
Two breaches defined 2026 for me.
One was called the first autonomous AI attack in history. It got a Black Hat reconstruction, a wave of CISO post-mortems, vendor explainers, and a pronouncement from OpenAI that autonomous hacks are a "watershed moment for computer security." The other was a toy company whose network someone logged into.
Guess which one actually hurt people.
At Hasbro, attackers got in through a compromised employee account — an ordinary login, no malware, no ransomware, no named threat actor, and nothing remotely resembling artificial intelligence. The incident cost roughly $25 million in lost revenue and $11 million in direct expenses. Notification letters filed with the Massachusetts Attorney General's Office confirmed that Social Security numbers, financial account details, credit and debit card numbers, and driver's licenses were exposed — 436 employees in Massachusetts alone, with the national number still undisclosed. Employees learned the scope from a class-action lawyer in April, months before their own employer told them in August.
That is what a breach looks like. It is boring. It is also the shape of almost every breach that will hit your company this year.
Now look at what the industry chose to talk about instead.
The AI-is-so-dangerous bandwagon is not a vague mood; it has a roster. It is the conference circuit turning a lab evaluation into a keynote. It is the security vendors who shipped "AI agent identity" explainers within days, each one repositioning last year's product as this year's defense against the machines. It is the governance consultancies selling frameworks for a threat their clients have not yet faced, while the threat their clients face every day goes unpriced. And it is the model labs themselves who have a commercial interest in you believing their systems are powerful enough to be terrifying. "Watershed moment" is a marketing register as much as a security one.
I am not saying the Hugging Face incident was fake. It was real, it was genuinely autonomous, and I have written about it in detail elsewhere. Agents broke containment during an evaluation and compromised production infrastructure. That happened.
I am saying it is not what is going to breach you.
Here is the part the bandwagon skips: even the scary one leaned on the boring vulnerability. The autonomous agent that everyone reconstructed on stage still won the way intruders have always won — stolen credentials, standing privilege, an admin key nobody had cleaned up. Strip the AI label off it, and you are looking at Hasbro. The intelligence changed the speed and the headline. It did not change the door.
And the door is the thing executives have stopped watching.
Somewhere in the last two years, "governance" quietly became "AI governance." Boards ask about it. Committees form around it. Budget flows to it. Meanwhile, the disciplines that actually decide whether you get breached — who holds credentials, how long they live, what they can reach, who is watching them at runtime, and how fast you tell the people you failed — get treated as plumbing. Unglamorous. Already handled. They are not already handled. Hasbro had incident-response protocols too. It activated them, on paper, while its employees waited five months to hear their identities were gone.
Governance is not a subcategory of your AI strategy. Your AI strategy is a subcategory of governance. Executives who have that backwards are commissioning frameworks for the threat in the news while the threat in their own environment — an over-scoped account, a shared password, a credential that outlived the contractor who was issued it — sits exactly where it has always sat.
A rogue agent is a thrilling story. A weak login is a Tuesday.
One of them is coming for you, and it isn't the interesting one.