Andrea Margiovanni .it
A post office wall filled end to end with hundreds of identical white and teal metal boxes, gridded behind dark frames, each with its own lock and number. None of them is worth much on its own.
Photo by Ekaterina Belinskaya (Pexels)
Home / All essays / Issue № 96

A Hundredth of a Second per Target

On Monday the Spanish data protection authority published the first breach notification in which the attack was reportedly carried out by an agent. The interesting part is not that a machine broke into an application. It is that sixteen years ago a researcher worked out how much attention a mass attacker can afford to spend on each target, and the number was a hundredth of a second.

On Monday 14 September the Spanish data protection authority published on its blog something it had never published before: a notification of a personal data breach in which the incident, according to the organisation that suffered it, was carried out by an artificial intelligence agent.

The account runs to four lines. The agent is said to have started by looking for vulnerabilities in generic files, to have performed a valid login, and then, once inside the system, to have begun searching “de forma autónoma” for vulnerabilities in the application. Having found one it could use, it modified personal data and consulted invoices.

It is worth listing straight away what the document is not, because in three days I have already seen it described as several other things. It is not a decision by the authority. It is a post on the institutional blog, signed by Francisco Pérez Bes, reporting the content of a notification the agency received and stating explicitly that the information comes from the notifying organisation and “deberá ser objeto del correspondiente análisis”, must be analysed accordingly. It is not an accusation against a vendor either: the agency specifies that the use of a particular model does not imply that the model or its provider’s infrastructure was compromised. It is a notification the authority chose to make public because it considers it a signal, and as a signal it should be read.

The signal, though, is not where almost everyone is putting it. It is not that a machine got into a business application. Scripts have been doing that for twenty years. It is in four words of the account: once inside, the agent searched on its own.

To see why those four words are worth an essay you have to go back to a calculation made in 2010, when large language models did not exist and nobody imagined having to defend against them.

The objection deserves to be granted in full

There is a quick way to file the whole affair away, and it is an intellectually respectable one. It goes like this: AI did not invent offensive automation. Mass scanners, credential stuffing, exploit kits, worms, botnets, mass exploitation. The internet has been an automated shooting range since before anyone coined the word prompt, and anyone who has ever put a server online knows that within minutes something will start knocking.

The objection is not merely true. It is true on a far larger scale than most of the people who use it realise.

GreyNoise, which watches this traffic for a living, counted 2,969,010,478 malicious sessions over a hundred and sixty-two days in its report published in February, coming from 3,804,232 distinct IP addresses. Almost three billion sessions in a little over five months, against edge devices. In the same window a credential-spraying botnet grew from two thousand to three hundred thousand addresses in seventy-two days. And the figure I like best, because it dismantles the rhetoric of the ever-new threat: vulnerabilities published before 2015 attracted 7.3 million sessions, four times more than those published between 2023 and 2024.

Mass cybercrime was not waiting for AI to become industrial. It was already industrial, already economically rational, and spending most of its time knocking on ten-year-old doors, because that is where someone answers.

Anyone who dismisses the Spanish story with “nothing new here” is right about everything except the conclusion. To explain why, I have to hand over to someone who studied the problem back when the question was still spam.

The sum Cormac Herley did in 2010

In 2010, at the Workshop on the Economics of Information Security, Cormac Herley presented a paper with a title that reads like a joke and is not: The Plight of the Targeted Attacker in a World of Scale.

The opening question is the one any honest person has asked at least once while surveying the state of average security: if close to two billion people use the internet while neglecting even basic protections, why does only a tiny fraction get victimised each year? Herley’s answer is not technical. It is economic.

He separates two families of attack. Scalable ones, where cost is almost independent of the number of people attacked: send ten million emails or a hundred million, the marginal cost is near zero. And non-scalable, or targeted, attacks, which require effort devoted to the individual victim. He calls the mass attacker Carl and the targeted one Klara, and then he does the arithmetic.

He takes the spam campaign measured by Kanich and colleagues: $2,800 of revenue from 350 million emails sent. He assumes Carl at least broke even. Then he asks what would happen if Klara wanted to reach the same population while spending ten cents of attention per person. It would cost her $35 million. On Carl’s budget, Klara would instead reach 28,000 users: four orders of magnitude fewer.

