AI & TechArtificial IntelligenceCybersecurityNewswireTechnology

How AI Made Two-Thirds of Ransomware Attacks Worse

▼ Summary

– 65% of organizations hit by ransomware said AI increased the attack’s effectiveness by enabling more convincing phishing, impersonation, and credential theft.
– AI tools help attackers produce lures that appear as legitimate business communications, removing traditional red flags like clumsy phrasing or mismatched logos.
– Initial ransomware entry points commonly involve human interaction: 47% used malicious links, 46% malicious attachments, and 36% credential harvesting.
– 40% of respondents said attacks bypassed controls because the initial lure appeared legitimate enough that employees suspected nothing wrong.
– A third of organizations reported existing email security controls failed to detect the attack entirely, and a quarter cited misconfiguration or gaps in controls.

A new global survey from Proofpoint reveals a stark reality: AI has made ransomware attacks significantly more dangerous, with nearly two-thirds of affected organizations reporting that artificial intelligence boosted the effectiveness of the breaches they suffered.

The study, which polled cybersecurity professionals worldwide, found that 65% of organizations hit by ransomware said AI played a direct role in making the attack more potent. Cybercriminals are now leveraging these tools to craft far more convincing phishing emails, impersonation schemes, and credential theft campaigns than ever before.

The findings were published July 22 in the 2026 AI-Era Ransomware Report, which noted that “across the incidents examined in this report, evidence of AI involvement was the norm, not the exception.” The analysis shows that human interaction remains the primary entry point for ransomware. Among the incidents studied, 47% involved malicious links, 46% used malicious attachments, and 36% relied on credential harvesting at some stage of the attack chain.

When asked why existing security controls failed, 40% of respondents said the initial lure appeared so legitimate that employees had no reason to suspect anything was wrong. In the past, telltale signs like clumsy phrasing, mismatched logos, or suspicious login pages often gave victims pause. Now, AI tools enable attackers to create lures that seamlessly mimic legitimate business communications.

Ryan Kalember, chief strategy officer at Proofpoint, explained: “AI hasn’t fundamentally changed ransomware, but it has materially improved the attacks that lead to ransomware. Today’s attackers are using AI to create highly convincing phishing emails, malware components like scripts, and credential theft campaigns that exploit human trust at scale. Organizations that continue treating ransomware and data extortion as endpoint or recovery problems are missing what these attacks most frequently begin with: people, identities and trusted communications.”

The threat extends beyond human targets. Enterprise software protections and technical controls are also struggling. A third of surveyed organizations said their existing email security controls failed to detect the attack entirely, while a quarter pointed to misconfiguration or gaps in their security setups.

Proofpoint’s conclusion is direct: “Organizations that want to reduce ransomware risk must focus on stopping attacks at the point of entry, protecting identities from compromise, and responding before attackers can turn access into extortion.”

(Source: Infosecurity Magazine)

Topics

ai ransomware 98% phishing emails 95% credential theft 90% attack entry points 88% security bypass 85% human trust exploitation 82% email security failures 80% impersonation attacks 78% ransomware detection 76% malicious links 74%