AI supercharges cybercrime: identity becomes the battleground as deepfake attacks and shadow accounts surge

Venture Beat

The gist

AI-powered cybercrime is exploding, turning digital identity into the new battleground as deepfakes, shadow accounts, and mega breaches overwhelm old-school defenses.

What to know

  • Vishing attacks surged 449% and AI-driven phishing now outsmarts traditional tools with hyper-personalization, deepfakes, and cross-platform lures.
  • Only 34.7% of enterprises have prompt injection defenses, while mega breaches at Oracle and Salesforce show how one compromised account can trigger supply chain chaos.
  • Burnout is rising among cybersecurity teams as attackers exploit trust and urgency, making human resilience and industry-wide collaboration critical to staying ahead.

AI Arms Social Engineering

Attackers now orchestrate hyper-personalized, multi-channel campaigns—leveraging deepfakes, chatbots, and platform spoofing—to defeat human instincts and legacy defenses at industrial scale.

The rise of AI-powered cyber attacks has fundamentally transformed the social engineering landscape, with attackers leveraging artificial intelligence to dramatically increase both the scale and sophistication of their campaigns. According to KnowBe4's 2025 Phishing Threat Trends Report, there was a staggering 449% surge in AI-powered vishing attacks and a 67% increase in the abuse of legitimate platforms throughout 2025. By hijacking trusted platforms and timing attacks around seasonal events like tax deadlines and holidays, cybercriminals are consistently outpacing traditional detection methods, making it increasingly difficult for organizations to defend against these multi-modal, AI-fueled threats.

AI-driven phishing and social engineering attacks now routinely exploit advanced personalization and multi-channel tactics, making them nearly indistinguishable from legitimate communications. KnowBe4's Q3 2025 report found that 90% of user interactions with phishing emails were driven by messages personalized with company names and internal topics, while 70% of simulated attacks used branded landing pages and 66% employed domain spoofing. Attackers impersonate internal departments like HR and IT, and frequently spoof trusted brands such as Microsoft, LinkedIn, and Amazon, deploying these lures not just via email but across platforms like Slack, Teams, and even calendar invites—demonstrating how AI enables a seamless, context-aware assault that traditional defenses struggle to detect.

The sophistication of AI-powered attacks extends far beyond text-based phishing, encompassing deepfake voice snippets, interactive chatbots, and even live video impersonations. Attackers now coordinate multi-modal campaigns—such as sending a single MFA push notification followed by a convincing vishing call from a deepfaked 'IT support'—to manipulate victims into granting access or divulging sensitive information. This evolution is exemplified by tactics like 'ChatOps Phishing,' where AI-driven bots impersonate support staff in real time, guiding users through the very steps that compromise their security, and by the use of deepfake voicemails or video clips to add further credibility to fraudulent requests.

AI not only automates and scales attacks but also supercharges reconnaissance, enabling attackers to build detailed persona graphs and mimic organizational language with uncanny accuracy. By scraping data from LinkedIn, press releases, and internal documentation, AI systems can craft grammatically perfect, context-aware messages that adapt to real-time interactions and objections. This level of personalization allows attackers to target high-value objectives—such as credential theft, wire fraud, and OAuth over-permissioning—with surgical precision, shifting the focus from broad, indiscriminate phishing to highly targeted, lucrative exploits.

The relentless pace of AI-driven cybercrime is evident in the rapid exploitation of new vulnerabilities and the industrialization of attacks across sectors. Campaigns like ClickFix and Quantum Route Redirect automate sophisticated phishing operations, leveraging infostealers, RATs, and even QR code-based 'quishing' to deceive victims at scale. Meanwhile, attackers iterate and refine their tactics—using pixel-perfect fake login pages, compromised legitimate domains, and advanced tricks like the 'URL sign'—until they achieve a single successful compromise, which can have devastating consequences. This industrialization is further underscored by the emergence of ransomware-as-a-service models and the targeting of critical infrastructure, such as hospitals, where the financial incentives and life-threatening stakes drive a persistent, evolving threat that consistently outpaces traditional defenses.

