Safety2 min read

Five Eyes Agencies: AI Cyberattacks Are Months Away

June 23, 2026Synthesized from 1 source: AI News

The intelligence agencies of the US, UK, Canada, Australia, and New Zealand issued a rare joint warning on June 22, 2026, stating that AI-powered cyberattacks capable of targeting businesses and governments are months away, and that every executive, not just IT teams, must treat this as a core business risk right now.

The Five Eyes joint statement published on June 22 is not a routine advisory. The signatories are the actual agency heads: from CISA and the NSA in the US, the NCSC in the UK, the ACSC in Australia, the CCCS in Canada, and New Zealand's NCSC. These organizations rarely issue joint public statements, and when they do, the specific wording matters. This one said: "The timeline is not years, it is months."

To understand what prompted that language, you need to know about two AI models that have been quietly reshaping the cybersecurity world since early 2026. Anthropic's Mythos was the first AI model to complete a 32-step simulated corporate network attack, end-to-end, in testing conducted by the UK's AI Security Institute: a test that would take a skilled human about 20 hours to complete. OpenAI's GPT-5.5-Cyber then matched that performance within weeks. Both models are currently accessible only to a small number of vetted security organizations, and the US government has blocked foreign access to them entirely, citing national security concerns.

The concern the agencies are raising is not that these specific models will be handed to criminals tomorrow. It is that once capabilities reach this level in frontier models, equivalent tools reach open-source and criminal networks within roughly 6 to 8 months. By the time you read this, the window is already narrowing.

For operators running any kind of business that relies on digital systems, meaning almost everyone, the practical shift is this: attacks that used to require a team of skilled hackers can now be automated. IBM's 2026 threat research found a 44% jump in attacks that began through publicly exposed applications, driven by AI-enabled vulnerability discovery. Ransomware attacks surged 42% in the first quarter of 2026 alone, with over 250 new criminal operators entering the market, many of them using AI tools they effectively rented.

The phishing threat has also changed in character. AI-generated phishing emails now achieve click rates roughly four times higher than traditional ones, because they are grammatically flawless and tailored to the recipient using publicly available information such as LinkedIn profiles or company websites. A phishing campaign that used to take a human team 16 hours to construct can now be built in about 5 minutes.

The Five Eyes agencies explicitly said that breaches will occur. Their message was not "prevent everything." It was: build your organization so that when a breach happens, it does not become an operational crisis. That means reducing the number of systems exposed to the internet, reviewing who inside your organization has access to what, and updating or removing legacy software that no longer receives security patches. The agencies also said that AI tools for defense, specifically tools that monitor for unusual activity and respond automatically, are now the most effective way to counter threats that move faster than human teams can.

One candid criticism came from independent cybersecurity advisors who noted that four of the five practical steps in the advisory would have applied just as well before AI existed. The advice is sound, but it is also a signal that most organizations have not done the basics. If you have old, unused accounts, software that has not been updated, or staff with access to systems they no longer need, those are your first priorities.

The statement also made clear, in language directed at boards and executives specifically, that cyber resilience is now a business continuity issue, not a technical one. Organizations that treat it as the IT department's problem will face "growing operational and strategic disadvantage," in the agencies' own words. That is not a technical warning. It is a governance one.

Stay informed

Get AI intelligence like this delivered to your inbox.