Eighty-one percent of small businesses suffered a security or data breach over the past year, and 38% of these businesses were forced to raise their prices as a result, a report from the Identity Theft Resource Center (ITRC) has found.
The report notes that external hackers have overtaken malicious insiders as the most common root cause of these incidents. This trend is partially driven by AI-assisted social engineering attacks, which were cited as a root cause by more than 41% of victims.
“The emergence of AI as a primary attack vector aligns with extensive industry analysis on the weaponization of generative AI for creating hyper-realistic phishing emails, deepfake audio and video, and adaptive malware,” the report says.
“These tools are effectively democratizing advanced attack capabilities that were once the domain of highly skilled actors. The primary advantage of a malicious insider has always been their intimate knowledge of internal processes, communication styles, and organizational hierarchies, allowing them to bypass defenses through trust and familiarity. AI tools now allow external actors to replicate this advantage at scale.”
Users should be aware of this trend, as many red flags associated with social engineering, such as typos or odd grammar, will no longer be present.
“Employee security training must be updated to address these new threats,” the report says. “Staff should be educated on the tell-tale signs of AI-generated content, such as subtle visual artifacts in deepfake videos, the lack of emotional nuance in a cloned voice, or the unnaturally perfect grammar of an AI-crafted email. Fostering a culture of healthy skepticism, where employees feel empowered to question and verify unusual or urgent requests, is vitally important.”
AI-powered security awareness training can give your organization an essential layer of defense against evolving social engineering attacks. KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 HRM+ platform to strengthen their security culture and reduce human risk.
Infosecurity Magazine has the story.
New-school Security Awareness Training is critical to enabling you and your IT staff to connect with users and help them make the right security decisions all of the time. This isn't a one and done deal, continuous training and simulated phishing are both needed to mobilize users as your last line of defense. Request your one-on-one demo of KnowBe4's security awareness training and simulated phishing platform and see how easy it can be!
