A new study from Kaspersky (yes, it still exists) has revealed that one in five enterprises fail to adequately protect their organisation from AI-powered threats.ย You might be inclined to put this down to end of the year speculative โthreats of the futureโ ball-gazing, but you would do so at risk of ignoring a very real and present danger to your data.
Threat intelligence analysts at Group-IB have, during the last few days alone, issued a report covering the use of AI-generated voices in a large-scale campaign targeting consumers of gaming applications.
The same threat intel service recently warned of a cyberattack on a โprominent Indonesian financial institutionโ that used AI-deepfakes, virtual camera software and face-swapping technology to bypass biometric banking protections that included liveness detection.
Still think that the AI threat isnโt something you should taking seriously, at least not yet? OK, a few more examples to shake you into acceptance: the deepfake impersonation fraud against the CEO of a cybersecurity company only failed because the attackers had used a recording of him giving a keynote presentation to fake his voice. A giveaway because his staff knew he had speech anxiety and his voice changed from normal when doing so.
Thatโs the CEO of a cybersecurity company, remember. Another cybersecurity consultant was very nearly compromised by a tech support scam driven by an AI-generated chatbot. Or how about another using AI-generated copyright violation messaging?
Time to prepare for AI cyberattacks
Like it or not, AI has become good enough, easy enough to use and – perhaps most importantly – cheap enough to deploy that ignoring it is no longer an option.
Yet, โdespite understanding the severity of the threat,โ Kaspersky said, many businesses are struggling to keep pace with the rapid evolution of AI-driven cybercrime.
โBarriers such as skill shortages, lack of AI-powered tools, and the complexity of managing advanced cybersecurity infrastructures leave many organizations vulnerable,โ the report warned.
Here are the numbers that should have you worried and looking for answers:
- 19% of respondents said they have considerable gaps in their cyber protection.
- 44% of organisations cited a lack of AI-related cybersecurity training for employees as a critical issue.
- 44% said the complexity of managing cybersecurity infrastructure makes it harder to stay ahead of attackers.
- 43% admitted that they lacked modern AI-powered cybersecurity solutions.
- 41% struggled with a lack of information from external experts about the evolving AI-related threat landscape.
Come on folks, please, start taking the AI threat seriously. Get off your collective arses now, before it is too late. Donโt let 2025 be the year you discover the costly consequence of not believing the hype.
Related cyberattack articles