
Traditional human-led penetration testing has served its purpose, but it simply cannot deliver the scale, scope, and speed required in the AI era. Even the best red teamers understand that an AI Hyperattack is the best way to keep pace with adversaries using frontier AI models for their attacks.
Our latest kill chain in Episode 5 of “Kill Chains and Coffee” only reinforces that viewpoint. Fresh off his presentation at Black Hat 2026, Armadin Principal Red Team Operator Craig Wright joined me to discuss a recent Armadin engagement with a telco provider.
We employed the Armadin Attacker to pressure-test the company’s entire attack surface to reveal truly exploitable risk that, in some cases, might have been hiding for decades.
The telco company had traditionally relied on periodic human-led pentesting but was curious to see what a managed AI Hyperattack assessment would uncover. The engagement included:
This particular kill chain sequence began with an AI agent identifying a hidden registration endpoint using route name inference. It self-registered an account, then found a second registration mechanism and used the new account to generate an authorization token before pivoting to authenticated testing.
It identified three vulnerable endpoints and produced working SQL injection payloads, eventually accessing five additional internal SQL servers. In total, the kill chain exposed 68.5 million lines of critical data, including workforce Personally Identifiable Information (PII), 911 call geolocation data, and enough SIM swap precursor data to fuel a social engineering attack that could execute a full SIM swap.
The Takeaways: Pentesting Must Be AI-First
At Armadin, we’re finding a lot of first-party apps that teams have built and linked to the internet—an attack surface where most organizations are uneasily vulnerable. Those apps require much harder security, but the sheer scope of the effort to protect them requires an AI-first approach.
You can’t expect human red teamers to address tens of thousands of internet-facing services in an 80-hour test period. You need an agentic AI approach to cover the entire attack surface—all paths, all the time. The way you get there is with an AI Hyperattack that safely delivers the machine speed and scale to help you identify truly exploitable risk.
Here are three primary takeaways from this kill chain:
Discover how a safe, managed assessment gives you the tools and confidence to identify truly exploitable risk across your environment. Learn more about AI Hyperattacks.