Blog Zscaler

Ricevi gli ultimi aggiornamenti dal blog di Zscaler nella tua casella di posta

Customer Stories

How Deception Helps Amex Global Business Travel Trap Autonomous AI Attacks

image

Autonomous AI (or agentic AI) is a clear and present danger for even the most security-savvy organizations. When an AI agent operating at machine speed crosses your perimeter, you can’t afford to lag behind. To successfully combat agentic AI threats, “getting faster” is never going to be good enough. Enterprise security teams need to turn attacker speed to their advantage by exploiting their weaknesses with advanced deception technology. 

Recent events offer a harsh warning of what’s ahead. The first verified AI-orchestrated nation-state attack targeting 30 organizations was detected in late 2025. Dubbed GTG-1002, the campaign used agentic AI to perform 80% to 90% of its tactical operations autonomously, spanning everything from intelligence gathering and vulnerability exploitation to lateral movement and data exfiltration. Soon after, Mexico’s government agencies were hit with an AI-assisted breach that exfiltrated more than 415 million citizen records.

Anthropic's Claude Mythos frontier model confirms the dangers of AI-generated threats. This model shows us how it can autonomously discover thousands of critical vulnerabilities across major operating systems and browsers and generate exploits without human guidance. Days after this disclosure, the Cloud Security Alliance (CSA) published a strategy brief reviewed by more than 250 CISOs and security leaders. Among its 11 priority actions, the briefing recommends that organizations build a deception capability within the next 90 days, classifying the risk as “high” with significant exposure within 45 days if left unaddressed.  

Absent a strategy for dealing with Mythos and other frontier models, they are likely to serve as very expensive technical debt generators. After all, the novel attack chains they create are often not as effective as they might seem. But open-weight models, on the other hand, are not far behind Mythos in capability. They are already able to orchestrate traditional kill chains at a speed and scale that accelerates the collapse of breakout times we have been observing for years now. Plus, a threat that is not getting the attention it deserves is attrition. Agentic attackers continue to operate as long as they have tokens to spend. Humans must rest, and true follow-the-sun coverage is very costly. Agentic defense will become table stakes in threat detection and response over the next 12 to 24 months as a necessary response to shrinking breakout times and the expanding duration of high-velocity attacks.

CSA’s advice runs counter to most security operators' understanding of deception. Deception has long been considered a compensating control only available to advanced teams at well-funded organizations. It is also perceived as being too static, too easy to evade, and too difficult to implement and manage. 

But deception is more accessible and powerful than commonly believed. I will address its perceived weaknesses, referencing the deception program we’ve built at Amex GBT and its integration with our agentic security operations. The core of this deception program is Zscaler Deception. It works alongside an array of easy-to-deploy open source decoys and is run end to end by a single engineer, with bandwidth to spare.

 

AI-powered threats make dwell time and the kill chain obsolete

Let’s take a deeper look at why the current arsenal of tools, such as EDR, NDR, XDR, SIEM, and UEBA, are insufficient for halting autonomous AI attacks. Granted, they are great at detecting and synthesizing data on attack patterns that follow the classic cyberattack kill chain sequence, but these tools operate at human speed and assume threat dwell time. 

Agentic AI attacks, on the contrary, move at machine speed with minimal human participation, degrading the value of dwell time as a meaningful gauge of risk. Dwell time is still an issue, as even AI-augmented attackers still require time for reconnaissance and exploit chaining. But we will need to measure those dwell times, and our response, with new values expressed in seconds and milliseconds rather than hours and minutes. The target for many MTTx metrics has become much smaller and is continuing to shrink. Along with the advantage of velocity, agentic AI attacks multi-task relentlessly, performing functions simultaneously across several pathways and often achieving their malicious objectives in minutes.

It is worth noting that this expansion of scope for simultaneous attacks does present new detection opportunities. AI attackers are detectable—and in some ways more detectable than a low-and-slow human attacker. The bigger gap is in response times, especially if you are closing detection gaps with high-fidelity controls like deception technology. Traditional tools are still essential components of your detection layer, but the accompanying processes for triage and response just can’t keep up.

 

AmexGBT-BlogImage

 

I recently did a presentation with Amir Moin, Principal Product Manager at Zscaler, at Zenith Live. He emphasized the need for accurate, proactive threat detection for what he describes as “periscope events.” As Moin pointed out, in anti-submarine warfare, sighting a periscope breaking the water is a clear indicator of an imminent threat. Advanced detection of AI threats needs to be equally unambiguous. The second requirement revolves around the speed of attacks and the speed of response. Standard security tools no longer work in an AI threat environment. By the time you collect telemetry, complete correlation, and start triage, attackers already have their hands on your data.

