Trending Topics

AI and automation drive 703% increase in credential compromise attacks
SlashNext has revealed that AI and automation are driving a huge increase in credential compromise attacks, with the threat accelerating at a shocking pace.
How shocking? Well, according to the report, credential theft attacks surged by 703% in the second half of 2024, with a sharp escalation in the use of sophisticated phishing kits and social engineering tactics.
The numbers get more concerning, if that’s possible, when you realise that 80% of embedded malicious links in emails were zero-day threats.
Let’s stick with those numbers. After all, what are threat intelligence reports for if not to appeal to statistic nerds such as myself?
During peak periods, users faced an average of 3-6 threats per week, up to 600 mobile threats per user on average. Oh, and social engineering-based attacks rose by 141% in the last six months.
High figures, no surprises
None of this surprises me, and it shouldn’t surprise you either. Just keep reading the cybsersecurity news and analysis here at TechFinitive, and you’ll be well aware of the threat posed by both AI and automation in today’s threat landscape.
From deepfake voice-cloning scams and AI-assisted ransomware threats through to the overall failure in readiness to address the AI-threats issue, the problem has been hiding in plain sight for quite some time now. No wonder those numbers are so high and so worrying.
“The 703% increase in credential phishing and 141% rise in social engineering attacks align with the expanded use of generative AI,” said Callie Guenther, Senior Manager of the Cyber Threat Research Team at managed detection and response provider Critical Start.
She added this this “enables attackers to produce natural-language phishing content at scale, localise campaigns across languages, and automate deep personalisation”.
When it comes to attack automation, Guenther warned, the zero-day links statistic reflect its use within phishing infrastructures. “Attackers are using tools that dynamically generate unique phishing URLs and evade static detection methods,” she said.
“These evade-and-adapt phishing kits modify their behavior in real-time, depending on environmental signals such as IP addresses and user agents, complicating traditional takedown efforts.”
Fighting AI credential attacks with AI
Nicole Carignan, Vice President of Strategic Cyber AI at Darktrace, said that we should be fighting AI with AI.
“As sophistication of phishing attacks continue to grow,” she said, “organisations cannot rely on employees to be the last line of defence against these attacks.”
Instead, they must “use machine learning-powered tools that can understand how their employees interact with their inboxes and build a profile of what activity is normal for users, including their relationships, tone and sentiment, content, when and how they follow or share links.”
Related cybersecurity news by Davey Winder
- Don’t call it quishing but, please, do take it seriously
- 1 in 5 enterprises admit they aren’t prepared for AI cyberattacks
- Why cybersecurity is sometimes just an illusion
