This was inevitable. AI lowers the barrier to entry for cybercrime just like it does for everything else.
The concerning part isn't that someone used AI for attacks - it's how "unprecedented" the scale became. Automation lets bad actors operate at a level that would have required entire teams before.
Defense needs to scale up accordingly. Manual security reviews can't keep pace with automated attacks.