July 28, 2026
The Next AI Breakthrough Won’t Target Computers. It’ll Target People.
For years, cybersecurity has focused on protecting systems. Organizations invest in firewalls, endpoint detection, identity management, and…

By mePrism Privacy
2 min read
For years, cybersecurity has focused on protecting systems. Organizations invest in firewalls, endpoint detection, identity management, and security awareness training because the assumption has always been the same: attackers first have to break into technology before they can reach people.
That assumption is changing.
When reports surfaced that Anthropic's latest frontier AI model had identified ways through highly classified systems in a matter of hours, the conversation quickly turned to artificial intelligence. Could models become powerful enough to outpace human defenders? Would governments begin restricting access to the most capable systems? Those are important questions, but they overshadow a more immediate one.
What happens when AI no longer needs to spend weeks researching its target?
The answer is surprisingly simple. It starts with personal data.
The most valuable input into a modern cyberattack isn't always a software vulnerability. Increasingly, it's a detailed profile of the person on the other side of the screen. Home addresses, family members, previous employers, leaked email addresses, phone numbers, property records, and social media activity all help attackers build believable identities. AI simply makes that process dramatically faster.
Those profiles already exist. Thousands of data brokers collect, aggregate, and sell personal information on millions of Americans. For years this was framed as a consumer privacy issue. People worried about spam calls, identity theft, or unwanted advertising. Those concerns remain valid, but AI changes the scale of the problem.
A model capable of analyzing massive datasets, correlating breach records, and generating convincing social engineering campaigns doesn't need to discover this information from scratch. It only needs to buy it.
That changes the economics of cybercrime. Instead of spending days researching a target, attackers can purchase a ready-made dossier and let AI identify the quickest path into an organization. The weakest link is no longer the firewall. It's the employee whose digital footprint has already been assembled elsewhere.
This is why the conversation around data brokers is beginning to shift. Privacy advocates have long argued that personal information should not be bought and sold so freely. Today, security leaders are arriving at the same conclusion for a different reason. Every publicly available record gives attackers another piece of context they can use to impersonate an employee, reset an account, bypass identity checks, or target an executive.
Recent incidents involving ransomware groups, sophisticated social engineering campaigns, and high-profile executive targeting all point toward the same trend: attacks increasingly begin with reconnaissance about people rather than exploitation of software.
That doesn't mean traditional security controls have become obsolete. Multi-factor authentication, endpoint protection, and employee training remain essential. But they address the attack after the adversary has already identified the target. They do little to reduce the personal information that made the target attractive in the first place.
As AI continues to improve, that imbalance will become more obvious. Faster models don't just find technical weaknesses more quickly. They process human information at a scale that wasn't practical even a year ago. The organizations that adapt will be the ones that treat personal data exposure as part of their cybersecurity strategy rather than a separate privacy issue.
Policy is likely to follow. Laws written before the arrival of frontier AI focused largely on consumer rights and transparency. Future legislation will almost certainly be shaped by national security concerns as well. When personal information becomes a strategic resource for criminal groups and foreign adversaries, data broker regulation stops being a niche privacy debate.
The practical takeaway is straightforward. Every piece of personal information removed from the data broker ecosystem is one less data point available to an attacker. AI may continue to make cyberattacks faster and more sophisticated, but reducing unnecessary exposure remains one of the few defensive measures that becomes more valuable as the technology advances.