28 May 2026

AI makes hacking faster and cheaper: security experts urge organisations to respond more rapidly

Society

Artificial intelligence is enabling the rapid and automated discovery of security vulnerabilities in software, including systems that have been in use for decades. Security experts warn that this development poses significant risks for businesses and governments alike. A hacker based in Amsterdam recently demonstrated how he gained full access to a government website using an AI tool that cost approximately ten euros.

Rogier Fischer of Amsterdam-based cybersecurity firm Hadrian used an AI system to analyse the source code of a government website. The system identified a flaw that allowed Fischer to download files that should not have been accessible. The passwords visible on his screen then enabled him to log into the website’s database. “There was nothing stopping me”, Fischer said. “Once you are inside, you can change things, for example. Or launch new attacks from within that database.” Hadrian carried out the attack using a low-cost AI tool from OpenAI, the company behind ChatGPT, at an estimated total cost of ten euros.

Matthijs van Amelsfort, director of the National Cyber Security Centre (NCSC), stressed that the speed at which attackers exploit vulnerabilities is increasing sharply. “In the past, it took days before an attacker exploited a flaw; now it takes hours”, he said. “That will become minutes.” This acceleration makes it increasingly difficult for organisations to respond before damage occurs.

Dimitri van Zantvliet, chair of the CISO Platform, the professional association for chief information security officers, confirmed that the urgency is widely felt. Hundreds of security professionals gathered this week at CISODAY 2026 to discuss the developments. “There is no panic, but it is certainly urgent”, Van Zantvliet said. He noted that AI systems can expose vulnerabilities in software that is twenty years old. “We need to accelerate, so that we fix those flaws before they are exploited.”

Cybersecurity firm AISLE investigated whether lower-cost AI systems are also capable of finding such flaws. Since September, the company has discovered more than two hundred vulnerabilities using a range of AI systems. Co-founder Jaya Baloo responded to claims made by the company behind the AI tool Mythos, which had argued its system was exceptionally capable at finding vulnerabilities and therefore restricted access to a small group. AISLE was able to identify the same flaws using older and cheaper systems. “The story was that AI had ‘suddenly’ become very good at finding vulnerabilities”, Baloo said. “But we could find those same flaws with older AI systems. So what do you mean, ‘suddenly’? We have been doing this for months.”

Read also

SCRIPT project

22 March 2024

CWI joins forces with startup Raynetics to push the frontiers of 3D image reconstruction

10 June 2025

Vacancy: Tenure-track or tenured position in responsible AI

28 November 2023

Subscribe to our newsletter

Would you like to stay informed about what is happening within the Amsterdam AI ecosystem?