Assume AI cybersecurity attacks are the future: 43% of companies have already experienced it
Assume AI cybersecurity attacks are the future: 43% of companies have already experienced it
Follow ZDNET: Add us as a preferred source on Google.
ZDNET's key takeaways
- New CDW research shows AI use in cyberattacks is increasingly common.
- 43% of organizations surveyed have experienced AI-enhanced phishing attacks.
- 41% of companies plan to use AI in their cyber defenses.
Forty-three percent of organizations have experienced AI-enhanced or AI-generated phishing attacks, and 37% have encountered AI-augmented malware, according to a new survey.
CDW's 2026 Security Research Report is based on a survey of 951 IT decision-makers across a variety of industries. Published Monday, the research reveals what appears to be an AI arms race between cyberattackers and defenders. Many organizations are considering investing in AI threat detection, training, and controls to combat the new face of modern cyber threats: AI techniques, tactics, and technologies.
AI-driven cyberattacks, by the numbers
There are serious numbers in the report that deserve our particular attention. One or two cyber incidents against high-profile organizations involving a sophisticated AI model is one thing, but there's an undercurrent of quiet, malicious AI attack development that is far more likely to impact the average company.
According to the report:
- 43% of organizations have experienced AI-enhanced or AI-generated phishing attacks.
- 37% of respondents reported encountering AI-powered malware.
Also: AI agents are fast, loose, and out of control, MIT study finds
In addition, when survey respondents were asked which AI-enabled cybersecurity threats pose the greatest risk to their organizations, 25% said AI-generated phishing and social engineering attacks were most concerning, followed by AI-powered malware and automated attack tools (21%). These attack vectors appear to have overshadowed worries about deepfakes, with only 8% of respondents citing deepfake impersonation as the biggest risk to their companies.
An AI breach is a matter of when, not if
For years, security experts have warned companies to adopt the mindset that they will experience a security breach at some stage -- it's a matter of when, not if.
With the rapid emergence of AI-backed, fully autonomous, agentic attacks, this message is more pertinent than ever.
Also: OpenAI's attack agent did exactly what it was told - just more relentlessly than expected
It was only this month that Hugging Face revealed an intrusion by agentic AI. Although the organization's own AI defenses caught it, the case highlights what companies face in keeping their systems, data, and customer records safe.
In total, 41% of respondents to the CDW survey said they planned to deploy AI-driven threat detection systems in the near future, with 49% focusing on threat and anomaly detection, 47% exploring threat intelligence analysis, and 42% opting for phishing and fraud detection.
"We should be concerned about the increasing ability of AI as a technology to discover and exploit weaknesses," commented Buck Bell, director of CDW's Global Security Strategy Office. "It's incumbent now on security practitioners to leverage similar tools to find those weaknesses before the bad guys find them."
There are also risks associated with the internal use of AI for business and productivity purposes. Without proper training and controls, employees may accidentally feed sensitive corporate data into LLMs -- exposing information and potentially handing it over for AI training. Without safety guardrails, AIs tasked with company functions could exceed their assigned roles and disrupt operations.
Thankfully, more organizations are now aware of these risks. In total, 46% of respondents say they frequently assess AI infrastructure and closely monitor it, while 45% intend to train their employees on safe and secure AI use. Furthermore, 44% are working on implementing data protection controls for AI systems and integrating AI systems into existing security monitoring workflows.
Also: 10 ways AI can inflict unprecedented damage
What portion of organizations' AI-related budgets should go to near-term productivity goals versus longer-term security and resiliency needs? If we are going to stop malicious AI from overwhelming organizations already hard-pressed to handle traditional security threats, we face some difficult decisions about investment priorities.
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.