A new report from NTT DATA is putting a hard number on something security teams have warned about for years: attackers are getting faster, and AI is the reason why. The company's 2026 report found that some AI-driven intrusions now move from initial access to full data exfiltration in as little as 72 minutes. At the same time, ransomware activity continues to climb, showing that speed and volume are rising together rather than one replacing the other.
For everyday internet users and businesses alike, this shift matters. A shrinking attack window means less time to notice a breach, less time to respond, and less time to limit the damage before sensitive data is already gone.
The Shrinking Window Between Access and Exfiltration
Traditionally, cyberattacks unfolded in stages that gave defenders room to react. An intruder would gain access, quietly explore a network, escalate privileges, and only later move to steal data. That process could take hours, days, or longer, giving security teams a chance to detect unusual activity before real damage occurred.
NTT DATA's findings suggest that timeline is collapsing. When AI-driven automation is involved in the attack chain, the report found that data can be identified, packaged, and exfiltrated in roughly 72 minutes. That is a dramatic compression compared to the slower, more manual intrusion patterns security teams have historically planned around.
This kind of acceleration is consistent with broader industry reporting on AI-enabled intrusions. Recent coverage, including reporting on AI agents used to breach dozens of companies for minimal cost, has shown that automation is not just making attacks faster, it is also making them cheaper and easier to scale.
Ransomware Isn't Slowing Down
One of the more notable points in NTT DATA's report is that ransomware is still rising even as attackers adopt faster, AI-assisted tactics. Speed and extortion are not competing trends; they appear to be reinforcing each other. A faster path to stolen data gives ransomware operators more leverage before a victim organization even realizes what has happened.
This lines up with other recent data on ransomware's trajectory. A separate report found that ransomware attacks surged 87% globally, with some regions facing thousands of attempted attacks per week. Combined with NTT DATA's 72-minute figure, the picture that emerges is one where ransomware groups are not just more frequent, they are also more efficient at extracting value once they get in.
The broader pattern also shows up in ongoing tracking of attacks against US companies. Wire services have maintained running tallies of incidents throughout the year, and factbox-style reporting on the surge in AI cyberattacks against US firms reflects the same trend NTT DATA is describing: attacks are becoming more frequent, more automated, and harder to predict using old assumptions about attacker behavior.
Why AI Is Compressing the Attack Timeline
The core reason AI shortens the attack lifecycle is straightforward. Tasks that used to require a skilled human operator working manually, scanning for valuable files, testing credentials, or identifying which systems hold sensitive data, can now be automated and run continuously. That removes much of the trial-and-error delay that used to slow attackers down.
This has direct privacy implications. The faster data can be located and pulled out of a network, the less warning individuals get before their personal information ends up exposed or sold. Detection tools built around older, slower attack patterns may simply not have enough time to flag anything before the exfiltration is already complete.
What This Means For You
For most individuals, this trend doesn't mean personal devices are suddenly at greater risk of being personally targeted by AI-driven attackers. The organizations facing these faster intrusions are typically businesses, hospitals, and other institutions holding large volumes of data. But that's exactly the concern: those are the same organizations holding your personal records, financial details, and account information.
A 72-minute exfiltration window means that by the time a breach notification goes out, weeks or months after the fact, the data may have been gone almost immediately after the initial compromise. That reinforces the value of assuming any account tied to a data-holding organization could eventually be exposed, and acting accordingly ahead of time rather than only after a breach notice arrives.
Taking Action Now
The rise of AI-driven cyberattacks doesn't require panic, but it does call for practical habits that assume breaches will happen faster and with less warning than before:
- Use unique, strong passwords for every account, ideally managed with a password manager, so one compromised login doesn't cascade into others.
- Enable multi-factor authentication wherever it's offered, since it can stop an attacker even after credentials are stolen.
- Monitor financial and account statements regularly rather than waiting for a breach notification, given how quickly data can now be exfiltrated.
- Stay cautious with organizations that store sensitive personal data, and pay attention to their security track record when possible.
NTT DATA's 2026 report is a reminder that the timeline for AI cyberattacks is shrinking fast, and both organizations and individuals benefit from adjusting their expectations, and their defenses, to match.