 

Uncovering common cracks in your defenses

There’s no such thing as perfect, full-coverage security. Even the most sophisticated security infrastructure has its blind spots. When we started our program, we uncovered four structural gaps in our defense. You may find similar ones in your own environment. 

  • Some endpoints—appliances and legacy systems for example—could not be secured with a modern EDR agent. 
  • Even on endpoints with EDR agents, there were blind spots, as in large production apps that required process exceptions.
  • Visibility into lateral movement of threats was blocked in certain contexts. For various reasons, we were unable to disable protocols known to be risky and vulnerable, such as Link-Local Multicast Name Resolution (LLMNR), used to find device IP addresses on LANs without a DNS server. 
  • Automated scanning at the perimeter continually created high signal volume and excessive false positives. This triggered alert fatigue, threatening to overwhelm our security analysts. Surfacing real threats required too much time and effort.

Those four gaps are the main reasons why we built our program based on modern deception technology—the only solution that addressed all of them. Note that none of these reasons are peculiar to AI. In fact, all of them predate AI and remain problems even for organizations with no AI adoption to speak of. So even if AI is not on the radar for you, you should still be pursuing a deception program.

 

Exploiting AI weaknesses with a decoy strategy

Here are some inherent characteristics of agentic AI attacks that you can use to your advantage:

  • The high velocity of AI attacks can work against them. Why? Because speed doesn’t matter to a decoy. It doesn't care what technique the attacker uses or how fast it moves. There’s never any reason for a legitimate user or process to touch a decoy. This means that every single interaction an AI agent has with a decoy is a periscope event—a clear threat. The faster the AI agent probes your network, the more deception surfaces it comes in contact with and the faster it gets detected. 
  • AI attacks are exhaustive. Running at machine speed along parallel paths, they leave no stone unturned and can bring down an organization in minutes. However, with deception in place, agentic attackers with a comprehensive scope and scale are virtually guaranteed to trip over a decoy. It detects them and then issues a high-fidelity alert, allowing you to contain them with pre-orchestrated responses.
  • AI agents can be designed to operate cautiously. They can deliberate throttle their activity to bypass rate limits and evade the behavioral guardrails that would otherwise trigger detection: the low-and-slow AI attacker argument. But that caution has a cost. The moment an AI attacker surrenders its speed advantage, it moves into the dwell-time window for which controls like EDR and UEBA were purpose-built. 
  • AI agents can be programmed to look for decoys. But the problem is they have to probe the environment first, and in the process of doing so, they still will encounter decoys and trigger an actionable alert. In fact, the probing itself is another detection opportunity. In addition, even knowledge of the existence of decoys won’t help, as the mental model of the environment has already been poisoned. The OODA loop of the attacker starts to break down as they question each artifact they discover. The attacker can never be certain they have mapped every decoy. More on that later.

To human or AI attackers, the decoys look like the real thing. If you regularly update the content and context of decoys, you’ll have a robust evergreen detection and prevention capability. Changes in attacker techniques and speed become irrelevant.  The update process can be fully automated and AI-augmented at a relatively low cost to the organization.

 

What we built and why

The idea was to create an environment akin to a lawn intentionally littered with rakes. No matter where an AI agent steps, they will take a hit and reveal their presence. In this scenario, the speed advantage of AI agents actually makes it easier and faster for us to trap them. 

 

SideshowBobRakes_AmexGBTPreso-Image
Sideshow Bob. Cape Feare, S05E02, The Simpsons.

 

With Zscaler Deception, we planted decoys alongside our real assets: endpoints, Active Directory users, vulnerable apps, credential stores, cloud storage, LLM chatbots, and model context protocol (MCP) servers. 

We focused decoy design on three layers:

  1. Perimeter: We built private threat intelligence (PTI)  honeypots in our DMZ, which sits between our internal network and the internet.

    Purpose: To absorb attack traffic and automatically distinguish real attackers from noise. That telemetry was used to update our defenses, including firewalls and web application firewalls, before attacks could build momentum.

  2. Network: We planted decoys across the cloud and physical infrastructure. 

    Purpose: To create destinations to bait attackers and deploy sensors to surface LLMNR attack patterns.

  3. Endpoint: We used the Zscaler Client Connector to plant lures and breadcrumbs on endpoints. These included a variety of decoy types deliberately architected to act like breadcrumbs guiding lateral movement toward further decoys and baiting attackers into generating high-fidelity identity signals. 

