{"slug": "assume-ai-cybersecurity-attacks-are-the-future-43-of-companies-have-already-it", "title": "Assume AI cybersecurity attacks are the future: 43% of companies have already experienced it", "summary": "43% of organizations have experienced AI-enhanced or AI-generated phishing attacks, and 37% have encountered AI-augmented malware, according to CDW's 2026 Security Research Report based on a survey of 951 IT decision-makers. The report reveals an AI arms race between cyberattackers and defenders, with 41% of companies planning to deploy AI-driven threat detection systems. 'We should be concerned about the increasing ability of AI as a technology to discover and exploit weaknesses,' said Buck Bell, director of CDW's Global Security Strategy Office.", "body_md": "# Assume AI cybersecurity attacks are the future: 43% of companies have already experienced it\n\n*Follow ZDNET: *[Add us as a preferred source](https://www.google.com/preferences/source?q=zdnet.com)* on Google.*\n\n### ZDNET's key takeaways\n\n- New CDW research shows AI use in cyberattacks is increasingly common.\n- 43% of organizations surveyed have experienced AI-enhanced phishing attacks.\n- 41% of companies plan to use AI in their cyber defenses.\n\nForty-three percent of organizations have experienced AI-enhanced or AI-generated phishing attacks, and 37% have encountered AI-augmented malware, according to a new survey.\n\nCDW's 2026 Security Research Report is based on a survey of 951 IT decision-makers across a variety of industries. Published Monday, the research reveals what appears to be an AI arms race between cyberattackers and defenders. Many organizations are considering investing in AI threat detection, training, and controls to combat the new face of modern cyber threats: AI techniques, tactics, and technologies.\n\n## AI-driven cyberattacks, by the numbers\n\nThere are serious numbers in the report that deserve our particular attention. One or two cyber incidents against high-profile organizations involving a sophisticated AI model is one thing, but there's an undercurrent of quiet, malicious AI attack development that is far more likely to impact the average company.\n\nAccording to the report:\n\n- 43% of organizations have experienced AI-enhanced or AI-generated phishing attacks.\n- 37% of respondents reported encountering AI-powered malware.\n\n**Also: AI agents are fast, loose, and out of control, MIT study finds**\n\nIn addition, when survey respondents were asked which AI-enabled cybersecurity threats pose the greatest risk to their organizations, 25% said AI-generated phishing and social engineering attacks were most concerning, followed by AI-powered malware and automated attack tools (21%). These attack vectors appear to have overshadowed worries about deepfakes, with only 8% of respondents citing [deepfake impersonation](https://www.zdnet.com/article/is-your-business-ready-for-a-deepfake-attack-4-steps-to-take-before-its-too-late/) as the biggest risk to their companies.\n\n## An AI breach is a matter of when, not if\n\nFor years, security experts have warned companies to adopt the mindset that they will experience a security breach at some stage -- it's a matter of when, not if.\n\nWith the rapid emergence of AI-backed, fully autonomous, agentic attacks, this message is more pertinent than ever.\n\n**Also: OpenAI's attack agent did exactly what it was told - just more relentlessly than expected**\n\nIt was only this month that Hugging Face revealed an intrusion [by agentic AI](https://www.zdnet.com/article/hugging-face-breach-blamed-on-ai-agent/). Although the organization's own AI defenses caught it, the case highlights what companies face in keeping their systems, data, and customer records safe.\n\nIn total, 41% of respondents to the CDW survey said they planned to deploy AI-driven threat detection systems in the near future, with 49% focusing on threat and anomaly detection, 47% exploring threat intelligence analysis, and 42% opting for phishing and fraud detection.\n\n\"We should be concerned about the increasing ability of AI as a technology to discover and exploit weaknesses,\" commented Buck Bell, director of CDW's Global Security Strategy Office. \"It's incumbent now on security practitioners to leverage similar tools to find those weaknesses before the bad guys find them.\"\n\nThere are also risks associated with the internal use of AI for business and productivity purposes. Without proper training and controls, employees may accidentally feed sensitive corporate data into LLMs -- exposing information and potentially handing it over for AI training. Without safety guardrails, AIs tasked with company functions could exceed their assigned roles and disrupt operations.\n\nThankfully, more organizations are now aware of these risks. In total, 46% of respondents say they frequently assess AI infrastructure and closely monitor it, while 45% intend to train their employees on safe and secure AI use. Furthermore, 44% are working on implementing data protection controls for AI systems and integrating AI systems into existing security monitoring workflows.\n\n**Also: 10 ways AI can inflict unprecedented damage **\n\nWhat portion of organizations' AI-related budgets should go to near-term productivity goals versus longer-term security and resiliency needs? If we are going to stop malicious AI from overwhelming organizations already hard-pressed to handle traditional security threats, we face some difficult decisions about investment priorities.\n\n#### Security\n\n[Editorial standards](/editorial-guidelines/)", "url": "https://wpnews.pro/news/assume-ai-cybersecurity-attacks-are-the-future-43-of-companies-have-already-it", "canonical_source": "https://www.zdnet.com/article/assume-ai-cybersecurity-attacks-are-the-future-43-percent-of-companies-have-already-experienced-it/", "published_at": "2026-07-27 14:00:40+00:00", "updated_at": "2026-07-27 14:26:04.388097+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-safety", "ai-policy"], "entities": ["CDW", "Buck Bell", "Hugging Face", "ZDNET"], "alternates": {"html": "https://wpnews.pro/news/assume-ai-cybersecurity-attacks-are-the-future-43-of-companies-have-already-it", "markdown": "https://wpnews.pro/news/assume-ai-cybersecurity-attacks-are-the-future-43-of-companies-have-already-it.md", "text": "https://wpnews.pro/news/assume-ai-cybersecurity-attacks-are-the-future-43-of-companies-have-already-it.txt", "jsonld": "https://wpnews.pro/news/assume-ai-cybersecurity-attacks-are-the-future-43-of-companies-have-already-it.jsonld"}}