For years, organizations trained employees to spot fake communications: look for poor grammar, check the sender’s email address, be wary of urgent requests and don’t click suspicious links. It was sensible advice because cybercriminals often gave themselves away. Artificial intelligence has changed that.
Today’s AI-enabled attacks don’t necessarily contain obvious mistakes. They can be grammatically flawless, personalized, contextually relevant and convincing enough to resemble the everyday emails, messages and requests employees receive from colleagues, customers or suppliers. The challenge is no longer spotting obvious scams. It’s making good trust decisions when almost every interaction looks genuine.
That shift is reflected in Mimecast’s latest State of Human Risk research. While 65% of organizations surveyed in Singapore and Australia believe an AI-enabled attack against their organization is inevitable within the next 12 months, 79% are concerned about AI being used as an attack vector. Yet 60% admit they are not fully prepared for AI-driven threats that exploit human vulnerabilities.
The numbers tell an interesting story. Organizations know the threat is real. Many are still figuring out how to respond.
AI hasn’t changed the objective. It’s changed the scale.
Cybercriminals have always exploited trust. Phishing, business email compromise and social engineering all rely on persuading someone to believe something that isn’t true or act on a request they shouldn’t. Generative AI hasn’t created those tactics. It...
Subscribe to Continue Reading
Get exclusive AI insights for marketers and business leaders - newsletters, strategies, and expert tips included.


