cd /news/artificial-intelligence/ai-powered-cyberattacks-are-scaling-… · home topics artificial-intelligence article
[ARTICLE · art-74249] src=thecoinheadlines.com ↗ pub= topic=artificial-intelligence verified=true sentiment=↓ negative

AI-powered cyberattacks are scaling fast: Here’s how companies can adapt and respond

Britain's National Cyber Security Centre expects AI to increase the frequency and intensity of cyber threats by improving existing attack methods, with Google and Microsoft documenting threat actors using AI across the entire attack chain from target research to post-compromise activity. Microsoft reported that North Korean group Jasper Sleet used AI to create fraudulent identities and résumés for remote IT workers, while the FBI and Europol confirm criminals are using AI to expand phishing, impersonation, and fraud globally.

read6 min views1 publishedJul 26, 2026
AI-powered cyberattacks are scaling fast: Here’s how companies can adapt and respond
Image: Thecoinheadlines (auto-discovered)

Artificial intelligence is helping cyberattackers move faster across nearly every stage of a cyber operation, including target research, vulnerability discovery, identity creation, malware development, credential theft and analysis of stolen data.

The biggest change AI is bringing to cyber operations is scale, as it can support tasks once handled by separate researchers, translators, developers and social-engineering specialists, helping attackers launch more campaigns, reach more victims and adapt quickly when a tactic fails.

Britain’s National Cyber Security Centre expects AI to increase the frequency and intensity of cyber threats by improving existing methods rather than creating an entirely new class of attack. It identified reconnaissance, vulnerability research, exploit development, social engineering, basic malware generation and the processing of stolen data as areas already benefiting from the technology.

AI is speeding up the entire attack chain

Google and Microsoft have documented threat actors using AI across the attack chain, from target research and vulnerability analysis to scripting, malware development, phishing support and post-compromise activity. Once inside a network, attackers can use the technology to map unfamiliar systems, identify high-value accounts, sift through stolen files and extract information useful for extortion or further compromise.

Microsoft said generative AI was being used to produce phishing messages, translations, code and malware components, while Google observed similar use by government-backed groups for targeting and technical research. Google added, however, that AI had not yet delivered breakthrough capabilities that fundamentally changed the threat landscape.

AI can also support the creation of look-alike websites, fake professional profiles and synthetic audio or video. A scammer who previously struggled to communicate naturally in a target’s language can now produce fluent messages, while an attacker impersonating an executive can prepare emails, voice calls and meeting material that reinforce the same false identity.

North Korean operations offer one clear example

Microsoft said a group it tracks as Jasper Sleet used AI to study job advertisements, create tailored résumés and build fraudulent professional identities for North Korean remote IT workers seeking positions at legitimate companies.

Face-swapping tools were used to place workers’ faces onto stolen identity documents, while voice-changing software helped some applicants conceal their accents during interviews.

Microsoft said AI was also used to maintain the deception after employment began by translating communications, generating professional responses and helping workers maintain a consistent writing style.

North Korea is one of the clearest examples because of the scale and coordination of its AI-supported operations, but the pattern is global.

In the United States, the FBI says criminals are using AI to expand phishing, impersonation and fraud, while Europol reports that networks targeting Europe are using generative AI to automate activity, personalize social engineering and reach more victims.

Ransomware benefits from the same machinery

Ransomware operators are benefiting from the same AI-driven gains seen across the wider cyberattack chain, using the technology to sharpen phishing, impersonation and credential-theft campaigns even when it does not carry out the final encryption.

In the UAE, Proofpoint said AI was helping attackers write more believable phishing messages, impersonate trusted people more effectively and research how organizations communicate before launching an attack.

A successful attack may begin with an email, QR code, phone call, fake meeting or compromised account. Once credentials are captured, attackers can enter systems, move through a network, steal sensitive data and prepare for encryption, extortion or both.

Attacks now look like normal message s

Proofpoint surveyed 953 full-time cybersecurity professionals across 12 countries, including the UAE, between March and April 2026, with all respondents working for organizations that had experienced a ransomware attack.

Proofpoint said 83% of surveyed UAE organizations believed AI had increased the effectiveness of the attack, including 36% that reported a significant impact. The findings suggest ransomware is moving beyond the familiar image of locked computers and encrypted files, becoming a longer extortion campaign built around stolen identities, sensitive data and repeated demands.

In the UAE, phishing emails and other forms of email-based social engineering were identified as the primary entry point in 30% of ransomware incidents. The report separately found that malicious attachments were the most commonly recorded initial threat at 57%, followed by QR-code phishing at 55% and telephone-based delivery at 45%.

More than a third of affected UAE organizations said employees did not suspect the attack because it appeared authentic, while 30% attributed the incident to users interacting with malicious content.

“AI hasn’t fundamentally changed ransomware, but it has materially improved the attacks that lead to ransomware,” Proofpoint Chief Strategy Officer Ryan Kalember said.

Paying does not always end the crisis

Proofpoint said 83% of surveyed UAE organizations affected by ransomware had data stolen during the incident, giving attackers leverage beyond the initial disruption, as the information could support further demands, be sold on criminal marketplaces or be exploited in additional attacks.

Despite repeated official warnings against ransom payments, more than four in five affected UAE organizations, or 81%, paid, yet nearly half of them, or 47%, were later hit with another demand.

The figures underline how ransomware has become less like a one-off transaction and more like an extended negotiation in which criminals can threaten encryption, data leaks and continued access at the same time.

Defenses must assume deception may succeed

Organizations cannot expect employees to identify every realistic email, cloned voice or synthetic video. Training remains important, but it should be supported by procedures that prevent one convincing interaction from becoming a full network compromise.

Requests involving payments, passwords, sensitive files or changes to account access should be confirmed through a separate, trusted channel. Employees receiving an unusual message from an executive should contact that person using a known number or established internal system rather than replying through the same email, call or meeting link.

Official cyber guidance also recommends evaluating both the content and its source because increasingly realistic manipulated media may defeat traditional visual checks.

CISA advises organizations to introduce phishing-resistant multifactor authentication, particularly for email, remote access and privileged accounts. It also recommends email-authentication controls such as DMARC, timely software updates, restricted administrative privileges, network segmentation and offline or protected backups that attackers cannot easily alter or encrypt.

Companies should also monitor unusual account behavior, including logins from unfamiliar locations, unexpected remote-access tools, sudden privilege changes and large transfers of company data.

The broader lesson is not that AI itself is the threat, as the same technology is also helping defenders analyze activity, identify anomalies and respond more quickly. What is changing is that attackers can now gain many of the same productivity benefits, allowing them to reach more targets and recover faster when one method fails.

That makes resilience more important than perfect detection, meaning organizations should prioritize verifying identities, limiting access, protecting backups and reporting suspicious activity quickly, since a ransomware campaign may appear routine until attackers have already gained unauthorized access.

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @national cyber security centre 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/ai-powered-cyberatta…] indexed:0 read:6min 2026-07-26 ·