This topic is prone to two extremes: either it’s hyped up as the end of the world, or it’s dismissed out of hand. Viewed objectively, AI is changing the economics of cyberattacks, but it hasn’t created a completely new type of attack.
The three most noticeable changes
Scams via email and text messages. In the past, the easiest telltale sign was grammatical errors in the writing style. That sign has disappeared. Worse still, the content can be personalized based on each person’s publicly available information, targeting tens of thousands of people at a time.
Voice and image spoofing. A few dozen seconds of audio recording are enough to create a convincing imitation of someone’s voice. Scams like “the boss is calling and asking for an urgent bank transfer” become much more convincing.
Vulnerability scanning. Reading source code to find vulnerabilities is something AI does quite well. This helps both attackers and defenders, but defenders have the advantage: they have the source code from the start.
What Hasn't Changed
Most successful breaches still occur through the same old entry points: weak and reused passwords, unpatched software, misconfigurations that expose services to the Internet, and employees who fall for phishing scams. AI makes the phishing step easier, but it cannot bypass two-factor authentication using a hardware token.
What aspects of the defense should be adjusted?
- Stop relying entirely on "what looks real." The payment approval process must be verified through an independent channel, not based on a familiar-sounding voice or email address
- Anti-phishing authentication — physical security tokens or passkeys, since they’re tied to the domain and can’t be redirected to a fake page
- Reduce the attack surface — every service that doesn’t need to be exposed to the Internet is one less place where AI can’t help an attacker
- Conduct drills based on new scenarios—test with well-crafted phishing emails and voice-spoofed calls, as these are the types of attacks employees will encounter
A fundamental rule: Verification must go through a different channel than the one used to receive the request. If you hear your boss’s voice on the phone, call back using the number you have saved.
Thảo luận