← Back to StoryBreak

Visa Warns AI-Powered Attacks Are Outrunning Human Cyber Defenses

Visa says artificial intelligence is compressing the time needed to discover vulnerabilities, scale scams and manipulate victims—forcing companies to move from periodic security reviews toward continuous, AI-assisted defense.

By StoryBreak

Published September 30, 2026 at 12:50 AM

Visa Warns AI-Powered Attacks Are Outrunning Human Cyber Defenses
AI-generated image / StoryBreak

Visa is warning that artificial intelligence is changing the cybersecurity race faster than many organizations can adapt—not necessarily because hackers have replaced humans, but because AI can compress the time, cost and expertise required to find weaknesses and manipulate victims.

The payments company’s recent security disclosures describe an attack environment increasingly defined by speed. In its Spring 2026 Biannual Threats Report, Visa said criminals are shifting away from direct technical compromises and toward less-defended targets: people, business processes and connections between organizations. Artificial intelligence is helping scale that deception.

That shift matters because a fraudulent payment does not always begin with a stolen card number. A convincing message, voice imitation or fake customer-service interaction can persuade a legitimate account holder to approve a transaction. Visa says scams have become a primary source of consumer harm, with nearly $1 billion in scam-related fraud attempts identified across its network between July and December 2025.

The company’s data also illustrates a more complicated picture than a simple collapse of payment security. Visa reported that device-token fraud fell 9.6% year over year and losses associated with account enumeration declined 16% during the same period. Those improvements suggest that stronger authentication, tokenization and network controls are blocking some traditional attacks. But the pressure has not disappeared; it has moved toward the human and organizational weak points surrounding the payment system.

Visa’s warning extends beyond consumer scams. Through Anthropic’s Project Glasswing, a defensive cybersecurity initiative, participants identified more than 10,000 high- or critical-severity vulnerabilities in widely used, systemically important software during the first month of testing, according to Visa’s account of the project.

That finding points to the central problem in the AI security race: discovering a vulnerability may no longer be the slowest step. Security teams must still determine whether a finding is real, assess its potential impact, coordinate a fix, deploy it without breaking critical services and prove that the attack path has actually been closed.

Human review remains important because an automated response can create its own damage. Isolating a system, changing access permissions or deploying a patch across production infrastructure can interrupt legitimate operations. The challenge is therefore not simply to remove people from the process, but to give them tools that can handle routine investigation and remediation at machine speed while preserving accountability for high-impact decisions.

Visa is trying to build that model with its Visa Vulnerability Agentic Harness, an open-source, model-agnostic framework for AI-assisted vulnerability management. The company says newer versions support not only discovery but also remediation and validation. Visa has reported that some fixes once taking weeks can be reduced to hours, although that figure describes the company’s own experience and is not an industry-wide benchmark.

The broader lesson is that “human defenses” are not becoming irrelevant; they are becoming a bottleneck. Periodic audits, alert queues and manual triage were designed for an environment in which attackers had to work at roughly human speed. AI-enabled tools can produce more signals, test more systems and personalize more scams before defenders have finished reviewing the first warning.

For businesses, the immediate question is not whether to buy an AI security product. It is where AI can safely accelerate detection, prioritization and recovery—and where human approval must remain mandatory. The organizations best positioned for the next phase will be those that treat resilience as more than prevention: they will continuously test their systems, close vulnerabilities quickly and verify that the fix works in the real world.

Visa’s message is ultimately a warning about time. In cybersecurity, the side that can identify, understand and contain a threat first has the advantage. AI is giving attackers more ways to move faster. Defenders now have to make speed, validation and recovery part of the security architecture itself.

Sources & Further Reading

StoryBreak

Independent digital news and reporting, updated throughout the day.

This article was researched and drafted with AI assistance and reviewed as part of StoryBreak's editorial process before publication. Read our editorial standards.