By Darren Guccione
We’re entering a new and novel frontier of cyber attacks, thanks to artificial intelligence (AI). AI has provided cybercriminals with a sophisticated toolkit of advanced weaponry that can be used for nefarious purposes ranging from fraud to advanced social engineering. Recently, for example, a company worker in Hong Kong paid out £20m in a deepfake conference call scam, exemplifying the believability and very real consequences of these kinds of attacks. It’s no wonder new research has revealed that AI-powered attacks and deepfake technology were ranked by IT security leaders as the top two most concerning cyber attack vectors for 2024.
This ‘AI toolkit’ adds another string to the bow of cybercriminals: a convenient convergence of tools to launch their attacks. A generative AI tool can be used to write legitimate looking phishing emails, for example, which is both fast and cost-effective for opportunistic cybercriminals. AI impersonation, similarly, helps provide a level of feigned legitimacy which can be exploited in social engineering attacks.
Ultimately, AI-generated collateral is looking increasingly more ‘human’ and harder to identify. So, how can businesses protect themselves?
Internal controls and privileged access
Privileged access management allows businesses to secure and tightly control access to accounts and systems that hold sensitive information, such as IT admin accounts. If the wrong person were to gain access to these accounts, sensitive information could be stolen, leaked or used in double extortion attempts.
Business leaders need to reconsider who has access to networks and accounts which provide the keys to their organization’s most sensitive information. A sophisticated deepfake impersonating a C-suite executive would be less effective in targeting a mid-level employee if, for example, that employee was unable to access systems that hold the sensitive data cybercriminals seek.
Education and awareness training that evolves with the times
Research has shown that global IT leaders believe phishing, malware, and ransomware are the fastest-growing cyber attack vectors. AI has, undoubtedly, made these attacks even easier (and quicker) for cybercriminals.
As threats evolve, awareness training should too. By educating employees on the new ways cybercriminals are targeting organizations – including AI-based attacks – employees can spot and report anything that looks suspicious. However, organizations should also have a robust and stacked cyber security program that does not solely rely on end-user education.
Keep software and devices up to date, secure accounts
Another way organizations can secure accounts and reduce the likelihood of being targeted by AI attacks is by regularly updating software and devices as soon as updates and patches are made available. Being efficient when it comes to patching security flaws and vulnerabilities can reduce the window of opportunity that hackers have to exploit them.
Additionally, all data should be backed up. In the event of a malware attack, backed-up data protects an organization from losing its information permanently. For extra security, encrypted back-up services can be beneficial for organizations.
Avoid giving out personal or sensitive information
Common AI attacks include AI-generated phishing emails, AI impersonation and deepfakes. Cybercriminals leverage AI to make scams more believable. When it comes to AI impersonation, for example, scammers can use AI algorithms to analyse large amounts of data, generating a fake persona. A technique called synthesis can even impersonate someone’s voice. Combined, these techniques can create a convincing impersonation. Deepfakes are similar in this way, leveraging AI to alter a person’s face or body to look like someone they’re not.
What all these techniques have in common is that they help cybercriminals look and act more legitimate than ever. That’s why it’s important to exercise caution when giving out personal or sensitive information to anyone online, even if they appear ‘real’. It’s important to ask yourself if the request is unusual or out of the blue. Consider a second form of verification before you think about sending any sensitive information and consider sending anything sensitive using an encrypted service so it’s only seen by the person it’s intended to be seen by.
Implement strong password practices
One of the most common ways AI is being leveraged by cybercriminals is through AI-based password cracking. Password cracking is a technique commonly used by cybercriminals to hack passwords. Specialist password-cracking software can automatically attempt brute force entry into an account using variations of commonly used passwords and trying every possible variation until it’s successful. AI has made this process radically quicker and more successful.
The importance of using strong passwords can never be overstated. As AI gets more sophisticated and quicker at guessing passwords, businesses must ensure that employees are practising good password hygiene. But with multiple accounts and multiple passwords to remember, employees may be inclined to reuse passwords or write them down, which is equally as dangerous. One way organizations can reduce password reuse and enforce strong password creation is by implementing a secure password manager.
There’s no need to reinvent the wheel
When it comes to evolving attack vectors, there’s often a focus on creating a new solution. However, the fundamental rules of protecting yourself and your organization remain as relevant as ever. Basic cyber security measures, such as creating strong and unique passwords, enabling multi-factor authentication, training employees, and keeping software up to date, are frequently overlooked but exceptionally important, no matter how evolved the threat landscape becomes.
The author
Darren Guccione is Co-Founder and CEO of Keeper Security.






