Writing

When agents swarm, nobody is too boring to attack

·9 min read·Security

In February 2024, CISA, the NSA and the FBI published a joint warning that a Chinese state-sponsored group had been living inside US critical infrastructure. Communications, energy, transportation, water. In some networks they had been there, undetected, for more than five years.

They didn't steal anything. No data exfiltrated, no ransom demanded, no centrifuges spun to death. They moved in, learned the building, and waited.

The absence of theft was the operation. You don't burn five years of access on a smash and grab if the plan is to be able to turn off a city on the day someone decides it's time.

Now give that campaign a swarm of agents instead of a room full of expensive human operators.

What a swarm could not do until recently

Automated attack swarms have existed since 1988. The Morris worm took about ten percent of the internet with no human touching any of it. Mirai, in 2016, assembled a swarm of hijacked cameras and routers big enough to knock a chunk of the US east coast off DNS, and it got in by trying about sixty default passwords. It was written by college kids fighting over the Minecraft server protection racket.

Every one of those was a distributed multi-agent system with an objective. Nobody called them agents, because the word wasn't fashionable and because they were profoundly stupid. They were scripts. They ran the same play on machine one and machine four million. They could not tell a honeypot from a domain controller, could not change tactics when a door shut, could not look at what they had found and decide whether it mattered.

So defense got built to exploit exactly that stupidity. Signatures, because the payload repeats. Rate limits and baselines, because a script has a metronome where a human has a heartbeat. Choke points, because a script with one hardcoded check can be stopped at that check.

A swarm of agents breaks all three, because each unit in it can reason and because they divide the work between them. They specialize, coordinate, and change their minds.

The bill for the last fifteen years, paid in human hours

None of what follows involved AI.

Stuxnet, 2010. Four zero-days burned in one operation to make Iranian centrifuges tear themselves apart while the monitoring screens showed everything nominal.

Ukraine, December 2015. Attackers opened breakers at substations and left roughly 230,000 people in the dark, in winter. Operators sat in the control room and watched their own mouse cursors move across the screen, locked out of their own consoles. The following December a purpose-built grid malware did it again, largely without a human driving.

NotPetya, June 2017. A Russian military intelligence operation aimed at Ukraine through a compromised update to the accounting software every Ukrainian business used for taxes. Then it escaped, because that's what worms do. Maersk, which moves something like a fifth of the world's shipping containers, lost around 300 million dollars and rebuilt roughly four thousand servers and forty five thousand PCs in ten days. They managed it only because one domain controller in Ghana happened to be offline during the attack, thanks to a local power cut, and still held a clean copy of the company directory. Total damage is generally put near ten billion dollars, from a weapon pointed at a different country.

Colonial Pipeline, May 2021. Fuel for a large part of the US east coast, stopped by a criminal crew that got in through one leaked VPN password on an account with no multi-factor authentication. People queued at gas stations and filled plastic bags with gasoline.

Bangladesh Bank, 2016. Fraudulent SWIFT instructions worth 951 million dollars. 81 million got out before it unraveled, partly because one order misspelled "foundation" as "fandation" and tripped a human review, partly because the money was routed through a bank called Jupiter, which collided with the name of a sanctioned Iranian shipping company and lit up a screening system by accident.

Grid, shipping, fuel, banking, industrial control. Every single one needed something genuinely scarce: patient, senior, expensive operators who knew exactly what they were doing and had months to spend doing it.

That scarcity was the main thing protecting everyone else.

The constraint just died

In September 2025, Anthropic disrupted what it described as the first documented large-scale AI-orchestrated espionage campaign: a state-linked group pointing a swarm of agentic tooling at roughly thirty organizations, with something like eighty to ninety percent of the operational work running with no human in the loop. Reconnaissance, vulnerability discovery, credential testing, lateral movement, exfiltration, all parcelled out to subagents. The humans' main contribution was convincing the model it worked for a security firm doing authorized testing.

In June 2025, an autonomous pentesting system called XBOW reached number one on HackerOne's US bug bounty leaderboard, ahead of every human on the board.

In August 2025, DARPA's AI Cyber Challenge finished at DEF CON. The competing systems found 86% of the synthetic vulnerabilities planted across 63 projects and patched 68% of them with nobody driving, and turned up 18 real, previously unknown bugs in live open source on the side.

The scarce ingredient in every attack in the previous section was expert judgment, applied patiently over months. A swarm used to be cheap muscle wired to one human brain that could only be in one room at a time. Now the brain is the part that copies itself.

I've argued before that AI made building almost free, and that this is less of a gift than it looks, because everyone gets the same advantage in the same week. Security is where that stops being a cute argument about startups and becomes a national exposure. Capability that used to be rationed by talent is now rationed by spend.

Swarms killed triage, and triage was your real defense

When elite operator hours were scarce, attackers had to choose. A state agency with, say, two hundred capable people could run a handful of deep campaigns at a time, so arithmetic forced it to pick the highest-value targets and leave the rest alone. If you were the eleventh most interesting utility in Europe, you were protected by a queue.