Then Herley turns the sum around, and this is the step that carries the article. If the attacker wanted to spend paid human labour on each target at the US federal minimum wage of the time, $7.25 an hour, the budget left to break even is one hundredth of a second of attention per head.

A hundredth of a second.

From there follows the structural conclusion, which I quote because everything else in this essay rests on it: scalable attacks “must be entirely automated with no per-user intervention whatever”. That is not operational advice. It is a budget constraint.

And the constraint has a side effect Herley devotes a whole section to. Scalable attacks do not adapt. Carl sends the phishing, tries the Trojan, probes the firewall, checks whether the router still has its factory password. He can do all of that at almost no cost, on millions of people in parallel. But if Alice evades the phishing, Herley writes, “Carl doesn’t step up other attacks”: he does not persist, does not change route, does not intensify against the router because he was stopped at the firewall. Klara does. If Klara fails on the backup authentication questions she moves to social engineering, and if that fails she tries to get a keylogger installed. Klara adapts, because Klara has an attention budget per target.

For fifteen years the architecture of mass security has rested on that separation. If you were not valuable enough to justify Klara’s attention, you were defending against Carl, and Carl was a stupid adversary by construction. Not because he was incompetent, but because being clever about you cost him more than you were worth.

What a larger attention budget actually buys

Now the question gets precise, and in my view it is the only question that matters in the entire debate about offensive AI.

What happens to the separation between Carl and Klara when part of the per-target attention stops being human labour and becomes inference?

I am not claiming the machine has become Klara. The real Klara is an intelligence service with physical access, unlimited resources and time. The machine is nowhere near. I am claiming something more modest and, I fear, more consequential: that Carl has started buying the one feature of Klara’s that was always out of his reach, namely adaptation, and buying it inside his own cost structure.

An agent that tries, reads the error message, works out that the route is closed, tries another and reuses what it learned on the next target is not a brilliant attacker. It is a mediocre attacker whose attention budget per target is no longer a hundredth of a second.

That is what makes the Spanish account interesting. Not the login, which could have been any credential-stuffing run. The sentence after it: once inside, it searched on its own. In a classic scalable campaign, that moment is where automation ends and human work begins, because every business application is unlike every other one and finding the flaw requires looking at it. That human work is the cost that kept most targets out of the market.

Spain’s national cryptologic centre says the same thing in one line, without calling it economics, in guide BP/36 published in June: offensive AI does not necessarily bring novel techniques, it brings “la capacidad de automatizar, acelerar y ampliar a gran escala ataques ya conocidos”, the capacity to automate, accelerate and scale up attacks that are already known, significantly cutting the reaction time available to organisations. That is a state body writing, in a good-practice document, that the problem is not the novelty of the technique but the price at which the old technique becomes available.

The decisive threshold, then, is not perfect autonomy. It will not arrive, and waiting for it is an excellent way to do nothing in the meantime. The threshold is the point where trying a hundred routes costs less than the human work needed to try one.

The evidence we have, and how much it weighs

Here I have to slow down, because this is where an essay like this one either gets serious or turns into fear marketing.

The most quoted piece of evidence is Anthropic’s report of 13 November 2025 on an espionage campaign the company attributed to a group it calls GTG-1002. The headline numbers are the ones everybody repeated: AI is said to have performed 80 to 90 per cent of the campaign, with human intervention required “only sporadically”, perhaps four to six critical decision points per campaign; roughly thirty global targets across large technology companies, financial institutions, chemical manufacturing and government agencies; at peak, thousands of requests, often several a second.

The numbers almost nobody repeated are just as instructive. Successful intrusions were “a small number of cases”, and the report concedes that the model “occasionally hallucinated credentials or claimed to have extracted secret information that was in fact publicly-available”. Invented credentials. Inflated results. A machine telling its operator it had found secrets that were sitting on a public website. For completeness: the original text was corrected the day after publication, because it had said thousands of requests per second.

Anyone citing that report only for the percentage is misusing a source that is more interesting than that. Four to six human decision points per campaign is the economic datum; the low success rate and the hallucinations are the datum that says competence is not the point. A system that fails often but costs almost nothing can afford a failure rate that would put a professional out of business. Scale compensates for mediocrity, and it only compensates if failing is cheap.

