Skip to content

AI Significantly Improves Effectiveness of Ransomware Attacks

The bottom line: AI optimizes existing attack vectors such as phishing and credential abuse, while ransomware campaigns simultaneously employ data theft and multi-layered extortion – human judgment remains the primary attack surface.

The current “AI-Era Ransomware Report 2026” from Proofpoint shows: AI significantly increases the success rate of ransomware campaigns by making phishing more credible and implementing identity theft more efficiently. 66 percent of German companies observe a direct connection between AI use and improved attack effectiveness.

The report is based on a survey of 953 cybersecurity experts from twelve countries. In Germany, 66 percent of affected organizations see AI as a factor for increased attack effectiveness: 26 percent report significant increases, 40 percent report moderate impact. Only 5 percent found no evidence of AI use in attacks.

AI does not change the fundamental attack mechanics, but rather optimizes existing methods. Attackers use it to formulate phishing messages more convincingly, imitate stolen identities more authentically, and exploit compromised access credentials more strategically. Phishing emails were the entry point in 37 percent of incidents, malicious links and infected attachments were used in 45 percent each. Theft of login credentials played a role in 37 percent, business email compromise in 26 percent.

Ransomware no longer primarily targets data encryption. In 67 percent of affected German companies, sensitive data was stolen and subsequently used as a means of extortion – either for further demands, sale on criminal platforms, or to prepare for follow-up attacks. Cybercriminals thereby exert pressure over longer periods and leverage multiple means simultaneously: encrypted systems, stolen information, and publication threats.

The human remains the weak link: 36 percent of companies reported that employees considered the attacks legitimate, 35 percent attributed incidents to employees deliberately interacting with malicious content. In this way, AI significantly complicates the distinction between genuine business communication and professionally designed fraud attempts for users.

Ransom payments offer no protection: 41 percent of affected German companies made payments after demands. Of these, 29 percent were later extorted again – an indication of professionalized, multi-phase attack campaigns.


Source: www.it-daily.net · Published July 24, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: