AI Agents’ ‘Alarming’ Hacking Skills Trigger Cybersecurity Spending Rush

AI Agents

AI Agents’ ‘Alarming’ Hacking Skills Trigger Cybersecurity Spending Rush accelerate spending on cybersecurity as the potential threat moves from science fiction towards reality.

Unlike traditional AI chatbots, autonomous agents can plan tasks, use tools, inspect computer systems and adapt their behaviour when something goes wrong.

AI criminal activity

Recent testing has shown that leading AI systems can successfully exploit real-world software vulnerabilities, raising concerns about what could happen when similar capabilities fall into the hands of criminals.

The concern is not simply that AI can write malicious code. Agents can potentially automate large parts of the attack process, from identifying weaknesses and gathering information to attempting exploitation and moving through compromised systems.

That dramatically changes the economics of cybercrime by allowing attacks to be conducted faster and at much greater scale.

Protection

Security experts are therefore warning companies to rethink how they protect systems that increasingly interact with AI.

AI Agents may have access to sensitive information, internal networks and business applications, effectively giving them privileges that could become dangerous if misused or compromised.

The financial response is already gathering momentum. Research reportedly suggests that around 96% of senior security leaders regard AI-enabled attacks as a significant threat, while the proportion of organisations expecting to devote at least a quarter of their cybersecurity budgets to AI-related protection is projected to rise sharply.

Security spend

Estimates that spending specifically designed to secure AI agents could reach around 15% of enterprise cybersecurity budgets within three years.

The irony is difficult to miss: AI is creating a new generation of cyber threats while simultaneously becoming one of the most important tools for defending against them.

The cybersecurity industry could be heading for a major investment boom — because businesses increasingly fear that the next hacker knocking on the digital door may not be human.

Jaguar Land Rover Cyber Attack: A digital siege on Britain’s automotive crown

JLR hacked

On 31st August 2025, Jaguar Land Rover (JLR), one of Britain’s most iconic automotive manufacturers, was struck by a crippling cyber-attack that forced an immediate halt to production across its UK facilities.

The incident, described by MP Liam Byrne as a ‘digital siege’, has since spiralled into a full-blown supply chain crisis, threatening thousands of jobs and exposing vulnerabilities in the nation’s industrial backbone.

The attack, believed to be a coordinated effort by cybercrime groups Scattered Spider, Lapsus$, and ShinyHunters, targeted JLR’s production systems, rendering them inoperable.

By 1st September, operations were suspended, and by 22nd September 2025, the shutdown had extended to three weeks, with staff instructed to stay home.

A forensic investigation is ongoing, and JLR has delayed its restart timeline until 1st October 2025.

The toll

The financial toll is staggering. Estimates suggest the company is losing £50 million per week. With no cyber insurance in place, JLR has been left scrambling to stabilise its operations and reassure its extensive supplier network—comprising over 120,000 jobs, many in small and medium-sized enterprises.

In response, the UK government has stepped in with a £1.5 billion loan guarantee, backed by the Export Development Guarantee scheme.

This emergency support aims to shore up JLR’s cash reserves, protect skilled jobs in the West Midlands and Merseyside, and prevent collapse among its suppliers.

Business Secretary Peter Kyle and Chancellor Rachel Reeves have both emphasised the strategic importance of JLR to Britain’s economy, calling the intervention a ‘decisive action’ to safeguard the automotive sector.

The cyber attack has also prompted broader questions about industrial cybersecurity, insurance preparedness, and the resilience of supply chains in the face of digital threats.

Unions have urged the government to ensure the loan translates into job guarantees and fair pay, while cybersecurity experts have called the scale of disruption ‘unprecedented’ for a UK-based manufacturer.

🔐 Ten Major Cyber Attacks of 2025

#TargetDateImpact
1️⃣UNFI (United Natural Foods Inc.)JuneDisrupted food supply chains across North America; automated ordering systems collapsed.
2️⃣Bank Sepah (Iran)March42 million customer records stolen; hackers demanded $42M in Bitcoin ransom.
3️⃣TeleMessage (US Gov Messaging App)MayMetadata of officials exposed, including FEMA and CBP; triggered national security alerts.
4️⃣Marks & Spencer (UK)April–MayRansomware attack led to 46-day online outage; £300M profit warning.
5️⃣Co-op (UK)MayIn-store systems crashed; manual tills and supply chain breakdowns across 2,300 stores.
6️⃣Mailchimp & HubSpotAprilCredential theft and phishing campaigns; fake invoices sent to thousands.
7️⃣HertzAprilGlobal breach with unclear UK impact; customer data compromised.
8️⃣Anonymous Data LeakJanuary18.8 million records exposed; no company claimed responsibility.
9️⃣Microsoft SharePoint ServersOngoingExploited by China-linked threat actors; widespread “ToolShell” compromises.
🔟Ingram Micro (IT Distributor)JulyRansomware attack by SafePay group; disrupted global tech supply chains.

As JLR works with law enforcement and cybersecurity specialists to restore operations, the incident stands as a stark reminder: in the digital age, even the most storied brands are vulnerable to invisible adversaries.

Other prominent recent major cyber attacks

#Attack NameTargetImpact
1️⃣Change Healthcare RansomwareU.S. healthcare systemDisrupted nationwide medical services; $22M ransom paid3
2️⃣Snowflake Data BreachAT&T, Ticketmaster, Santander630M+ records stolen; MFA failures exploited3
3️⃣Salt Typhoon & Volt TyphoonU.S. telecom & infrastructureEspionage targeting political figures & critical systems3
4️⃣CrowdStrike-Microsoft OutageGlobal IT servicesMassive disruption due to botched update
5️⃣Synnovis-NHS RansomwareUK healthcare labsHalted blood testing across London hospitals
6️⃣Ascension Ransomware AttackU.S. hospital chainPatient care delays; data exfiltration
7️⃣MediSecure BreachAustralian e-prescription providerSensitive medical data leaked
8️⃣Ivanti Zero-Day ExploitsGlobal VPN usersNation-state actors exploited vulnerabilities
9️⃣TfL Cyber AttackTransport for LondonInternal systems disrupted; public services affected
🔟Internet Archive AttackDigital preservation siteAttempted deletion of historical records