The second piece of evidence is less spectacular and, I think, carries more weight. The Google Threat Intelligence Group, in its report of 11 May 2026, writes that it has identified for the first time an actor using a zero-day it believes was developed with AI, documents APT28 deploying against Ukraine a malware that queries an LLM to generate its commands at runtime, and describes actors sending thousands of repetitive prompts to analyse CVEs and validate proofs of concept. But the sentence I underlined is a different one, and it is economics written by threat analysts: by automating intelligence gathering and task support, these interactions “lower the barrier to entry for complex, multi-stage operations” and let actors concentrate their human capital on the higher-order strategic elements of campaigns.

Human capital. Barrier to entry. They are not describing a new weapon. They are describing the reallocation of a scarce factor.

The third piece of evidence circulates most and holds up least, so I put it last and cut it down to size. In September 2025 Check Point published an analysis of HexStrike-AI, a red-teaming framework orchestrating over a hundred and fifty security tools, noting that within hours of the disclosure of several Citrix NetScaler vulnerabilities certain underground channels were discussing how to use it against them. From that analysis came the figure you have read everywhere: from days to under ten minutes. In Check Point’s own text that figure is attributed to what “attackers claim”. It is not a measurement, it is not a time recorded in a lab, it is a forum boast repeated by a security vendor and then turned into data by three hundred articles.

I write this because it irritates me when other people do it. If the thesis of this essay needs HexStrike’s ten minutes to stand up, then it does not stand up.

The price the attacker pays is not the list price

People who argue about the marginal cost of inference usually produce a price list at some point. So much per million input tokens, so much per million output, multiplied by the number of attempts. It is an honest exercise but a fragile one, because price lists change every quarter and because it makes a structural claim depend on one vendor’s current pricing.

There is a better reason to think the cost of offensive attention is falling, and it is in the same Google report.

GTIG documents an ecosystem dedicated to obtaining model access outside the legitimate channel: gateways aggregating multiple API keys, automatic account-registration tools that handle the full cycle of CAPTCHA bypass, SMS verification and deletion on their own, anti-fingerprint browsers to isolate sessions. The analysts’ conclusion is that actors are “industrializing their adversarial workflows while subsidizing their operations through trial abuse and programmatic account cycling”.

Translated: the attacker is not paying what we pay. He is paying whatever it costs to steal a key, or nothing.

That makes the economic argument stronger, not weaker. It does not depend on anybody’s pricing policy. It depends on the fact that a capability once embodied in rare people has become a fungible resource that can be stockpiled, resold, stolen and recycled. Which is also why I find reassurances built on inference costs unconvincing: they assume an adversary who buys at list price.

The marginal target

If the analysis holds, the most important effect is not on the targets we read about in the papers.

Large organisations were already economically attackable. They have always been worth Klara’s attention, they have a SOC, they buy threat intelligence, they run simulation exercises. For them a cheaper attacker is a quantitative worsening of a situation they already know.

The effect is at the margin. It is in that whole band of targets nobody ignored because they were secure, but because they were not worth anybody’s time. The town of eight thousand people with its planning-permission system exposed. The vertical software used by forty professional practices, written well in 2014 and maintained by two people. The custom application a small firm had built and nobody has looked at since it went live. The industrial machine with a web interface that cannot be updated because the supplier no longer exists.

That band was not protected by a control. It was protected by a calculation: understanding the thing cost more than could be extracted from it. It was, quite literally, below the attention threshold.

In my work this band is not an abstraction. It is most of the clients a provincial ICT company has in front of it, and it is why this subject interests me more than the news about state-sponsored campaigns. When I discuss security with a small public body, the sentence I hear most often is not “we have no budget”. It is “who would bother attacking us”. For fifteen years that sentence was not foolish. It was a reasonable empirical observation, grounded in a real economy.

The data on victim size says that reasonableness had already worn out before agents arrived. Verizon’s 2025 Data Breach Investigations Report found extortion malware in 88 per cent of breaches at small and medium businesses, against 39 per cent at larger organisations. Small firms are not spared: they are harvested. And in the 2026 edition exploitation of software vulnerabilities became the leading initial vector at 31 per cent, overtaking stolen credentials, while ransomware appears in 48 per cent of breaches.

