AI is making cyberattacks faster and harder to detect, Interpol warns. Here’s what companies should watch
- ID
- 31024
- Status
- summarized
- Published
- 02 Oct 2026, 12:57 PM
- Fetched
- 02 Oct 2026, 1:17 PM
- Provider
- CNBC Technology
- Category
- technology
- Original URL
- https://www.cnbc.com/2026/10/02/interpol-cyberattack-cyberthreat-agentic-ai.html
- Source URL
- https://www.cnbc.com/id/19854910/device/rss/rss.html
Summary
- Score
- 4.5
- Created
- 02 Oct 2026, 1:18 PM
- Tags
- Audience
- developersai_agent_userssaas_founders
What happened
INTERPOL global CISO Bjorn R. Watne told CNBC at Tech Week Singapore that AI is an "evolution and not a revolution" in cybercrime — it accelerates existing scams and fraud rather than inventing new categories, letting operators target many victims at once while better translation and synthetic digital identities make fraudulent interactions harder to tell apart from real ones. Watne said agentic AI adds new risk because those systems gain greater access and the ability to act on a user's behalf, and advised companies to first identify their "crown jewels" — the assets most critical to operations — and tailor defenses to who would want to steal them. The piece carries no incident data, statistics, or named tooling.
Why it matters
If you ship an AI agent with write access — payments, email, account changes, database writes — the specific warning here is about agents acting for users, not about better phishing text. The practical decision is scoping: give each agent the narrowest credential set that still does the job, and log every action it takes on a user's behalf, because detection of an impersonated human is getting harder. Note the piece gives no numbers or threat intel to act on, so treat it as a framing prompt for your own permission review, not as a source of new controls.
Discussion angle
Ask everyone shipping an agent: what is the worst single action your agent could take if prompted wrong, and does it currently have the credentials to do it? Compare against the "crown jewels" framing — most teams secure the database and forget the agent's API token.