Sources
PR Newswire - Consumer TechnologyPR Newswire - Business TechnologyToxSec - AI and CybersecurityCyberWire DailyTechRadarCyberWire Daily

Defense Goes Layered and Adaptive

Security teams are racing to integrate human vigilance, adaptive AI, and behavioral analytics, as attackers target identity systems and exploit gaps in organizational readiness.

Defensive innovation in cybersecurity has rapidly shifted toward layered, AI-driven strategies that blend people, process, and technology to counter increasingly dynamic threats. As signature-based detection becomes obsolete in the face of AI-generated phishing—capable of infinite, highly personalized variations—organizations are adopting multi-faceted defenses: empowering employees with continuous, realistic AI-generated training, enforcing out-of-band verification for sensitive requests, and streamlining phishing reporting through one-click mechanisms. This holistic approach recognizes that no single layer is sufficient; only by integrating human vigilance, robust processes, and adaptive technologies can defenders hope to keep pace with industrialized social engineering attacks.

The technological backbone of modern defense has evolved beyond static text analysis, now emphasizing phish-resistant multi-factor authentication (MFA) like FIDO2 and passkeys, strict email authentication protocols (SPF, DKIM, DMARC), and behavioral anomaly detection. This shift reflects the reality that attackers, aided by AI, increasingly bypass traditional controls by targeting the attack process itself—leveraging hands-on keyboard techniques and exploiting identity systems. Comprehensive identity visibility, continuous posture hardening, and runtime anomaly detection across cloud, SaaS, and on-prem environments are now essential, as seen in the industry’s response to threats like Scattered Spider and the widespread adoption of unified platforms by leaders such as CrowdStrike and JumpCloud.

Yet, as AI accelerates both attack and defense, the challenge of scaling these innovations remains formidable. Trust and enterprise procurement cycles continue to dictate the pace of adoption—AI-powered startups, despite rapid feature development, face lengthy proof-of-concept processes and must overcome systemic inertia in a risk-averse market. Even as unified, AI-driven platforms gain traction, operational complexity, resource constraints, and the persistent gap between AI adoption and security readiness—exemplified by only 34.7% of enterprises having prompt injection defenses—underscore that defensive innovation is as much about organizational change and collaboration as it is about technical prowess.

By early 2026, the defensive playbook is being rewritten in real time, as attackers exploit vulnerabilities within hours and leverage AI to outpace patching and detection. Defenders are responding with intent classification, stateful context tracking, adversarial AI validation, and output filtering to combat sophisticated runtime and prompt injection attacks. However, the scale and speed of exploitation—such as 79% of detections being malware-free and breakout times as fast as 51 seconds—demand not just technical innovation, but also a culture of transparency, continuous testing, and industry-wide knowledge sharing to close the gap between exposure and response.

Sources
ToxSec - AI and CybersecuritySoftware Analyst Cyber ResearchThe Cybersecurity Pulse (TCP)PR Newswire - Business TechnologyVenture BeatVenture in Security

Identity: The New Attack Surface

Compromised machine and human identities now trigger cascading breaches across SaaS and supply chains, exposing the cracks in legacy governance as non-human accounts surge out of control.

The cybersecurity battlefield has fundamentally shifted toward identity as the primary attack surface, with attackers exploiting both human and non-human identities across sprawling SaaS and supply chain ecosystems. By late 2025, mega breaches involving Oracle and Salesforce exposed the interconnectedness of modern enterprises, where a single compromise can cascade across vendors like Cloudflare, Google, and DocuSign. This trend is compounded by the proliferation of non-human identities—service accounts, bots, and shadow AI—which now vastly outnumber human users, as highlighted by ManageEngine’s 2026 report, making traditional identity governance models obsolete and demanding unified, automated, and risk-based approaches.

