AI accelerates both attacks and defences, but critical security gaps persist

Delinea has unveiled new research highlighting how ransomware attacks have continued to surge over the past year, despite fewer victims paying. Over two-thirds (69%) of organisations globally have fallen victim to ransomware, with 27% being hit more than once. Meanwhile, attackers are harnessing AI to automate, scale, and sharpen their operations.

  • Friday, 30th May 2025 Posted 10 months ago in by Phil Alsop

Based on insights from over 1,000 IT and security leaders worldwide, the 2025 State of Ransomware Report reveals an increasingly volatile threat landscape driven by AI-powered attacks, stolen credentials, and Ransomware-as-a-Service (Raas). While only 57% of organisations paid ransoms, down from 76% in 2024, the frequency and impact of attacks continued to grow as threat actors turned to other tactics like extortion, with 85% of ransomware victims threatened with exposure.

“Ransomware has evolved into a shape-shifting, AI-enabled threat that no business can afford to underestimate,” said Art Gilliland, CEO at Delinea. “In order to combat the sophistication of today’s attacks, organizations must fight AI with AI and embrace proactive, identity security strategies like zero trust architecture, Privileged Access Management, and continuous credential monitoring to stay ahead.”

AI: The Double-Edged Sword

The report highlights the growing role of AI on both sides of the ransomware equation. Threat actors are using AI to automate phishing, impersonate trusted individuals via deepfakes, and accelerate attacks. At the same time, defenders are increasingly relying on AI to detect and respond to threats faster, with 90% of organisations now using AI in their ransomware defence strategies – primarily within Security Operations Centres (64%), for analysing Indicators of Compromise (62%), and to prevent phishing (51%).

Despite 90% of executives expressing concern over ransomware threats, many organisations continue to fall short in essential security practices, with only 34% enforcing least privilege access controls and just 57% implementing application control measures. Most victims reported extended recovery times, with 75% taking up to two weeks to recover.

A recent global study explores the role of trust in cybersecurity and its influence on risk and decision-making, highlighting key challenges...

Decoding the accelerated cyber attack cycle

Posted 15 hours ago by Sophie Milburn
Rapid7's latest report highlights the shrinking timelines in cyber threat landscapes and underscores the urgency of effective cyber-resilience...

Flare launches Foretrace for employee identity protection

Posted 15 hours ago by Sophie Milburn
Flare introduces Foretrace, providing employees with tools to help monitor and address personal identity risks within the enterprise environment.

Inside the Race: Insights from Pax8’s Mission Briefing

Posted 18 hours ago by Sophie Milburn
From Red Bull Racing HQ, Pax8’s Mission Briefing explored a channel under pressure, where rising complexity and the rapid growth of AI are...
Docusign has updated its Intelligent Agreement Management platform in the UK, adding new features for contract preparation, processing, and...

Empowering AI with secure identity control

Posted 4 days ago by Sophie Milburn
Ping Identity introduces “Identity for AI,” extending identity and access control to autonomous enterprise agents with real-time enforcement and...

Huntress extends ITDR solution to Google Workspace

Posted 6 days ago by Sophie Milburn
Huntress expands its Managed ITDR coverage to Google Workspace, providing organisations with enhanced detection and response for identity-based...
DigiCert updates its Document Trust Manager to support document security and global compliance as digital document use and AI-related risks increase.