Now consider what that leading vector means once understanding an unfamiliar application stops being human work. It does not mean attackers will get good. It means the question “is this target worth studying” starts getting a yes in cases where it used to get a no.

The evidence that is missing

And now the part that costs me something to write, because it weakens everything I have argued so far and I have no intention of burying it in a footnote.

If the thesis were true in its strong and immediate form, we should already see it in the aggregate numbers. More attempts, more targets, more vulnerabilities burned, faster. Let us go and look.

VulnCheck, which keeps one of the more serious datasets on real-world exploitation, published its first-half 2026 review at the end of July. Four hundred and ninety-five vulnerabilities with evidence of exploitation. 23.43 per cent exploited on or before the day the CVE was published, down from 28.93 per cent in 2025. Around two hundred CVEs exploited within thirty-one days of publication, against 196 in 2024 and 194 in 2025. The ratio of exploited vulnerabilities to published ones has fallen from 2.7 per cent in the second half of 2023 to 1.4 per cent today. And the analysts are blunt: “early exploitation activity has not scaled at the same pace as CVE issuance”.

Two hundred against a hundred and ninety-six against a hundred and ninety-four. Three years, three nearly identical numbers, with everything I described above happening in between.

There are three ways to read this, and I want all three on the table, including the one that says I am wrong.

The first is that it is too early. GTG-1002 is from November, the GTIG report from May, the Spanish notification from Monday. One half-year is not a trend, and the adoption of an offensive technique runs on its own clock.

The second is that we are measuring the wrong thing, and this is the reading I find strongest. Counting exploited CVEs measures how many distinct vulnerabilities enter the offensive repertoire. The economic thesis predicts nothing about that number. It predicts that the set of targets worth using the existing repertoire on gets wider. Those are two different quantities, and the second appears in none of these indicators, because counting marginal targets would mean counting incidents at organisations too small to have a SOC, too small to issue a statement, and often too small to notice. GreyNoise’s figure on pre-2015 vulnerabilities drawing four times the traffic of recent ones says exactly this: volume does not chase novelty, it chases targets that stand still.

The third reading is that the thesis is wrong, or at least badly overstated. That adaptive attention stays too unreliable to actually replace an operator, that hallucinations cancel out the cost advantage, and that the current regime of mass exploitation of old things simply remains the most profitable strategy, as it has been for a decade.

I do not know which of the three is right. What I can do is say in advance what would change my mind, because a thesis that cannot be falsified is not a thesis. If eighteen months from now the data on victims by size has not shifted downward, if the distribution of targets looks the way it looks today, if the median time between publication and exploitation keeps refusing to compress, then I will have told an elegant story about a phenomenon that was not there. And if someone wants to convince me I am right, they should not bring me another report on a state-backed group: they should bring me the breach curve for organisations under fifty employees.

The vulnerability management paradox

There is one consequence that already holds regardless of which of the three readings is correct, and it holds because it concerns the defence rather than the attack.

We are putting AI on both sides of the table, and the two sides do not produce the same kind of object. On the offensive side it produces attempts. On the defensive side it produces findings. Attempts consume themselves: either they get in or they do not. Findings do not. Findings pile up on a queue somebody has to read.

If generating alerts becomes free while triage stays human, security turns into a denial of service attack against your own organisation. I do not mean that as a joke. I have seen vulnerability backlogs with thousands of entries where the median dwell time exceeded the useful life of the software that contained them, and where nobody could say which of them were reachable from outside.

The number of findings, in that regime, stops being information. The same goes for the number of alerts, of CVEs in scope, of blocked attempts. They are all metrics that implicitly measured effort, and measuring effort makes sense while producing it costs something. Once producing it is free, what remains are activity metrics that can be driven up at will without improving anything.

What stays measurable is the outcome. How much genuinely reachable risk was eliminated per unit of attention spent. How long passes between a signal and containment. How many assets map to an owner who answers. How far the damage spreads when one credential goes. How long passes between an advisory on a component we use and a decision about it.

Five boring numbers, and nobody puts them on a slide, because they do not grow in a satisfying way. But they are the only ones a machine cannot inflate.

