Artificial intelligence is revolutionising how we defend against cybersecurity threats, but it's a double-edged sword. While AI helps defenders identify and respond to threats faster, cybercriminals are weaponising AI to launch more targeted attacks against New Zealand businesses.
How is AI a threat?
Recent research shows that AI-generated phishing emails have a 300% higher success rate than traditional campaigns. Attackers are using large language models (LLMs) to create highly personalised, contextually relevant messages that bypass traditional email security filters.
Deepfake technology has also become a significant threat, criminals are using AI-generated voice and video to impersonate executives and bypass multi-factor authentication systems. These attacks are particularly effective in New Zealand's business culture, where trust and personal relationships are highly valued.
Attackers are also leverging our trust in AI services we use against us. For example by playing on organisations trust of rules files for AI services like Cursor, threat actors can inject malicious prompts and turn our greatest productivitiy tools against us.
What are some common AI powered attack methods?
1. Intelligent Phishing Campaigns
AI can analyse social media profiles, company websites, and public information to craft highly targeted phishing emails. These messages often reference specific projects, colleagues, or business events to appear legitimate.
2. Automated Vulnerability Discovery
AI-powered tools can scan thousands of websites simultaneously, identifying vulnerabilities faster than human attackers. This automation allows criminals to target more organisations with greater precision.
3. Social Engineering at Scale
Machine learning algorithms can analyse communication patterns and create convincing impersonations of trusted contacts, making social engineering attacks more effective.
4. Adaptive Malware
AI-driven malware can modify its behaviour based on the target environment, making it harder to detect and analyse using traditional security tools.
How can we address AI powered risks?
Implement AI-Powered Security Tools
Deploy security tools that use machine learning to detect unusual behavioural patterns and identify potential threats before they cause damage.
Enhanced Employee Training
Traditional security awareness training is no longer sufficient. Employees need education on recognising AI-generated content and understanding how these attacks differ from more conventional threats.
Zero Trust Architecture
Implement a zero trust security model that verifies every access request, regardless of the source. This approach limits the damage from successful AI-enhanced attacks.
Regular Security Assessments
Conduct frequent penetration testing and vulnerability assessments using AI-powered tools to identify weaknesses before attackers do. AI tools can increase your productivity in this regard reducing cost, and allowing for security to be implement further, as well as increasing findings.
Verify and validate your AI solutions
Don't blindly trust the AI solutions your organisation use. Understand that there are real threats related to trusting everything your AI services output. For exampel, attackers can leverage your trust of your AI tools to get you to act on malicious prompts. Additionally make sure that MCP server integrations are trusted and have been verified.
Consider the people!
Despite AI's capabilities, humans are still central to cybersecurity. Consider training your people to:
- Question unexpected requests, even from seemingly trusted sources
- Verify information through multiple channels
- Report suspicious activities immediately, and be trained on these practices
- Maintain healthy scepticism about digital communications
- Understand that AI is there to augment your job, not do it for you.
Compliance Considerations
New Zealand's Privacy Act 2020 and upcoming cybersecurity regulations will likely address AI-related security risks. Businesses should prepare for increased compliance requirements around AI usage and data protection.
Future-Proofing Your Security Strategy
As AI technology continues to evolve, businesses should:
- Invest in AI-powered security tools that can keep pace with emerging threats
- Develop polices around AI usage which address both opportunities and risks
- Train staff on AI-related security threats and defence strategies
- Regularly update security controls to address new attack vectors
What to take away
AI presents both the greatest opportunity and the greatest threat to cybersecurity. Businesses that fail to adapt their security strategies to address AI-enhanced threats will find themselves increasingly vulnerable to sophisticated attacks.
The key is to use AI as a defensive tool while understanding and preparing for its offensive capabilities to be used against your organisation. This requires an ongoing investment in technology, training, and strategic planning.
