AI-Powered Ransomware Makes Attackers More Successful, Survey
AI is proving to be a Swiss Army knife for the average cybercriminal who employs ransomware. It helps them set up more convincing phishing campaigns, commit identity fraud, and steal login credentials, according to recent research by Proofpoint.
Ransomware is more successful than ever, thanks to the targeted exploitation of employees, identities, and trusted communication channels. Of the surveyed organizations worldwide hit by ransomware, 65 percent say that the use of AI by criminals increased the effectiveness of their attack.
Modern ransomware has evolved from a one-time encryption attack into a prolonged extortion campaign, shows the research, based on a survey of 953 cybersecurity professionals from twelve countries. Attackers are increasingly stealing login credentials and sensitive information before deploying ransomware, using trusted communication channels to gain initial access, and applying constant pressure through repeated extortion demands.
People were already the primary target of ransomware attacks, and AI is making the situation worse. With the help of AI, attackers can craft more convincing phishing messages and write messages that are better tailored to the recipient, in which they impersonate someone else. They can also research organizational structures and patterns in messaging communications more quickly.
Among international organizations that have experienced a ransomware attack, 28 percent report that AI significantly increased the attack’s effectiveness. Another 37 percent report that effectiveness increased somewhat. Only nine percent said they have no evidence of AI use.
When organizations identified the primary point of entry for their ransomware incidents, the results largely pointed to human interaction. Phishing emails and other email-based social engineering attacks were the initial point of entry in one-third of the incidents. Malicious links (47%) were identified as the most common initial threat, followed by malicious attachments (46%), credential harvesting (36%), and business email compromise (35%). This demonstrates that today’s most successful ransomware campaigns continue to rely on trusted communications and user interaction throughout the entire attack lifecycle.
Despite years of advice from law enforcement and security agencies not to pay, more than half (54%) of affected organizations paid the ransom. What is somewhat new is that, of those who paid, more than a third (37%) faced a second extortion demand. At the same time, attackers are applying multiple forms of pressure through continuous encryption, stolen data, and the threat of disclosure.
But encryption is no longer the ultimate goal: nearly two-thirds of organizations confirmed that data was stolen during the incident. The new ransomware campaigns are less about locking down systems and more about obtaining sensitive data, identities, and persistent access. These campaigns generate revenue through repeated demands or by selling data on criminal marketplaces, or they are used as a springboard for secondary attacks.
When asked how a ransomware attack was able to bypass existing security measures, the two most frequently cited answers were clear: attacks succeed through manipulation. Technical causes were generally not a factor. Four in ten organizations reported that employees did not notice the attack because it appeared authentic, while slightly fewer respondents (38%) attributed the incident to users who interacted with the malicious content. This demonstrates that the use of AI in an attack makes it more difficult to distinguish social engineering from legitimate business communications.
The findings confirm that organizations should no longer view ransomware primarily as a malware problem. AI is making phishing, identity fraud, and the theft of login credentials increasingly convincing. Stopping ransomware means protecting employees, identities, and trusted communications before attackers even reach the endpoint, according to the report’s authors.
The main takeaway: AI democratizes cybercriminality even further. Clumsy communication from non-natives will quickly become a thing of the past, because generative AI gives criminals the linguistic sophistication they need to convince larger groups of higher-positioned employees that a message, or a phone call, is legit.

