The cybersecurity landscape has changed radically in recent months. We are no longer talking about isolated attacks or lone hackers with exceptional skills. Artificial intelligence (AI) has democratized talent that was once exclusive to a few, and cybercrime has become an industrial, continuous, and optimized operation. Data from the ENISA Threat Landscape 2025 is compelling: more than 80% of this year's phishing has been AI-assisted, and the European agency warns that offensive automation is already considered a structural risk for the EU. In this article, we analyze how AI is outpacing traditional defenses and what organizations can do to stay ahead.

Table of contents [Show]
Rodrigo Jiménez del Val, Cybersecurity Engineering and Architecture Manager at CyberProof Spain (UST), recalls that in the 1990s, Kevin Mitnick was exceptional because he combined psychological intuition and meticulous research that few could replicate. Today, AI has democratized that exceptionality: any operator with little experience can generate hyper-personalized campaigns, in any language, and with a quality that previously required weeks of artisanal preparation.
"The difference is not just that attacks are better; it's that they change in speed, scale, and adaptability," explains Jiménez del Val. Attackers can automate reconnaissance, create convincing messages, analyze vulnerabilities, and adapt malware at a speed that overwhelms traditional defense cycles. What was once linear (one attacker, one campaign, one set of tools) now resembles a continuous industrial operation. "We are not facing a new technique, but a new cybercrime economy," he concludes.
Guillermo Fernández, Director of Sales Engineering for Southern Europe at WatchGuard Technologies, emphasizes that AI allows attackers to analyze the environment, generate multiple variants, learn from failed attempts, and modify their tactics in real time. "This translates into a much more precise combination of a targeted attack with the scale of a mass campaign," he adds.
Benjamín Zamora, Pre-sales Engineer at Infinigate Iberia, goes further: "AI enables the industrialization of personalization. A phishing email no longer has to be generic or contain obvious errors; it can mimic an organization's tone, adapt the language, use public information about the recipient, and build a very credible narrative." This reduces the user's ability to identify the deception and forces organizations to strengthen detection based on behavior, context, and anomalies.

Deepfakes are taking social engineering to an unprecedented level of realism. Ignazio Franzoni, Director of Solutions Engineering at Netskope, points out that identity impersonation is much more credible, especially in fraud scenarios affecting executives, finance teams, or suppliers. "The problem is no longer just a suspicious email; it can be a plausible voice message, a video call, or a fake digital identity."
But the real qualitative leap comes with autonomous agents. "They not only generate content but can also act: call APIs, interact with tools, retrieve data, write to systems, and automate workflows," explains Franzoni. If these agents are compromised, the risk is enormous. Javier del Álamo, Systems Engineer at Exclusive Networks Iberia, summarizes: "If we combine both technologies, the result is, at the very least, concerning: deepfakes allow better deception, and agents allow faster action."
Automation is completely changing the attack economy. "Previously, personalizing a campaign required time, knowledge, and resources. Now, thousands of variants of messages, domains, identities, or evasion techniques can be generated in minutes," says Benjamín Zamora. This especially affects the reconnaissance and exploitation phases, where attackers can analyze large volumes of public information, identify vulnerable targets, and launch tailored attacks at a speed far exceeding the manual capacity of defensive teams.
The response, therefore, cannot continue to rely solely on manual processes. "Organizations need automated detection and response capabilities, threat intelligence, event correlation, and complete visibility across endpoints, network, cloud, and identity," concludes Zamora.

Pablo Chapinal, Regional Director for Iberia at Zscaler, highlights that attackers are replacing quantity with quality. "According to our ThreatLabz report, although phishing volume in Spain decreased by 52.79% during 2025, the country remains among the top ten most attacked in the world." This shows that campaigns are increasingly precise, convincing, and difficult to detect, thanks to the use of generative AI to create fraudulent websites, personalized emails, and advanced social engineering techniques.
This paradigm shift also affects how organizations must prepare. "Many traditional security tools were designed to protect human users and predictable access patterns. Today, organizations must be prepared to manage millions of interactions generated by autonomous agents that access applications, data, and services dynamically," adds Chapinal.
All organizations are exposed, but the risk increases for those with many identities, cloud services, remote access, or sensitive processes based on digital communications. Guillermo Fernández notes that finance, HR, procurement, and executive areas are especially attractive for impersonation and fraud. SMBs also face high exposure due to their lower monitoring capacity, and MSPs are high-value targets because of their access to multiple clients.
Vulnerability also depends on operational maturity, as Elisabetta Villa, Director of Cybersecurity Product Marketing for EMEA at ReeVo, points out: "When information is fragmented and teams are overwhelmed, any well-orchestrated automated attack has a higher chance of success." Sectors such as finance, healthcare, and public administrations are especially critical, according to Carlos Baquero of Serval Networks, because they handle highly sensitive information that is perfect for double or triple extortion via AI-driven ransomware.
Josep Albors, Director of Research and Awareness at ESET Spain, recalls that most AI-powered attacks still reuse known techniques and can be mitigated with basic security measures and advanced solutions. "Current SOCs already incorporate continuous detection, response automation, and AI-based process analysis," he says, although he admits that maturity is uneven across organizations. "Those without specific action guides, 24/7 monitoring, and real-time detection tools are clearly at a disadvantage."
Pablo Chapinal adds a revealing fact: "95.2% of phishing attempts are already hidden within encrypted traffic, making their detection extremely difficult with traditional tools." The good news is that AI also strengthens defensive capabilities, enabling more accurate anomaly detection and automated responses. However, as Rafael de Pablo, Director of Data & AI Solutions at Babel, concludes, "The key question is not whether an organization will have a vulnerability, but how long it takes to fix it. If your response time is measured in days and the attacker's in hours, you know who is winning."
At ForgeNEX, we have already analyzed how AI has industrialized cybercrime and how automation with n8n and AI can help businesses optimize their processes, but also defend themselves better. Cybersecurity is no longer an exclusive topic for technical departments; it is a strategic priority that requires a proactive and automated approach.
Original source: ComputerWorld. Analysis and adaptation by ForgeNEX.