AI Is Helping Cybersecurity Teams Better Address Threats. It Is Also Giving a Boost To Bad Actors
The biggest shift is not that AI allows attackers to do something entirely new, but that it dramatically reduces the time and expertise required.

Artificial Intelligence is giving cybersecurity teams new tools to detect threats and automate routine work. However, that very technology is allowing cybercriminals to launch more convincing attacks faster and on a larger scale at the same time.
While AI models developed by companies such as Anthropic, OpenAI, and Google can help hackers identify vulnerabilities in computer systems faster than before, security teams are using similar models to detect and fix those same weaknesses.
Anthropic reported last November that Chinese hackers used its AI model for what the company called a "highly sophisticated espionage campaign." According to the company, attackers used the model to gather intelligence and support vulnerability research, illustrating how AI can accelerate multiple stages of sophisticated cyber operations.
The biggest shift is not that AI allows attackers to do something entirely new, but that it dramatically reduces the time and expertise required. Tasks that once demanded specialized knowledge, such as writing convincing phishing emails in multiple languages and analyzing source code for vulnerabilities, can now be completed in minutes.
A recent report from AI-native threat intelligence firm Cyble recorded 69 ransomware attacks against the US banking, finance and insurance sector in the first half of 2026. These attacks were carried out by 20 separate groups, fifteen of which managed just one attack each, a fragmentation that shows a low barrier to entry and an evolving system of threats.
Echoing this view, Domininkas Virbickas, product director at VPN provider NordVPN, told International Business Times that AI was not necessarily creating new attack strategies by enhancing those that already existed.
Changing the rules
Europe's multilingual environment once offered digital users a degree of accidental protection. Poor translations and unnatural wording often made fraudulent messages easier to identify. Attackers now use generative AI to remove this barrier.
Before the technology became widely available, criminals often had to rely on non-native speakers or poor machine translators, making phishing attempts in smaller European countries easier to identify.
Today's large language models (LLMs) can produce fluent, natural-sounding text in dozens of languages, removing one of the accidental barriers that previously limited the effectiveness of cross-border scams.
"AI writes beautiful texts in various languages, and that raises the bar," Virbickas said.
He went on to note that the most common AI-assisted scams involve fake online shops and fraudulent websites, where victims pay for products that never arrive. "AI boosts current scam methods because they require time, effort, hosting a website, contacting people, sending emails or messages," he said. "It makes the activities cheaper and faster."
Beyond producing convincing emails, AI can automate document creation, data analysis, code generation, and translation, tasks that cybercriminals routinely rely on.
In the past, spelling mistakes and awkward phrasing were clear warning signs. Today, distinguishing a phishing email from a legitimate one has become more difficult. The same applies to AI-generated or manipulated images, which can appear authentic at first glance.
Fighting fire with fire
Cybersecurity companies, VPN providers, and hosting services also use the technology to detect phishing websites and identify suspicious activity. Virbickas said large language models are used as tools to review code, but are not allowed to operate without human oversight.
Developers also need to understand the risks that AI introduces and design systems that detect them, said Mantas Lukauskas, AI tech lead at Hostinger, a Lithuanian web-hosting company. "We worked on a phishing detector, and one of the features that we developed was discovering whether a domain name was real or phishing," he told International Business Times.
Until recently, analyzing website imagery required specialized computer-vision models such as convolutional neural networks, or CNNs, he added. "To classify imagery, you had to use a convolutional neural network, but right now you can just send screenshots to any LLM, and it will do the work."
New pitfalls
One common mistake employees make is uploading sensitive information indiscriminately into AI tools. According to Lukauskas, this can create serious risks for companies.
"You need to keep your data secure. You also need to understand that it can be leaked by being input into the LLMs," Lukauskas explained. In 2023, Bloomberg reported that Samsung engineers leaked internal source code by uploading it to ChatGPT.
Entering proprietary code or confidential documents into public AI systems may expose sensitive information if organizations do not have appropriate privacy controls in place. This is where the threat lies. "Attackers can discover weak spots," added the AI tech lead.
AI-generated code creates additional risks. It may rely on outdated software libraries, reproduce insecure coding patterns, or generate code that appears functional but contains hidden vulnerabilities. Attackers may also learn to recognize weaknesses commonly produced by particular models. "If they can identify those patterns, they may be able to exploit them. That's why relying solely on AI isn't a good idea."
AI itself has become a target. As organizations integrate the technology into their products and workflows, the code has to be more secure than ever. While this integration allows for sped-up procedures and internal flows, attackers also have more opportunities to conduct malicious activities.
Thinking critically
According to Lukauskas, thinking critically is one of the most important things at a time when AI has become so widely used for scams and malicious activities on the web.
"Even if an email or a logo looks good, you're not safe," he explained. Although AI models have improved, they can still produce incorrect answers. Their outputs should be treated as suggestions rather than unquestionable facts, especially when security decisions are involved.
As AI continues to develop, the cybersecurity landscape evolves as well. Users can no longer rely on obvious warning signs such as poor grammar or awkward translations. Instead, they need to verify the source of emails, websites, and requests for sensitive information, even when they might appear legitimate.
Building trust
As scams become more sophisticated, cybersecurity companies face a growing challenge of their own, namely, convincing users that they can be trusted. For companies such as VPN providers, demonstrating security requires more than making promises. According to Virbickas, it involves independent audits, transparency, and continuous testing.
One approach used by NordVPN is commissioning no-log reports, which include the types of information the company does not collect, store, or record any user activities. "We work with the Big Four (KPMG, PwC, Deloitte or EY) and we give them access to our servers and infrastructure. In this way, they can see what is being logged or not," Virbickas explained.
The company also commissions assessments of the security of its code. Such external reviews are intended to give users evidence that a company's security and privacy claims have been independently examined.
© Copyright IBTimes 2026. All rights reserved.


















