← The Desk 2026-07-27 The Wire
The Perimeter Site

Three Hundred Ninety Seven Data Breaches This Week Reveal Persistence of Legacy Credential Theft

Ingrid Solheim
2026-07-27
# Three Hundred Ninety Seven Data Breaches This Week Reveal Persistence of Legacy Credential Theft The consensus on the wire this week is that we have reached the era of the autonomous breach. With 272 stories hitting the wire specifically regarding AI security, the narrative is neatly packaged: attackers are now using large language models to automate the reconnaissance phase, craft hyper-personalised phishing lures at scale, and write polymorphic code that evades traditional detection. The argument is that the human analyst is now obsolete, outpaced by a machine that doesn't sleep and doesn't make typos. If you read the press releases from the security vendors, we're no longer fighting people; we're fighting an industrialised intelligence. It is a seductive story. It justifies the sudden scramble for "AI-native" security stacks and the panic in boardrooms. It also makes the failure of a CISO look less like negligence and more like an act of God. However, if you follow the paperwork—the actual breach notifications and the regulatory filings—the picture is far more mundane. We saw 397 data breaches this week. That is the real number. When you strip away the adjectives and look at the root causes cited in the disclosure filings, the "AI revolution" vanishes. Most of these incidents weren't the result of a sophisticated autonomous agent; they were the result of someone using a password they've used since 2018 or a VPN gateway that hadn't been patched in six months. The machinery of regulation is slow, but it is honest. In Brussels, the focus remains on the 72-hour notification window under GDPR. When a firm files that notice, they don't usually write "we were outsmarted by a neural network." They write that an unauthorised party gained access via a compromised administrative account. The "AI-driven attack" is mostly a branding exercise for old-fashioned credential stuffing and social engineering. A phishing email that is grammatically correct because it was run through a translator isn't an autonomous attack; it's just a phishing email without typos. We've seen this cycle before. In the early 2010s, every single intrusion was labelled an "Advanced Persistent Threat" (APT). It sounded prestigious. It suggested a state-sponsored shadow war. In reality, most of those "APTs" were just criminals using off-the-shelf toolkits and exploiting the same three vulnerabilities that everyone had been told to patch for a year. The parallel breaks down only in the speed of the hype. The transition from "this is a niche tool" to "this is the only threat that matters" happened in months, not years. The strongest objection to my skepticism is the volume of the AI security discourse. One might argue that 272 stories in a single week cannot be mere noise; it must represent a tangible shift in the threat vector. But volume is not evidence of a shift in technique; it is evidence of a shift in marketing. If you're a vendor selling a security product, you cannot sell "better password hygiene" or "consistent patching" as a premium service. There is no margin in reminding a client to do the basics. There is, however, immense margin in selling an AI-powered defensive shield to protect against AI-powered attacks. By framing the threat as a futuristic, autonomous force, vendors can bypass the boring conversation about why the client's internal audit from last October was ignored. This leads to a second-order effect that is quietly devastating: the insurance market. Underwriters are not immune to the hype. When the narrative shifts toward "autonomous threats," insurance premiums for cyber coverage begin to pivot. We are seeing a trend where "AI-readiness" is becoming a prerequisite for lower premiums. The danger here is that firms will spend their limited budgets on expensive, shiny AI-detection tools to satisfy an insurer, while leaving the actual doors unlocked. They'll have a state-of-the-art AI sentinel guarding the front gate while the attackers are simply walking through a back door left open by a forgotten service account. Who benefits from this hype? Primarily the vendors and the consultants who get to rewrite the strategy slides every six months. It creates a perpetual loop of urgency that overrides the slow, patient work of regulation and governance. Who benefits if the crowd is wrong? The attackers. Criminals love it when their targets are looking for the "super-weapon." While the CISO is preoccupied with the theoretical risk of an autonomous agent infiltrating the network, the attacker is perfectly happy to spend three days on LinkedIn finding the name of a junior accountant's dog and using that to reset a password. I'll be watching the next round of filings from the Norwegian Data Protection Authority. They tend to be quite dry about how breaches actually happen. If we start seeing a genuine spike in breaches where the entry point cannot be explained by credential theft or known vulnerabilities, I'll change my mind. Until then, I suspect we're just paying a premium for a ghost story. For now, the most effective "AI defence" is still a long, complex password and a patch that actually gets installed. It's not an exciting narrative, and it doesn't make for a good press release, but it's the only thing that actually shows up in the audit logs.
◼
← More from the Desk Live Wire →

DISCLAIMER: Articles on this site are generated automatically from public security news feeds for educational and informational purposes. They may contain errors, and nothing here constitutes security, legal, or compliance advice. Verify details against original advisories and vendor bulletins before acting on them.