AI in cyberattacks: what is documented and what is still proof of concept
The question we hear most about AI and security starts from a wrong premise: that there is now an “artificial intelligence virus” — something technically new that defence products don’t yet recognise.
That is not what the 2026 reports show. The techniques are the same as ever: phishing, stolen credentials, exploitation of exposed services, extortion. What AI changed was the economics of the attack — what it costs to run, how many targets fit into the same effort, and how much skill you need to start.
The distinction matters because it changes the defence. If the problem were a new technique, the answer would be a new tool. Because the problem is volume and quality applied to known techniques, the answer is to do well what we already know how to do — only now with no slack left.
The numbers, and what each one means
It is worth starting with what is actually measured, because this subject attracts a lot of claims without a source.
- 25% of organisations attacked identified AI use in the incident — one in four. That is from IBM’s Cost of a Data Breach Report 2026, and it represents 56% growth over the previous edition. It is not a projection: it is what victims reported.
- R$ 7.19 million is the average cost of a data breach in Brazil, up 6.5% from R$ 6.75 million in 2024, in the same study. The global average sits around US$ 4.88 million.
- 67.3% of the identified malicious use was code development. Anthropic analysed 832 banned accounts between March 2025 and March 2026; most involved malware creation.
- From 33% to 56% — the share of those actors classified as medium risk or above, comparing the first and second halves of that same period. The average attacker’s capability is rising fast.
- +150% in fraud attempts using manipulated video and audio in Brazil in one year, according to Serasa Experian’s 2026 Identity and Fraud Report. For scale, FEBRABAN recorded R$ 10.1 billion in fraud losses across the financial system in 2024, up 17%.
Notice what these numbers say together: the use is real and measured, but it is still a minority of cases. What matters is not today’s percentage — it is how fast it is climbing.

The three real changes
Scale. What used to need one dedicated operator per target now runs in parallel. A campaign documented by Amazon’s threat intelligence hit edge devices in 55 countries, with a single actor running an automated framework that swept exposed interfaces and executed exploitation paths without human input — compromising more than 600 edge devices in a few weeks.
Quality of the lure. Clumsy, broken language used to be the main warning sign we taught users to look for. That sign is gone. Today the message arrives in the right language, in the company’s own tone, with plausible context.
Barrier to entry. Operations that required a team now fit inside one operator. Between December 2025 and February 2026, Check Point Research documented a single operator compromising nine Mexican government agencies in roughly two months, with more than 5,000 AI-executed commands.
Is there already AI-powered ransomware?
This is the question that comes up most, and the honest answer has two halves — because the two halves get confused, and the confusion leads to the wrong decision.
Yes, the artefact exists — but it is a proof of concept. In August 2025, ESET identified PromptLock, presented as the first AI-powered ransomware. It does not carry a ready-made malicious routine: it carries natural-language instructions that feed a locally hosted model, and that model generates the scripts on the fly to sweep the file system, exfiltrate and encrypt — on Windows, Linux and macOS. Because the code is born different on every run, signature-based detection loses much of its effectiveness.
The detail that changes the reading: PromptLock was never seen in a real attack. It was academic work, attributed to NYU researchers, that surfaced on a public analysis platform. It is a demonstration of feasibility, not a campaign in progress.
And yes, real groups already use AI in ransomware operations — just at other points in the chain, and that is where the effect is felt today:
- Writing and obfuscating variants. The FunkSec group is the most cited example of AI-assisted malware development. Generating variants with different obfuscation is exactly the kind of repetitive work where AI pays off.
- Automating the negotiation. The extortion conversation, which required an operator with time and some command of the victim’s language, can now run at scale.
- Raising the psychological pressure. Content tailored to the victim — in their language, citing their business — makes the threat more credible and the decision to pay more likely.
- Selecting and classifying what was stolen. Reading through what was exfiltrated quickly and identifying what hurts most to expose is reading work at volume.
One trend worth recording alongside this: extortion without encryption is growing. The attacker encrypts nothing — they exfiltrate and threaten to publish. It is faster, it draws less attention from controls that watch for mass encryption, and it neutralises the defence many companies rely on: the backup. Against that model, restoring does not solve anything.