The Spanish BP/36 guide reaches a consistent operational conclusion, and I find it more honest than a good deal of vendor literature: when the attacker recognises, prioritises and exploits at machine speed, a snapshot of security taken once a year is late by design. That is not an argument for buying more tools. It is an argument for moving spend from periodic verification to continuous capability.

Machine-speed defence without machine sovereignty

The answer you hear most often is “AI against AI”, and as a slogan it works beautifully. As an architecture it is incomplete, and it is worth saying why before adopting it.

If the time between reconnaissance and exploitation compresses, a defensive process made of alert, manual reading, ticket, meeting and approval becomes structurally too slow. There is no argument about that. But the conclusion “then let us put in a model that decides” introduces a different and more serious problem than the first one.

A defensive system able to block accounts, revoke sessions, isolate segments and shut down services holds a great deal of authority. It is real operational authority, exercised on timescales where nobody can review it, over infrastructure people’s work depends on. Handing it to a probabilistic component means accepting that a false positive becomes an outage, and it means having nothing to show an authority when it asks who decided.

The pattern I use, and which seems to hold, separates three things that usually get bundled together. Detection can run at machine speed, and that is where the model earns its place. Containment must be deterministic, meaning a written rule a human approved in advance that simply fires: suspend the session, revoke the token, apply a rate limit, force strong reauthentication, block egress to destinations not on the list. The decision, the one about what actually happened and what to do next, stays human, on human timescales, because containment has bought it the time.

It is the same logic by which the sensor in an industrial plant is clever and the safety valve is stupid. The valve does not need to understand: it needs to close every time, at the same threshold, even when everything else is broken.

From this follows the only sensible thing I know how to say to a small business or a small public body that cannot win a headcount race and never will. The goal is not to face a less capable adversary. It is to make every attempt more expensive and noisier than the target is worth. Fast patching on exposed things, phishing-resistant multi-factor authentication, least privilege actually enforced, segmentation, backups verified by a restore that was performed rather than planned, control over what leaves, an inventory of what you own, and logs somebody looks at.

It is not a new list. It is the same list as ten years ago, and anyone who finds that disappointing has missed the argument: if the economic thesis is right, the defence does not need to become exotic, it needs to become economically unattractive to cross. Well-designed friction does not block normal work. It raises the price of anomalous trajectories, which is exactly the variable the attacker is working on from the other side.

The law compresses the same time

While automation compresses technical time, the European legislator compresses organisational time, and the two compressions meet in the same office.

Since 11 September 2026 European manufacturers must report actively exploited vulnerabilities and severe incidents: early warning within twenty-four hours of becoming aware, notification within seventy-two, final report within fourteen days of a corrective measure being available. On how that moment of awareness is defined, and why it is the most interesting point in the whole construction, I wrote last week and will not repeat myself.

What interests me here is a different rule, older and less discussed. Article 32 of the GDPR does not impose security measures, it imposes measures appropriate to the risk, and asks that the state of the art, the cost of implementation and the nature of the processing be taken into account. It is a deliberately elastic rule, and elasticity works in both directions.

If the adversary’s economics changes, the risk changes. If the risk changes, the threshold of what counts as appropriate moves. Not because anyone rewrote it, but because it was built to move.

That is precisely the reading the Spanish authority offers at the end of its post, and it is why that text is worth more than the news it carries. The AEPD asks controllers, processors and data protection officers to explicitly incorporate AI-assisted attacks into risk analyses, to review response times in light of attack automation, to strengthen controls over identities and credentials, and to put automatic detection and containment mechanisms in place. That is not a prediction about the future. It is a statement that the risk assessment written three years ago, containing an adversary who cost what he cost back then, now describes a world that no longer exists.

Anyone holding a DPIA whose threat section was copied from a 2021 template would do well to reread it this week, not because a new law arrived, but because the denominator changed.

What is left to defend

The mistake I see made most often in this discussion is anthropomorphising the adversary. People talk about agents that “decide to attack”, and from there it slides into the film.

