Generative AI Results In 1760% Increase in BEC Attacks

Stu Sjouwerman | Mar 12, 2024

Phishing Generative AIAs cybercriminals leverage tools like generative AI, making attacks easier to execute and with a higher degree of success, phishing attacks continues to increase in frequency.

I’ve been covering the cybercrime economy’s use of AI since it started.

I’ve pointed out the simple misuse of ChatGPT when it launched, the creation of AI-based cybercrime platforms like FraudGPT, and how today’s cybercriminal can basically create foolproof malicious content. Now we’re seeing the fruits of that labor.

According to cybersecurity vendor Perception Point’s 2024 Annual Report: Cybersecurity Trends & Insights, phishing attacks represent 70.8% of all advanced attacks via email (business email compromise or BEC) and 79,8% of web browser-based attacks.

But the interesting caveat is how all of these attacks have been “enhanced” (as Perception Point puts it) by generative AI.  According to their analysis, only 1% of attacks in 2022 utilized GenAI. But that number last year jumped to 18.6% - a 1760% increase!

I expect that number to continue to jump this year and, potentially, just as large an increase, given the popularity of GenAI and the increasing preponderance of maliciously-intended AI-based platforms.

But in the end, much of the output of AI in these circumstances is just really good phishing emails. So, it becomes that much more imperative that employees be enrolled in new-school security awareness training so they can interact with every email with a sense of vigilance and scrutiny, helping to reduce the likelihood of a successful phishing attack.

KnowBe4 empowers your workforce to make smarter security decisions every day. Over 65,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.