Where else AI is already being used
Social engineering with voice and video. This is the most mature front and the one that hits mid-sized Brazilian companies hardest. The pattern that shows up most is the “CEO fraud”: a call or audio message with a director’s cloned voice asking for an urgent, confidential transfer. It offers the attacker the highest return, because it depends on no vulnerability at all — it depends on hierarchy and haste.
Operation with little human supervision. In November 2025 an espionage operation was dismantled that used a coding assistant to attempt to infiltrate targets with minimal human intervention, covering 30 techniques across 13 tactics of the MITRE ATT&CK framework. That is the difference between AI helping to write and AI running the operation.
Attack tooling as a product. Commercial underground platforms already automate fraud — they generate the email in the victim’s style, extract financial data and create fake calendar invitations to pressure the transfer. The attacker no longer needs to know how to use AI: they buy the result.
A new target: the company’s own AI. The front almost nobody is watching. Three documented patterns: theft of API keys from AI providers, which turn into cost and access on the victim’s account; agent configuration files used as a persistent vector to bypass controls; and malicious instructions hidden in content the assistant will read. If your company gave an assistant access to a system or to data, that assistant became attack surface — and it is probably not in the risk inventory.
What did not change — and therefore still decides
None of the cases above began with something exotic. The way in is still an exposed service left unpatched, a valid credential obtained by deception, or access that should have been removed and was not.
That is good news, because it means the work that protects you is the same as before — only the margin for delay has shrunk. If your scan finds the exposed service in thirty days and the automated attacker finds it in three, the problem is not their AI: it is your deadline.
What to do, in the order that pays
- Close what is exposed, on a short clock. An administration interface published on the internet is the target of automated scanners. Prioritise by what has known exploitation, not by a generic severity score — that is what we cover in managed security.
- Remove trust from voice and image. No transfer, change of bank details or grant of access should be authorised by audio, video or a call — however convincing it sounds. The rule needs to be written down, and the verification needs to happen through an independent, known channel. It is the highest-return defence against the most active front today.
- MFA with no exception that matters. A leaked credential is still the most profitable vector, and the second factor is what makes it useless.
- Assume exfiltration, not just encryption. If extortion without encryption is growing, backup stops being a sufficient defence. What takes its place: knowing where the sensitive data is, limiting who can access it in volume, and detecting anomalous outbound traffic.
- Shorten the gap between it happening and someone knowing. An automated attack is fast; the difference becomes detection. Alerts with an owner and a procedure — observability applied to security.
- Replace the user training. Out goes “look for bad grammar”, in comes “confirm through the agreed channel whenever someone asks for urgency, secrecy or a change of account”. The trigger is the request, not its form.
- Inventory your own AI. Which assistants have access to what, with which key, reading which content. API keys go into the vault and into the rotation cycle, like any other credential.
Defence uses AI too — and that is where it pays most
It is worth stating the other side, without turning it into a sales pitch. AI is good at exactly the work that overloads a security team: reading large volumes of signal and pointing at what breaks the pattern, summarising hundreds of correlated alerts into one incident with a narrative, translating a technical finding into decision-making language, and cutting a list of thousands of vulnerabilities down to what is genuinely exploitable.
It is the same logic we apply in file-estate analysis: the machine reduces the volume to what deserves a human eye. The decision stays with people — and in security, it needs to stay that way.
What this leaves you with
The honest summary for whoever decides: the attacker’s sophistication went up, their cost went down and your deadline shrank. One in four breaches already has AI in the mix, and that fraction grew more than 50% in a year. None of this is solved by buying a tool with “AI” in the name.
If the basics are closed — exposure controlled, access cycled, exploitable vulnerabilities on a clock, alerts with an owner — the company remains defensible, because the documented cases come in through the same doors as always. If the basics are not closed, the attacker’s AI will simply find the hole faster than anyone would have found it before.
And there is a final point that tends to go unnoticed: the front that hits Brazilian companies hardest today is not technical, it is the boss’s voice on the phone. Defending against it costs no licence — it costs a written rule and the discipline to follow it even when the request seems urgent. Especially when it seems urgent.
To go deeper, the cybersecurity and LGPD e-book in the Inove Academy covers the technical controls that underpin the legal obligation — and how to demonstrate them when someone asks for evidence. If your starting point is the endpoint estate, begin with modern workplace.