[Digital Today reporter Chi-gyu Hwang] The victims of hacking will be AI agents, not people, Axios reported on Sept. 8, citing Bugcrowd CEO Dave Gerry (데이브 게리).
Gerry spoke with Axios last month on the sidelines of the Black Hat conference. "You will see agents becoming the victims," he said. "Cases of agents being hacked, not people, will increase."
Gerry expects scenarios in which AI agents are hacked to increase first for enterprise agents rather than consumer ones. Most AI agents are currently deployed in corporate environments.
"This will be the biggest attack path," he said. "To make things easier, people handed over blanket access to key assets to AI agents."
Gerry also highlighted that AI agent features have recently been added even to tools companies have used for a long time, making it harder to determine how far AI has penetrated inside networks.
"One day, AI features are suddenly switched on in tools already approved as safe," he said. "The number of previously approved tools that need to be reviewed again keeps increasing."
The security industry has stressed account security for AI agents. That is because it views agents as a new insider threat. If hackers use internal agents, they can gain unlimited access to sensitive systems, siphon data and infiltrate other parts of an organisation.
Even before the spread of AI agents, weak account management was the most targeted path for hackers. Account-based attacks accounted for 60 percent of Cisco incident response cases in 2024. "Attack methods are new, faster and larger in scale," Gerry said. "But the key is basic security: knowing what you have and putting controls in place."