Ensign finds frontier AI can execute most stages of enterprise cyberattacks
Ensign's 2026 report reveals frontier AI can run enterprise cyberattacks, as ransomware spikes across Asia Pacific and threat actors target critical systems.
Frontier artificial intelligence models can already complete multiple stages of a realistic enterprise cyberattack, potentially reducing the time, technical expertise and financial resources required to execute sophisticated campaigns. According to research from Ensign InfoSecurity in the seventh edition of its 2026 Cyber Threat Landscape Report, the cybersecurity provider evaluated ten generally available frontier AI systems within an AI Cyber Range Assessment. Among the tested systems, OpenAI’s GPT-5.6 Sol, Anthropic’s Claude Opus 4.8 and Z.AI’s GLM 5.2 achieved high success across seven of eight attacker objectives.
Table Of Content
Operating expenses varied considerably between models exhibiting comparable offensive capabilities. Z.AI’s GLM-5.2 delivered performance on par with GPT-5.6 at roughly one-fifth of the operating cost, while open-source Eastern models consistently achieved higher capability per dollar throughout Ensign’s testing.
Internal security controls still slow attacks
While the tested systems performed well at gaining initial access to simulated environments, their reliability degraded as they attempted to advance through the attack chain. At least half of the evaluated models struggled to steal credentials and move consistently between systems. These findings indicate that segmenting networks, establishing clear trust boundaries and restricting lateral movement make it significantly harder for an AI-assisted attacker to progress after an initial breach.
Detection presented another substantial obstacle for the automated systems. None of the ten models could confidently evade defensive detection tools, with even the top-performing systems recording only partial success. This demonstrates that established internal controls can still interrupt AI-assisted intrusions, making strict movement restrictions and effective detection capabilities vital as offensive automation expands.
The rapid evolution of these tools requires security teams to re-evaluate their operational resilience. “Leading frontier AI models are already capable of executing multiple stages of a cyberattack chain more quickly and at a lower cost. The threat is further intensified as the capability gap between models continues to narrow, and cost may soon cease to be a barrier for threat actors. Frontier AI is fundamentally changing the speed, scale and economics of cyberattacks, requiring organisations to rethink how they assess cyber risk and resilience,” said Xiang Zheng Teo, Vice President of Advisory at Ensign InfoSecurity.
Ransomware and data theft increase across Asia Pacific
Drawing upon Ensign’s regional cybersecurity operations, incident response engagements, threat intelligence and international collaborations, the broader assessment recorded elevated ransomware activity across several parts of Asia Pacific. Ransomware activity doubled across ASEAN in 2025, with the region targeted by all 18 leading ransomware groups analysed in the report. Over the same period, Australasia witnessed an increase of more than 600%, while East Asia saw incidents rise by more than 400%.
Ensign discovered that threat actors are employing AI to accelerate reconnaissance, uncover exploitable flaws and generate more convincing phishing lures. In addition, attackers continue to leverage legitimate administrative tools already present within compromised networks, which makes malicious actions far harder to distinguish from everyday system activity. Exfiltration of sensitive records is also increasingly replacing system encryption as the primary motivation for attacks, with threat actors frequently breaching environments via edge devices, remote access infrastructure and third-party suppliers through vulnerabilities that have remained unpatched for years.
The illicit value attached to stolen records continues to climb across the region. In Singapore, Ensign placed the underground market price of a complete Singaporean Fullz identity package at US$95, more than triple the US$30 recorded in 2023.
Hacktivists widen their targets in ASEAN
ASEAN recorded the highest proportion of hacktivist activity among the three examined regions at 19.1%. Targeting expanded beyond public sector bodies to critical national infrastructure, including utilities, energy, transportation and telecommunications providers. Manufacturing and industrial organisations, banking, finance and insurance, alongside telecommunications, media and technology firms, remained among the most targeted sectors. Business and professional services were similarly pursued because they handle confidential information and deliver essential services to larger enterprises.
To withstand these intensifying campaigns, Ensign recommends prioritising the identification and patching of critical internet-facing assets while routinely testing security controls against newer AI models. Strong foundational defences and adaptive measures remain essential to maintaining operational integrity. “Organisations should strengthen their cybersecurity foundations by prioritising the scanning and patching of critical internet-facing assets and continuously validating their defences against the latest AI models. With frontier AI capabilities advancing on a roughly two-month cycle, security controls cannot afford to remain static. Agility and dynamism in cyber defence defines the good cyber defender from the rest.”







