Cyber criminals use AI to sharpen attacks

At a recent cybersecurity summit focused on artificial intelligence held in the Bahamas, top industry specialists have sounded the alarm over a rapidly growing threat: cyber criminals are leveraging cutting-edge AI tools to launch more sophisticated, scalable, and personalized attacks than ever before, with small and medium-sized enterprises (SMEs) bearing the brunt of this new wave of malicious activity.

Frank Gomez, a cybersecurity specialist at global IT management firm Kaseya, explained that generative AI and accessible large language models have eliminated historic barriers for bad actors. Individuals with limited technical expertise or language proficiency can now craft highly convincing attack campaigns that would have required significant skill and time just a few years ago. The evolution of AI-powered threats has grown exponentially over the past two to three years, Gomez noted, with attackers advancing their capabilities at a staggering pace — what would have taken a decade of skill building a decade ago can now be achieved in just 12 months thanks to readily available AI tools.

Gomez highlighted a recent example where an organization saw all 300 of its employees receive individually tailored phishing emails. Just a few years ago, developing a personalized campaign of that scale would have taken roughly a full month of work by attackers; today, that same task can be completed in a fraction of the time. He added that SMEs have become the primary target for these AI-enabled attacks, as bad actors correctly assume most small and mid-sized businesses lack the robust security infrastructure of large corporations. Many SMEs still operate without advanced email filtering systems or tools that can monitor anomalous login activity across their networks, leaving them uniquely exposed. Compounding this risk, Gomez noted that over 50% of organizations hit by ransomware ultimately pay the demanded ransom, as they have no viable backup or recovery alternative to restore their operations.

The warnings were delivered on the sidelines of the Fortify AI Cybersecurity Summit, hosted at Margaritaville, where hundreds of technology and cybersecurity professionals gathered to unpack the risks of unregulated rapid AI adoption and share strategies for stronger organizational defense. Emmanuel Oscar, senior systems engineering manager at leading cybersecurity firm Fortinet, echoed Gomez’s concerns, noting that the fast evolution of AI has drastically expanded the overall cyber threat landscape. Today, Oscar explained, attackers are already using AI to sharpen their coordinated campaigns, forcing cybersecurity defenders to turn to the same technology to keep pace. “Using AI to help the defenders defend against a very sophisticated threat actor that’s also leveraging AI,” Oscar said, adding that attackers are often more coordinated in their efforts than defensive teams.

Oscar explained that cybersecurity firms across the industry are currently racing to develop AI-powered defensive tools that can detect and mitigate AI-enabled attacks, support overstretched cybersecurity analysts, and protect AI models themselves from common exploitation techniques such as prompt injection and jailbreaking. Crucially, Oscar added that many vulnerabilities among Bahamian companies do not stem from outdated technology alone — weak governance and a lack of leadership buy-in for cybersecurity are often the root cause of breaches. “Sometimes it’s not even a technical issue; it’s more of governance. It’s leadership,” he said. “Culture starts from the top and works itself down.” He called for cross-sector collaboration between public and private stakeholders to strengthen the country’s cybersecurity posture as it continues its digital transformation.

Montino Roberts, executive chairman and founder of Professional Business Services, the organizer of the summit, said the event was designed to move beyond abstract discussions of AI risk and toward practical, hands-on training for organizations of all sizes. Roberts warned that AI can be weaponized with surprising ease, and its potential to disrupt business operations and compromise sensitive data is massive. Rather than relying solely on traditional lecture-style presentations, the summit incorporated live, interactive demonstrations of attack techniques, allowing participants to attempt to exploit an AI model themselves before learning how to block and defend against those same attacks.

Roberts drew a parallel between this hands-on defensive training and the historic construction of Nassau’s Fort Charlotte, which has stood for more than 200 years as a defensive stronghold. “It wasn’t built to last because no one attacked it. It was just built so it could support those attacks. In the digital world, we’re trying to teach the same thing today,” he explained.

Noelle Russell, CEO of the AI Leadership Institute, which partnered with PBS on the summit, added that organizations need to fundamentally reframe how they approach AI governance. Many businesses currently treat AI as a trusted co-pilot or collaborator, but Russell argued that all AI systems should be viewed through the lens of “zero trust” — “a zero trust contractor,” as she put it. She compared regulating AI systems to setting clear expectations and boundaries for employees: organizations do not control every action of their human workers, but they put clear guardrails, policies, and consequences in place to reduce risk. The same framework, she argued, is required for AI tools.

“We don’t control humans, but we definitely give them guardrails,” Russell said. “We just have to get everyone’s mind focused on the same principles we apply to humans. We do now need to create the same policies and safety precautions for [AI] agents as well.”