Skip to main content

911IT Fix

Artificial intelligence is changing cybersecurity in two directions at once: it’s a powerful defensive tool, and it’s increasingly a weapon in the hands of attackers and a liability when misused internally. Four recent incidents, all tied to Los Angeles, show exactly what’s at stake.

AI-generated fake legal citations. In August 2026, the Los Angeles Times and CalMatters reported that lawyers representing State Farm in an LA County house fire insurance dispute submitted court filings containing AI-generated “hallucinated” case law, legal citations that simply didn’t exist. For any Los Angeles business relying on AI tools to draft documents, this is a reminder that AI output still requires human verification before it goes anywhere official.

AI-powered account takeover. In May 2026, KTLA reported on a new phishing toolkit, flagged by the FBI, that allows attackers to hijack Microsoft 365 accounts (Outlook and Teams) without ever needing the victim’s password. These attacks are increasingly automated and personalized using AI, making them harder for employees to spot.

AI chatbots weaponized for cyberattacks. In February 2026, the Los Angeles Times reported that a hacker exploited Anthropic’s Claude AI chatbot to help carry out a series of cyberattacks against Mexican government agencies. It’s a clear example of how generative AI tools can be turned into attack infrastructure, not just used to defend against it.

Human error still opens the door. In December 2025, Harbor Regional Center, a Los Angeles-area nonprofit, reported a data breach after a single employee email account was compromised, exposing patient and client information. No AI was involved on the attacker’s side here, but it’s a reminder that basic account security fundamentals, like multi-factor authentication, remain the foundation everything else is built on.

What this means for your business: treat AI-generated content (legal, marketing, or code) as a draft that needs human review, not a finished product. Make sure every account, especially Microsoft 365 and email, has multi-factor authentication enabled. And work with an IT partner who monitors for the newer, AI-assisted attack patterns, not just traditional malware signatures. Schedule a free consultation to see how prepared your business is for this next wave of threats.