AI Adoption Highlights the Need for Businesses to Invest in Proactive Cybersecurity Measures

The swift embrace of Artificial Intelligence has not only accelerated technological advancements but also opened new avenues for cybercriminals to exploit AI for increasingly sophisticated attacks, according to Kaspersky. The company emphasizes the urgent need for businesses to bolster their cybersecurity measures to tackle these emerging threats.

Kaspersky, a leader in global cybersecurity and digital privacy, is integrating AI into its solutions to enhance threat detection and user protection. The company is leveraging AI to make its technologies more resilient against evolving cyber threats.

Cybercriminals are now using AI in innovative and troubling ways. For instance, they are deploying ChatGPT to create malicious software and automate attacks, while AI tools are being used to monitor users’ smartphone activities, potentially intercepting sensitive information like messages, passwords, and financial details.

In 2023, Kaspersky’s solutions safeguarded 220,000 businesses worldwide and thwarted approximately 6.1 billion attacks. Additionally, the company protected 325,000 unique users from potential financial theft due to banking trojans. The firm reported an increase in its daily detection rate, identifying over 411,000 malicious samples daily in 2024 compared to 403,000 the previous year.

Vitaly Kamluk, a cybersecurity expert with Kaspersky’s Global Research & Analysis Team (GReAT), noted that the scale of cyberattacks has grown beyond human capabilities alone, with automation and AI playing significant roles in these attacks.

Recent research by Kaspersky into AI-powered password cracking revealed that most passwords are stored using cryptographic hash functions, making it difficult to reverse-engineer them. The largest known password leak contained about 10 billion lines, including 8.2 billion unique passwords. Alexey Antonov, Kaspersky’s Lead Data Scientist, highlighted that 32% of user passwords are weak and can be cracked from their encrypted forms within an hour using modern brute-force methods and advanced GPUs.

Furthermore, AI models like ChatGPT-4o are being used to craft sophisticated phishing messages that bypass language barriers and tailor emails based on social media profiles. This personalization makes phishing attempts more difficult to detect. Ethan Seow, Co-founder of C4AIL, observed a dramatic 90-fold increase in spam emails targeting organizations for phishing since the launch of ChatGPT.

AI’s rise has also expanded the attack surface for organizations. Cybercriminals now deploy advanced techniques, including deepfakes, which are used to deceive users through impersonations of celebrities or to make fraudulent requests using the victim’s voice. Experts suggest that deepfake detection remains a future challenge, with ongoing research needed to address this issue effectively.

Adrian Hia, Managing Director for the APAC region at Kaspersky, emphasized at the recent Cybersecurity Weekend for Asia Pacific Countries 2024 that achieving 100% system uptime is critical for maintaining business resilience. Uptime refers to the operational status of a system, while resiliency involves the ability to identify, address, and recover from security breaches.

Kaspersky’s Igor Kuznetsov pointed out that AI is increasingly driving spam attacks, making them faster and more extensive. The company’s defensive AI systems successfully identified over 99% of malware in 2023, though the struggle between malware detection and evasion continues.

As AI and Generative AI technologies evolve rapidly, experts call for timely regulatory and ethical frameworks to keep pace with these advancements. Seow noted that regulations are lagging behind the technological developments, and Kamluk stressed the importance of ethical education, particularly among the younger generation, to navigate the potential of AI responsibly.

More Articles & Posts