2 min Security

AI makes ransomware more effective in 65 percent of cases

AI makes ransomware more effective in 65 percent of cases

AI does not fundamentally change ransomware, but it makes the attacks leading up to it much more convincing. Nearly two-thirds of affected organizations say that AI increased the effectiveness of the attack.

This is according to research by Proofpoint. The company surveyed 953 security professionals in twelve countries. The conclusion is clear: modern ransomware is no longer a simple encryption attack. It has evolved into a long-term extortion campaign, in which attackers first steal login credentials and sensitive data before actually deploying the ransomware.

Among the affected organizations, 28 percent say that AI made the attack significantly more effective. Another 37 percent noticed a partial improvement. Together, that adds up to 65 percent. Only 9 percent saw no evidence whatsoever of AI use.

Humans as the biggest vulnerability

The primary entry points all revolve around human interaction. Phishing emails and other email-based social engineering tactics were the starting point in 34 percent of incidents. Malicious links (47 percent) and attachments (46 percent) were the most common initial threats, followed by credential harvesting (36 percent) and Business Email Compromise (35 percent).

“AI hasn’t fundamentally changed ransomware, but it has materially improved the attacks that lead to ransomware,” says Ryan Kalember, Chief Strategy Officer at Proofpoint. According to him, organizations that treat ransomware as an endpoint or recovery issue are missing the very elements where these attacks begin: people, identities, and trusted communications.

Paying the ransom solves nothing

Despite all the warnings, more than half (54 percent) of the affected organizations paid the ransom. Yet more than a third (37 percent) subsequently received a second extortion demand. Nearly two-thirds confirmed that data had been stolen.

The researchers point out that the attacks succeed through manipulation, not technical failure. Two in five said employees did not recognize the attack because it appeared authentic.

Tip: Proofpoint acquires AI security company Acuvity