
Observe ZDNET: Add us as a preferred source on Google.
ZDNET’s key takeaways
- New CDW analysis reveals AI use in cyberattacks is more and more frequent.
- 43% of organizations surveyed have skilled AI-enhanced phishing assaults.
- 41% of corporations plan to make use of AI of their cyber defenses.
Forty-three p.c of organizations have skilled AI-enhanced or AI-generated phishing assaults, and 37% have encountered AI-augmented malware, in response to a brand new survey.
CDW’s 2026 Safety Analysis Report relies on a survey of 951 IT decision-makers throughout a wide range of industries. Printed Monday, the analysis reveals what seems to be an AI arms race between cyberattackers and defenders. Many organizations are contemplating investing in AI menace detection, coaching, and controls to fight the brand new face of contemporary cyber threats: AI methods, techniques, and applied sciences.
AI-driven cyberattacks, by the numbers
There are critical numbers within the report that deserve our specific consideration. One or two cyber incidents in opposition to high-profile organizations involving a classy AI mannequin is one factor, however there’s an undercurrent of quiet, malicious AI assault improvement that’s way more prone to impression the common firm.
In accordance with the report:
- 43% of organizations have skilled AI-enhanced or AI-generated phishing assaults.
- 37% of respondents reported encountering AI-powered malware.
Additionally: AI agents are fast, loose, and out of control, MIT study finds
As well as, when survey respondents have been requested which AI-enabled cybersecurity threats pose the best danger to their organizations, 25% mentioned AI-generated phishing and social engineering assaults have been most regarding, adopted by AI-powered malware and automatic assault instruments (21%). These assault vectors seem to have overshadowed worries about deepfakes, with solely 8% of respondents citing deepfake impersonation as the most important danger to their corporations.
An AI breach is a matter of when, not if
For years, safety specialists have warned corporations to undertake the mindset that they may expertise a safety breach at some stage — it is a matter of when, not if.
With the fast emergence of AI-backed, totally autonomous, agentic assaults, this message is extra pertinent than ever.
Additionally: OpenAI’s attack agent did exactly what it was told – just more relentlessly than expected
It was solely this month that Hugging Face revealed an intrusion by agentic AI. Though the group’s personal AI defenses caught it, the case highlights what corporations face in conserving their programs, knowledge, and buyer data protected.
In complete, 41% of respondents to the CDW survey mentioned they deliberate to deploy AI-driven menace detection programs within the close to future, with 49% specializing in menace and anomaly detection, 47% exploring menace intelligence evaluation, and 42% choosing phishing and fraud detection.
“We must be involved in regards to the rising capacity of AI as a know-how to find and exploit weaknesses,” commented Buck Bell, director of CDW’s World Safety Technique Workplace. “It is incumbent now on safety practitioners to leverage related instruments to search out these weaknesses earlier than the dangerous guys discover them.”
There are additionally dangers related to the inner use of AI for enterprise and productiveness functions. With out correct coaching and controls, staff might by accident feed delicate company knowledge into LLMs — exposing info and doubtlessly handing it over for AI coaching. With out security guardrails, AIs tasked with firm capabilities might exceed their assigned roles and disrupt operations.
Fortunately, extra organizations at the moment are conscious of those dangers. In complete, 46% of respondents say they steadily assess AI infrastructure and intently monitor it, whereas 45% intend to coach their staff on protected and safe AI use. Moreover, 44% are engaged on implementing knowledge safety controls for AI programs and integrating AI programs into present safety monitoring workflows.
Additionally: 10 ways AI can inflict unprecedented damage
What portion of organizations’ AI-related budgets ought to go to near-term productiveness targets versus longer-term safety and resiliency wants? If we’re going to cease malicious AI from overwhelming organizations already hard-pressed to deal with conventional safety threats, we face some tough choices about funding priorities.
