AI and automation drive 703% increase in credential compromise attacks

SlashNext has revealed that AI and automation are driving a huge increase in credential compromise attacks, with the threat accelerating at a shocking pace.

How shocking? Well, according to the report, credential theft attacks surged by 703% in the second half of 2024, with a sharp escalation in the use of sophisticated phishing kits and social engineering tactics.

The numbers get more concerning, if thatโ€™s possible, when you realise that 80% of embedded malicious links in emails were zero-day threats.

Letโ€™s stick with those numbers. After all, what are threat intelligence reports for if not to appeal to statistic nerds such as myself?

During peak periods, users faced an average of 3-6 threats per week, up to 600 mobile threats per user on average. Oh, and social engineering-based attacks rose by 141% in the last six months.

High figures, no surprises

None of this surprises me, and it shouldn’t surprise you either. Just keep reading the cybsersecurity news and analysis here at TechFinitive, and youโ€™ll be well aware of the threat posed by both AI and automation in todayโ€™s threat landscape.

From deepfake voice-cloning scams and AI-assisted ransomware threats through to the overall failure in readiness to address the AI-threats issue, the problem has been hiding in plain sight for quite some time now. No wonder those numbers are so high and so worrying.

โ€œThe 703% increase in credential phishing and 141% rise in social engineering attacks align with the expanded use of generative AI,โ€ said Callie Guenther, Senior Manager of the Cyber Threat Research Team at managed detection and response provider Critical Start.

She added this this “enables attackers to produce natural-language phishing content at scale, localise campaigns across languages, and automate deep personalisation”.

When it comes to attack automation, Guenther warned, the zero-day links statistic reflect its use within phishing infrastructures. โ€œAttackers are using tools that dynamically generate unique phishing URLs and evade static detection methods,โ€ she said.

โ€œThese evade-and-adapt phishing kits modify their behavior in real-time, depending on environmental signals such as IP addresses and user agents, complicating traditional takedown efforts.โ€

Fighting AI credential attacks with AI

Nicole Carignan, Vice President of Strategic Cyber AI at Darktrace, said that we should be fighting AI with AI.ย 

โ€œAs sophistication of phishing attacks continue to grow,โ€ she said, โ€œorganisations cannot rely on employees to be the last line of defence against these attacks.โ€

Instead, they must โ€œuse machine learning-powered tools that can understand how their employees interact with their inboxes and build a profile of what activity is normal for users, including their relationships, tone and sentiment, content, when and how they follow or share links.โ€

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.