Bachelor thesis · 2026 · Grade 1.7
Autonomous AI agents in cybercrime
Risks, scenarios and options for companies
This thesis examines how autonomous AI agents change the threat landscape in cyberspace – deliberately from the attacker’s perspective, with a focus on protecting companies. The central finding: what matters is not that AI makes attacks possible, but that it turns scalability, adaptivity and persistence into something operational. Working through three attack scenarios – autonomous reconnaissance, AI-assisted social engineering and agentic exploitation – it identifies recurring weakness patterns in companies and derives organisational, technical and strategic options from them.
Research question
How does the use of autonomous AI agents change the threat potential in cyberspace from the perspective of protecting a company?
Sub-questions examined
- 01Which realistic attack scenarios involving autonomous AI agents can be identified today?
- 02Which organisational and technical weaknesses do such scenarios make particularly exposed?
- 03To what extent do human factors – convenience, lack of awareness, unreflected use – contribute to that exposure?
- 04Which concrete safeguards and organisational changes are needed to make companies more resilient against AI-assisted attacks?
Three attack scenarios worked through
A
Autonomous reconnaissance and target selection
Companies can be systematically mapped from the outside without classic defences ever coming into play. What is visible in job ads, on social media, in subdomains and test systems adds up to a usable target profile – and the adding up is precisely the work an agent takes over.
B
AI-assisted social engineering and phishing
Personalisation and the ability to hold a conversation strip away many of the warning signs awareness training has relied on. The attack moves into everyday work: it no longer looks wrong, it looks plausible. Training that warns about typos and generic mails therefore falls short.
C
Exploitation through agentic loops
Research and testing can be accelerated and run in parallel. That shortens the window between a vulnerability becoming public and being exploited – exactly the span in which patch management would have to take effect.
Recurring weakness patterns
Open OSINT and missing visibility
Companies often do not know what is visible about them from outside. The sources usually originate outside IT – in HR, marketing, communications – which is why ownership cannot be left with IT alone.
Blurred processes and diffused responsibility
Once exceptions become the norm, an attacker can anticipate that norm. Four-eyes approval, fixed escalation paths and exceptions recorded in writing only work if leadership does not quietly undermine them through pressure for speed.
Detection gaps from missing correlation
Individual events look harmless; the pattern does not. Without correlation across sources, slow and distributed attacks stay invisible.
The human factor as an amplifier
Convenience, time pressure and routine lower the threshold for bypassing safeguards – in every phase, not just in social engineering. The very relief that makes digital work viable becomes an attack vector.
Recommended actions
Organisational
- ▸OSINT hygiene as a recurring process, owned jointly across HR, communications and IT
- ▸Train awareness around processes rather than tell-tale signs: how is a payment request verified, even when it sounds plausible?
- ▸Clear processes without side routes – four-eyes approval, defined escalation, exceptions recorded in writing
- ▸Governance for your own AI use: who may deploy agents, with which data, under whose oversight?
Technical
- ▸Prioritise patching by external exposure and business criticality, not by schedule
- ▸External attack surface management as a continuous capability – with ownership, or it only produces new lists
- ▸Email authentication done consistently, including reporting and a staged move to stricter policies
- ▸Segmentation and least privilege: what decides the damage is how far an agent gets automatically after initial access
- ▸Anomaly detection plus clear playbooks for unusual logins, forwarding rules and OAuth consent flows
Strategic
- ▸Review existing risk assessments for whether they reflect the speed and scalability of agentic attacks at all
- ▸Decide binding measures with a good effort-to-effect ratio – with ownership and a timeframe, not as an appeal
- ▸Develop your own guidelines for AI use instead of waiting for regulatory pressure – the EU AI Act sets a frame but does not replace internal governance
- ▸Use threat intelligence systematically: reaction speed matters more than it used to
Outlook
The next step plausibly lies in multi-agent systems: instead of one generalist, specialised agents work together – reconnaissance, communication, technical paths – coordinated by something that prioritises goals. On the defensive side that suggests a picture of agent against agent. The research needed is less about new model tricks than about empirical studies of real incidents and protection concepts that also work on a small budget.
Limits of this work
- The scenarios rest on technically plausible conditions, not on empirical validation through interviews, case studies or incident data of my own. The analysis is qualitative rather than statistical.
- The field moves fast. Some assessments may look different in one or two years – in both directions, because defences adapt too.
- Legal and economic depth were deliberately left out; each would deserve a thesis of its own.
- The work draws partly on vendor threat reports, which can be interest-driven. They were framed with research and official sources, but some bias may remain.
Key facts
Bachelor thesis, B.Sc. Cyber Security Management
Hochschule Niederrhein, Mönchengladbach
2026 · Grade 1,7 · 76 pages
Supervisors
- Prof. Dr. rer. pol. Matthias Mehrtens
- Prof. Dr.-Ing. René Treibert
Keywords
- autonome KI-Agenten
- KI-Sicherheit
- Cyberkriminalität
- Social Engineering
- Prompt Injection
- Business Email Compromise
- External Attack Surface Management
- OSINT
- EU AI Act
- Informationssicherheit
- ISO/IEC 27001
- KMU
Full thesis as PDF
Autonomous AI agents in cybercrime – Risks, scenarios and options for companies. Mohammadreza Tavakoli, Hochschule Niederrhein, 2026.