Cybercriminals have adopted AI faster than most businesses have adopted defences against it. IBM’s latest Cost of a Data Breach research found a 56% increase in AI-driven attacks – including deepfake impersonation scams and AI-generated malware – making this one of the fastest-growing threats businesses face this year. Here’s what changed, and what to do about it this month.

1. Why the Threat Landscape Has Changed
AI has lowered the skill and cost required to run a convincing attack. Phishing emails are now written in fluent, personalised language instead of broken English. Voice-cloning tools can convincingly imitate a manager’s voice in a phone call authorising a wire transfer. Malware can be generated and mutated automatically to slip past signature-based antivirus tools. None of this requires a sophisticated attacker anymore – just access to widely available AI tools.
2. The New Attack Types Worth Briefing Your Team On
Three patterns are showing up most often: deepfake impersonation (fake voice or video used to authorise payments or share credentials), AI-written phishing and business email compromise (highly targeted messages that reference real projects and contacts), and AI-enabled malware that adapts itself to evade detection. Staff who were trained to spot “obvious” scams are often unprepared for these more convincing versions.
3. Fighting AI With AI
The good news is that the same AI capabilities are available on the defensive side. Modern security platforms now use AI to detect anomalies in real time, flag deepfake audio and video, and spot behaviour patterns that indicate a compromised account – often faster than a human analyst could. Security specialists increasingly recommend a layered approach, stacking several different detection methods rather than relying on one tool to catch everything.
4. Don’t Forget Your AI Agents Themselves
If your business has started using AI agents (see our related post on agentic AI), each one needs its own identity, access controls and activity log, just like an employee. Non-human identities are on track to outnumber human users inside many organisations – and an agent with excessive access is just as dangerous as an over-privileged employee account.
5. A Practical Security Checklist for This Month
Enforce multi-factor authentication everywhere, including for AI tools and agent accounts. Brief staff specifically on deepfake voice/video scams and how to verify unusual payment requests through a second channel. Review what data and systems any AI tool or agent can access, and remove anything it doesn’t need. Finally, have your IT provider run a current vulnerability check – AI-generated attacks move faster than annual security reviews.
PROFBITS provides managed security and IT infrastructure support built for this new class of threats. Get in touch for a quick security review before the end of the month.