Brian Sims
Editor
Brian Sims
Editor
PROOFPOINT – THE specialist in human-centric and agent-centric cyber security – has issued its 2026 AI-Era Ransomware Report, duly revealing that Artificial Intelligence (AI) is making ransomware significantly more successful by helping attackers to create more convincing phishing, impersonation and credential theft campaigns.
The global study has found that nearly two-thirds (65%) of global organisations affected by ransomware said AI increased the effectiveness of the attack, reinforcing a broader shift in which ransomware increasingly succeeds by exploiting people, identities and trusted communications.
Based on a survey of 953 cyber security professionals across 12 countries, the research shows that modern ransomware has evolved beyond an encryption event into a sustained extortion campaign. Attackers are now increasingly stealing credentials and sensitive data before deploying ransomware, using trusted communications to gain initial access and then applying continued pressure through repeated extortion demands.
“AI hasn’t fundamentally changed ransomware, but it has materially improved the attacks that lead to ransomware,” observed Ryan Kalember, chief strategy officer at Proofpoint. “Today’s attackers are using AI to create highly convincing phishing e-mails, malware components like scripts and credential theft campaigns that exploit human trust at scale. Organisations that continue treating ransomware and data extortion as endpoint or recovery problems are missing what these attacks most frequently begin with: people, identities and trusted communications.”
Key findings
People are the primary ransomware attack surface and AI is making it worse. With AI, attackers can create more convincing phishing lures, write more targeted impersonation messages and transact faster reconnaissance of organisational structures and message patterns.
Among UK organisations that experienced a ransomware attack, 31% said that AI significantly increased the attack’s effectiveness. Another 33% said that it somewhat increased effectiveness. Combined, 65% said AI made the attack more effective. 11% reported no evidence of AI use at all.
The leading entry methods are all human dependent. When UK organisations identified the primary point of entry for their ransomware incident, the results pointed overwhelmingly to human interaction. Phishing e-mails and other e-mail-based social engineering attacks were the initial entry vector in 24% of incidents.
Malicious links were identified as the most common initial threat (40%), followed by Business e-mail Compromise (35%), malicious attachments and credential harvesting (32%). This demonstrates that today’s most successful ransomware campaigns continue to rely on trusted communications and user interaction throughout the attack lifecycle.
Payment leads to escalation, not resolution. Despite years of guidance from law enforcement and security agencies advising against payment, nearly six in every ten (58%) of those affected UK organisations paid a ransom. Just over one in every five (22%) of those that paid faced a second extortion demand, highlighting ransomware’s evolution from a single payment event into an ongoing negotiation in which attackers hold multiple forms of leverage at the same time: continued encryption, stolen data and the threat of public disclosure.
No longer the end game
Encryption is no longer the end game. Nearly two-thirds (66%) of UK organisations confirmed that data was stolen during the incident. Today’s ransomware campaigns are less about locking systems and more about acquiring data, identities and persistent access. These can be monetised through repeated demands, sold on criminal marketplaces or otherwise used as launching pads for secondary attacks.
Attacks succeed through manipulation. When UK respondents were asked why the ransomware attack was able to bypass their existing controls, 24% of organisations said employees didn’t suspect the attack because it appeared authentic, while 31% attributed the incident to users interacting with malicious content: evidence that AI is making social engineering increasingly difficult to distinguish from legitimate business communications.
Ransomware impact varies by country. Respondents in the UK reported average rates of AI-enhanced attack effectiveness (65%), higher rates of ransom payments (58%) and low confirmed sensitive data theft (24%).
Meanwhile, user interaction as a bypass factor was highest in Japan (49%), India (49%) and Singapore (48%). In these markets, the most common failure mode was users engaging directly with malicious content rather than being deceived by impersonation.
Proofpoint’s findings reinforce the view that organisations can no longer treat ransomware primarily as a malware problem. As AI makes phishing, impersonation and credential theft increasingly convincing, preventing ransomware means protecting people, identities and trusted communications before attackers ever reach the endpoint.
*Access Proofpoint’s 2026 AI-Era Ransomware Report online at www.proofpoint.com/us/resources/threat-reports/ai-era-ransomware-report
Western Business Media Limited
Dorset House
64 High Street
East Grinstead
RH19 3DE
UNITED KINGDOM