Supply chain and SaaS vulnerabilities have become the Achilles’ heel of enterprise security, as attackers increasingly exploit hidden credentials, long-lived tokens, and shadow accounts left unmanaged through mergers, integrations, and rapid automation. Incidents like ClickFix and Sha Hulud, along with the Oracle and Salesforce mega breaches, underscore how dependency chains and third-party access can amplify risk, with attackers embedding themselves for long-term persistence rather than quick data theft. The rise of open source ecosystem attacks—where fake contributor accounts and counterfeit packages infiltrate dependency chains—demands rigorous practices like dependency pinning, SBOM discipline, and continuous monitoring to defend against these invisible threats.

Managing the expanding universe of identities—especially non-human actors like API keys, service accounts, and autonomous AI agents—has become a Sisyphean task for security teams, with shadow AI now cited as the fastest-growing governance threat inside enterprises. Only 1% of organizations have fully adopted just-in-time privileged access, while 54% uncover unmanaged privileged accounts weekly, revealing a critical gap in both policy and tooling. As Dan Herbatschek warns, shadow AI introduces operational blind spots and untracked data exposure, requiring a governance-first approach with transparent policies, proactive monitoring, and dynamic, context-driven controls to keep pace with the relentless growth of machine and AI-driven identities.

Identity-centric attacks have grown more sophisticated, leveraging social engineering and OAuth abuse to bypass even advanced authentication controls, as seen in the ConsentFix and MFA phishing campaigns of early 2026. Attackers now trick users into granting permissions to legitimate applications or running malicious scripts themselves, blurring the line between technical and human vulnerabilities. This evolution, coupled with the persistence of shadow identities and the complexity of managing entitlements across multi-cloud and SaaS environments, means that real-time monitoring, automated remediation, and behavior-based anomaly detection are no longer optional but essential for defending the modern enterprise.

Sources
Software Analyst Cyber ResearchCyberWire DailyCybersecurity MasteryIBM TechnologyCyber Security HeadlinesGlobeNewswire - Industry News on Technology

Human Weakness, Weaponized by AI

Attackers manipulate trust and familiarity, while AI-powered scams and insider threats overwhelm even savvy employees—making resilience and rigorous internal controls urgent priorities.

The human element remains the soft underbelly of cybersecurity, as AI-driven social engineering exploits familiarity and trust with alarming precision. KnowBe4’s Q3 2025 report revealed that 90% of user interactions with phishing emails are triggered by messages personalized with company names and internal topics, a testament to how deeply attackers understand organizational culture and employee psychology. This underscores the critical need for continuous training and behavior change, as CISO advisor Erich Kron emphasizes, since even the most tech-savvy employees remain vulnerable to tactics that feel familiar and legitimate.

Insider threats have evolved into a formidable challenge, blurring the line between external and internal risk as attackers routinely compromise insider credentials or recruit employees from within. Analyses from late 2025 highlight that insiders possess intimate knowledge of detection blind spots and trust models, rendering traditional defenses less effective and exposing the inadequacy of outdated background checks, especially for non-US nationals. With the rise of AI-generated fake credentials and the recruitment of insiders by ransomware gangs, organizations are urged to adopt rigorous controls—akin to those in nuclear facilities—such as strict separation of duties and dual control mechanisms, while embracing zero trust principles internally.

The psychological sophistication of modern scams, powered by AI, has escalated both the operational risk and emotional toll on individuals and organizations. From virtual kidnapping extortion schemes to deepfake-driven scam ecosystems, attackers leverage multi-stage psychological kill chains and urgency as weapons, entrapping victims in increasingly isolated and manipulative environments. This arms race in deception demands not only technical defenses but also heightened empathy for victims, continuous education on evolving scam tactics, and adherence to immutable counter rules—making resilience a moving target that requires constant vigilance and adaptation.