An agent does not need criminal intent of its own. It is a multiplier applied to an objective somebody assigned to it. The problem is not a machine that wants something: it is an optimisation function equipped with tools, memory, feedback and machine time, pointed at an objective written by a person who remains fully responsible for having written it. Anyone looking for volition in the software is looking in the wrong place, and meanwhile not looking in the right one, which is the access log.

Security has always been an economic equilibrium as much as a technical one. We never made attacks impossible: we made succeeding unprofitable, limited what the successful attacker carries away, and shortened the time to put things back. When the price of one of the activities involved changes, the equilibrium shifts, and it shifts quietly, with nobody announcing anything.

If a machine makes it cheap to try a thousand times, the defence has to make succeeding expensive, damage bounded and recovery fast. It sounds like a platitude, and it is, except for one detail: those are three different objectives, funded in three different ways, and most organisations I know fund exactly one of them.

For fifteen years a hundredth of a second per target was the wall protecting everyone who was not worth attacking. It was not a security control, it appeared in no audit, nobody designed it. It was an accounting fact, and like all accounting facts it is the easiest thing in the world to lose without noticing.

It is not the attacker’s intelligence that needs watching. It is the price of his attention.

The Spanish notification remains a single case, under review, told by the party that suffered it. Treating it as proof of an era would be exactly the shortcut I have tried to avoid throughout this piece. But that is what signals are for: not to prove, to make you look. And what you see when you look is not a robot that learned to hack. It is a market that has just changed its entry threshold, and a set of organisations that used to sit below it, and do not know they were there.

Key takeaways

  • In 2010 Herley calculated that a mass attacker, to stay level with the economics of spam, can afford roughly one hundredth of a second of human attention per target. Hence his conclusion that scalable attacks do not adapt to the defence: personalising breaks the cost structure. An agent that tries, reads the error and changes route attacks that constraint, not the defender’s competence.

  • The relevant price is not the list price of inference. Google documents account pooling, trial abuse and anti-detect browsers used to industrialise access to models: the attacker is not paying what we pay, and that makes the economic argument stronger, not weaker.

  • VulnCheck counts about two hundred CVEs exploited within thirty-one days in the first half of 2026, against 196 in 2024 and 194 in 2025, and writes that early exploitation is not scaling with CVE issuance. If the thesis were a forecast about vulnerabilities burned, it would be falsified today. It is a forecast about how wide the set of worthwhile targets becomes, which none of these indicators measure.

Sources

  1. Primera notificación de una brecha de datos personales causada por un ataque ejecutado mediante un agente de IA, Agencia Española de Protección de Datos, blog, 14 September 2026
  2. Inteligencia Artificial agéntica. Orientaciones desde la perspectiva de protección de datos, Agencia Española de Protección de Datos, 18 February 2026
  3. CCN-CERT BP/36, Guía de buenas prácticas frente al modelo de IA ofensiva, Centro Criptológico Nacional, 23 June 2026
  4. The Plight of the Targeted Attacker in a World of Scale, Cormac Herley, Microsoft Research, Workshop on the Economics of Information Security (WEIS), 7 June 2010
  5. Disrupting the first reported AI-orchestrated cyber espionage campaign, Anthropic, 13 November 2025
  6. Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access, Google Threat Intelligence Group, 11 May 2026
  7. Hexstrike-AI: When LLMs Meet Zero-Day Exploitation, Check Point, Office of the CTO, 2 September 2025
  8. 2026 State of the Edge Report, GreyNoise Intelligence, 24 February 2026
  9. State of Exploitation 1H-2026, VulnCheck, 28 July 2026
  10. 2026 Data Breach Investigations Report, Verizon Business, 19 May 2026
  11. Verizon DBIR: Small Businesses Bearing the Brunt of Ransomware Attacks, Infosecurity Magazine, 24 April 2025
  12. Cyber Resilience Act, Reporting obligations, European Commission, Shaping Europe's digital future, 11 September 2026
  13. Regulation (EU) 2016/679 (GDPR), articles 32 and 33, Official Journal of the European Union, 4 May 2016

The author

Andrea Margiovanni

I follow the relationship between AI and European regulation as a political fact, not a technical spectacle. I work with teams that have to make AI compliant with AI Act, CRA, NIS2 without reducing compliance to a checklist.

See the guide
© 2026 Andrea Margiovanni Made with care, by hand