very attractive target to attackers because it’s an easy way to disrupt economies and entire societies,” Gaetje said, pointing to the most recent ENISA report showing cyberattackers increasingly targeting industrial operations and critical infrastructure as well as supply‑chain partners.

AI THREATS RAPIDLY EVOLVING

Awareness of the potential dangers of AI‑driven cyberattacks has spiked since September 2025, when state‑sponsored attackers launched what is considered to be the first reported AI‑orchestrated cyber campaign by exploiting Anthropic’s Claude Code, a developer tool designed to help programmers with coding tasks, and repurposing it as an autonomous cyber weapon.

With AI agents performing an estimated 80% to 90% of the operations, the attack succeeded in “jailbreaking” the AI model running Claude Code—a process of convincing the model to bypass guardrails designed to prevent harmful behaviors. Attackers were able to infiltrate some of the 30 targeted organizations worldwide, conducting reconnaissance, writing custom exploit code, harvesting credentials, moving laterally through compromised networks and stealing sensitive data.

While the attack raised the specter of more large‑scale autonomous cyberattacks leveraging AI’s agentic capabilities, the most immediate AI‑related challenge for defenders is the ability AI gives attackers to accelerate existing techniques, including reconnaissance, impersonation, access abuse and workflow execution, according to Netwrix, a provider of identity and data security solutions.

Cyberattacks come in a variety of forms but attackers typically seek entry into data systems by identifying and exploiting bugs in an organization’s software that allow them to compromise the target system and disrupt its functionality. The sheer speed at which attackers can gain entry using AI tools is breathtaking.

Click here to read the full article.

SUMMIT ART CREATIONS/SHUTTERSTOCK.COM