AI helps attackers as well as defenders.
How Attackers Use AI
- Phishing: fluent, personalised messages in any language, at scale.
- Social engineering: researching targets and generating convincing pretexts.
- Malware development: assistance writing or modifying code.
- Vulnerability discovery: analysing code and systems for weaknesses faster.
- Automation: agents that perform reconnaissance and parts of attacks with less human effort.
- Impersonation: deepfake voices and video.
What Changes
AI lowers the skill and cost needed for some attacks and increases their volume and polish. Tell-tale signs like poor grammar are no longer reliable indicators of phishing.
Defender Responses
- Phishing-resistant authentication such as passkeys and hardware keys.
- Verification procedures for payments and sensitive requests.
- Faster patching, since vulnerabilities may be found and exploited sooner.
- AI-assisted detection and response.
- Updated security awareness training.
Provider Safeguards
AI providers monitor for and disrupt malicious use of their models, and publish reports on observed misuse.
Stay Informed
Follow threat intelligence on AI-enabled attacks relevant to your sector.