Swarms delete the queue. A swarm runs the patient five-year residency campaign and the mass opportunistic sweep at the same time, across hundreds of targets, with specialized subagents for each phase and no fatigue, no turnover, no need to prioritize. Depth stops being a budget you spend on one target and becomes a default you apply to all of them.

So the question for a bank, a port, a regional grid operator or an insurer is no longer whether it is important enough to be targeted by this kind of adversary. Everyone is now inside the blast radius of a capability that used to be reserved for a shortlist.

One swarm, two very different owners

Strategic companies now face two adversaries who look identical on the wire.

The criminal wants money and takes the shortest path, which in 2026 means encrypting the thing you cannot operate without and pricing the ransom just under the cost of your downtime. Swarms make their economics obscene: an attacker's agent can be wrong nine times out of ten and still win, because the nine failures cost a few dollars of inference and the tenth is the payday.

The state wants the option. Hybrid warfare is the doctrine of doing everything short of shooting: pressure applied through energy, finance, logistics and information, with enough deniability that nobody has to invoke a treaty. Your company is the terrain that gets fought on. The objective is to be able to hurt your country on a day of someone else's choosing, while making sure you never notice they're there.

At the moment of intrusion you cannot tell which one you have. Both rent the same commodity tooling, both use leaked credentials and living-off-the-land tricks that leave almost no malware behind. Attribution takes months, comes from intelligence agencies, and lands long after you've had to decide what to do.

The insurance trapdoor

Insurers are on the list of strategic companies, and they are also where this stops being merely expensive.

When NotPetya hit Merck, the company claimed around 1.4 billion dollars. The insurers refused, invoking the hostile and warlike action exclusion: a Russian military operation, therefore an act of war, therefore not covered. Merck fought. The appellate court held that the exclusion required actual military action, not merely a government acting with ill will. The parties settled in January 2024, days before the state supreme court was due to hear it, which conveniently left no binding precedent.

Then the market did the sensible commercial thing and closed the hole. Lloyd's now requires standalone cyber policies to carry exclusions for state-backed attacks, on the stated grounds that those losses could exceed what the insurance market can absorb.

So if a hostile state takes you down as part of a hybrid campaign, there is a real chance the loss is contractually yours: the whole number, on your balance sheet, with no counterparty. That's what turns this from a security budget conversation into a solvency conversation.

Maersk survived NotPetya because of a power cut in Ghana. In Europe the clock has started anyway: NIS2 and DORA moved this from good practice to obligation, with named accountability for boards, and those deadlines are in the past tense.

Your swarm against theirs

Bolting a language model onto your existing alert pipeline is an expensive way to make your backlog more articulate. A defender's agent wrong ten percent of the time produces a firehose of false positives that buries the analyst it was meant to help, which is exactly the failure mode SOCs already have with no AI in the building.

Three things hold up against a swarm.

Deception, as the primary signal. Almost every detection technique degrades as attackers improve, because they all separate malicious behavior from normal behavior, and a better attacker looks more normal. Decoys work the other way. A fake host, a fake bucket, a canary credential sitting in a repo like bait, a seeded record matching no real customer: none of it has a legitimate purpose, so no legitimate process ever touches it. Every interaction is evidence by construction, not a probability score against a baseline that drifts. Exhaustive enumeration is exactly what swarms are best at, so the more thoroughly they sweep, the more decoys they trip. It is also the only technique here that catches a five-year resident who left no malware behind, because it keys on what the intruder touched rather than on what they brought.

Swarms for verification, not generation. If the attacker gets to parallelize, so should you, but on the other half of the problem. The right job for defensive agents is taking one high-confidence signal and independently confirming or killing it, with evidence attached, at machine speed. Investigation is the expensive human hour, and in these sectors the analysts you would need to hire do not exist in sufficient numbers. That's the hour worth buying back.

Autonomy with a governor. Full autonomy for reading, hard human gates for anything that writes, deletes or reboots. This matters double in critical infrastructure, where a badly scoped automated response causes the outage you were trying to prevent. The first internet worm died in 1988 of unbounded self-replication. Do not rebuild that bug with a bigger budget.

Your own agents are new surface, and a target. Every internal tool an agent may call, every place a model reads text it didn't write and then acts on it. Prompt injection is social engineering against a colleague who never sleeps, never escalates to a manager, and holds an API key. Put canaries in there too.

Decoys, cost, and procurement

The threat model isn't the uncertain part. It sits in government advisories and court filings, not in anybody's pitch deck. The defense is the part I'd want argued with, and three specific claims would sink it. That deception stops paying once you pass a few hundred decoys and the maintenance eats the signal. That verification-by-swarm costs more than the analyst hour it replaces, once inference is priced honestly rather than hopefully. That procurement at a utility answers any novel control with a twelve month pilot, which makes the whole approach academic no matter how well it works.

I've spent a decade building AI tooling around data, not defending a substation at 3am, so I'd rather hear those objections from people who have.

If you run security at a bank, a utility, an airport, a hospital group, an insurer, or anywhere else your country would notice going dark, tell me which of the three you've already lived through.