Operational burnout is becoming endemic among cybersecurity professionals, especially as AI amplifies the frequency and complexity of attacks. The relentless pace—illustrated by the University of Hawaii Cancer Center’s ransomware ordeal and the podcast refrain, 'No rest for the weary, but hey, that’s job security for us defenders'—forces leaders to make ethically fraught decisions under pressure, often with lives or critical services at stake. This climate underscores the necessity for organizational support, robust AI governance frameworks, and a cultural shift that prioritizes both resilience and the well-being of those on the digital front lines.

Building true cyber resilience is as much about fostering community and knowledge sharing as it is about deploying technology. Case studies from healthcare show that peer-to-peer learning, communities of practice, and story-driven training not only help organizations with limited resources anticipate attack patterns but also create a sense of shared purpose and protection. Human Risk Management programs that leverage clear metrics and engaging content—like those at Fable—demonstrate measurable reductions in risky behaviors and boost employee engagement, making the case for investment in people as the most effective line of defense.

Sources
PR Newswire - Business TechnologyCyber Security HeadlinesN2K NetworksN2K NetworksCISO Talk by James AzarSiliconANGLE theCUBE

Governance and Trust Under Fire

Modern defense hinges on real-time oversight and collaborative intelligence, as legacy controls falter and organizations race to adopt flexible, AI-aware policy frameworks in the face of unstoppable threats.

The escalating complexity of modern cyber defense—driven by AI agents and the proliferation of machine identities—demands real-time monitoring and robust governance to manage encryption credentials and access controls. As organizations expand through mergers and acquisitions, they inherit a patchwork of legacy credentials and hidden encryption gaps, creating invisible vulnerabilities that only active oversight and transparent credential management can address. As one analyst put it, 'Now you have pure software to solve, talking to each other and having to access different areas in your infrastructure,' underscoring the need for organizations to know exactly 'who has access to what' in an era where a single overlooked credential can open the door to catastrophic breaches.

By late 2025 and into 2026, the cybersecurity community has recognized that trust—not speed—remains the bedrock of effective collaboration, even as AI accelerates the pace of feature development and threat evolution. Public-private partnerships, such as those fostered by the Cyber Threat Alliance and industry-specific ISACs, have become critical platforms for timely, contextualized information sharing, enabling organizations to prepare for threats before they become public and to coordinate responses to incidents like Russian GRU campaigns or ransomware attacks on healthcare. As Vice Admiral Jan Tai and others have emphasized, technology now enables the rapid exchange of indicators of compromise and adversary tactics, but the most resilient defenses are built on relationships and shared knowledge that transcend organizational and national boundaries.

The rise of AI-driven threats has exposed the limitations of traditional, deterministic security controls and forced a shift toward flexible governance and adaptive policy frameworks. Companies like WitnessAI are leading the charge by offering customizable AI guardrails, while industry leaders and regulators—from the U.S. Department of Defense to the European Union—are pushing for quantum-resistant encryption and agile policy responses. As OpenAI’s candid admission that prompt injection is 'here to stay' illustrates, the future of cyber defense will hinge on governance models that accept inherent AI vulnerabilities, prioritize real-time detection over prevention, and foster coordinated public-private action to build collective resilience.

Despite the urgency for innovation, systemic inertia and market dynamics continue to slow the adoption of transformative cybersecurity solutions, with trust and risk aversion dictating the pace of change. Even as AI and quantum computing accelerate the emergence of new attack surfaces, organizations remain anchored to incremental improvements and familiar frameworks, often prioritizing speed and convenience over fundamental security principles like least privilege and defense-in-depth. As Chris Ray of Gigaom notes, 'The companies winning at security aren't the ones moving fastest. They're the ones who remember that access control, least privilege, defense in depth aren't optional,' highlighting the enduring importance of foundational practices amid technological upheaval.

Sources
Lexicon by Interesting EngineeringVenture in SecurityCyberWire DailyThe Cybersecurity Pulse (TCP)New York Stock ExchangeSiliconANGLE theCUBE

Get the stories behind the trends

Deep-dive reporting and the weekly brief, in your inbox.