    Purpose: To seed the environment with fake assets that legitimate users have no reason to access. Any interaction with these assets immediately signals an attacker. If an attacker happens to evade EDR and continues to chase a decoy, they trigger a high-fidelity alert and are engaged and contained.

 

How deception disrupts the decision cycle for human and AI attackers

At Amex GBT, we have learned to leverage deception technology’s super power: its ability to poison the attacker’s decisioning cycle based on the OODA loop model, developed by US Air Force Colonel John Boyd in the 1970s.

In Boyd's framework, attackers:

  • Observe the environment.
  • Orient themselves by building a mental model.
  • Decide what to do next.
  • Act.

Deception is uniquely capable of addressing both human and AI operators by corrupting the Observe and Orient phases.

When human operators are in the loop, they see false signals, identify them, and discard them, progressively losing confidence in their model of the environment. Bad decisions compound as operators redirect the agent based on corrupted assumptions. 

To trap AI agents, deception plants fake credentials, phantom servers, and fabricated topology into the environment model. The agent then acts based on a corrupted map, failing to verify the data it collects. As a result, it makes decisions based on an environment that doesn't exist. Every parallel thread of the attack operates on this bad data simultaneously. The agent is confidently wrong all the time and at scale.

A common objection we hear is that, given enough time and patience, an AI agent will map static decoys over time and eventually find a way around them. Our experience with deception, however, proves otherwise. We’ve discovered that:

  • AI can never be sure it has found all decoys. This uncertainty is identical to what dynamic deception produces. An incomplete map of the environment poisons the OODA loop just as a moving target does.
  • The moment an AI agent slows down to avoid decoys, it surrenders its primary advantage of machine speed, turning this asset into a liability.

Reconnaissance creates another detection surface. Our deception implementation uses network decoys specifically to identify probing behaviors at the edge and internally. It then correlates those signals with telemetry from other tools, augmented with AI analysis. The very act of mapping the environment becomes a trip wire.

 

What four years of using deception and decoy technology looks like

Our rigorous penetration tests and adversary emulations, along with PTI telemetry, confirmed the effectiveness of Zscaler Deception. With every pen test engagement, red teams hit every decoy type every single time. Even more striking was how far ahead of other detection technologies it was in two real-world incidents. Within minutes of attackers making contact with an endpoint, alerts were triggered, completely shutting down privilege escalation and lateral movement. 

Zscaler Deception has proven its value, delivering these positive results for Amex GBT:

  • One engineer runs the entire program, with bandwidth to spare
  • Minutes (sometimes less) for detection of endpoint incidents
  • Zero false positives during four years of production deployment
  • Low total cost of ownership relative to signal fidelity

 

Key takeaways for taking immediate action

If you're not running an advanced deception program today, you won’t be prepared to combat the attacks that are here now and continually evolving. Here are steps you can take to fortify your defense against agentic AI attacks. 

  • Take stock of your environment: Identify your most critical security gaps.
  • Implement deception technology near your crown jewels first. This is where it’s likely to discover an attack quickly. This first win will give your SOC team high confidence in the value of the solution before the complete rollout.
  • Treat every decoy alert as a confirmed incident: With Zscaler Deception’s zero false positives, you can skip triage and move directly to scoping and response, including autonomous response in appropriate contexts.
  • AI attackers are highly susceptible to deception technology: Their speed and aggressive reconnaissance actually increase the probability of contact with a decoy.
  • Don’t neglect your AI workloads: Make sure you deploy decoys to safeguard these precious assets. 

Above all, recognize that deception and decoy technologies are no longer a supplementary security layer. They have earned a place among your primary defensive mechanisms in an AI-augmented threat landscape.

form submtited
Grazie per aver letto

Questo post è stato utile?

Esclusione di responsabilità: questo articolo del blog è stato creato da Zscaler esclusivamente a scopo informativo ed è fornito "così com'è", senza alcuna garanzia circa l'accuratezza, la completezza o l'affidabilità dei contenuti. Zscaler declina ogni responsabilità per eventuali errori o omissioni, così come per le eventuali azioni intraprese sulla base delle informazioni fornite. Eventuali link a siti web o risorse di terze parti sono offerti unicamente per praticità, e Zscaler non è responsabile del relativo contenuto, né delle pratiche adottate. Tutti i contenuti sono soggetti a modifiche senza preavviso. Accedendo a questo blog, l'utente accetta le presenti condizioni e riconosce di essere l'unico responsabile della verifica e dell'uso delle informazioni secondo quanto appropriato per rispondere alle proprie esigenze.

Ricevi gli ultimi aggiornamenti dal blog di Zscaler nella tua casella di posta

Inviando il modulo, si accetta la nostra Informativa sulla privacy.