AI Has Industrialized Cybercrime: Attacks Are No Longer Linear, They Are a Continuous, Optimized Operation

AI Has Industrialized Cybercrime: Attacks Are No Longer Linear, They Are a Continuous, Optimized Operation

  • 21/Aug/2026
  • ForgeNEX by ForgeNEX
  • AI

Cybercrime has ceased to be a craft and has become an automated industry. The convergence of generative AI, offensive automation, criminal ecosystems as a service, and autonomous bots has given rise to a new generation of threats that surpass the capabilities of traditional defenses. According to the ENISA Threat Landscape 2025, more than 80% of phishing in 2025 was AI-assisted, and the report 'Cybersecurity in the Frontier AI Era' (July 2025) already warns that AI is enabling large-scale automated cyberattacks, including the malicious use of models, data poisoning, and autonomous offensive agents. The conclusion is clear: offensive automation is a structural risk for the EU.

la-ia-crea-una-nueva-ofensiva-digital-que-supera-a-0.jpg

To understand the magnitude of the change, experts consulted by CSO España agree that AI has democratized the exceptionality that once characterized elite hackers. Rodrigo Jiménez del Val, from CyberProof (UST), recalls that Kevin Mitnick in the 90s based his attacks on meticulous social engineering, a rare skill that was difficult to replicate. Today, an operator with little experience can generate hyper-personalized campaigns, in any language and adapted to the victim's context, with a quality that previously required weeks of manual preparation. The difference is not just that attacks are 'better', but that they change in speed, scale, and adaptability: attackers automate reconnaissance, create convincing messages, analyze vulnerabilities, and test variations at a speed that overwhelms traditional defense cycles.

Guillermo Fernández, from WatchGuard Technologies, adds that traditional attacks responded to pre-programmed rules, whereas with AI, the attacker can analyze the environment, generate multiple variants, learn from failures, and modify tactics in real time. Furthermore, AI reduces the cost and knowledge required to launch sophisticated campaigns, allowing the combination of the precision of a targeted attack with the scale of a mass campaign. Benjamín Zamora, from Infinigate Iberia, summarizes it as 'industrializing personalization': a phishing email is no longer generic or full of obvious errors; it can mimic an organization's tone, use public information about the recipient, and build a credible narrative, forcing defenses to rely on behavior, context, and anomalies.

la-ia-crea-una-nueva-ofensiva-digital-que-supera-a-1.jpg

Deepfakes and Autonomous Agents: The Perfect Deception and Automated Action

Ignazio Franzoni, from Netskope, explains that deepfakes make social engineering much more credible, especially in frauds targeting executives, financial teams, or suppliers. It is no longer just a suspicious email, but a plausible voice message, a video call, or a fake digital identity. But the qualitative leap comes with autonomous agents: they not only generate content, but can act, call APIs, interact with tools, retrieve data, and automate workflows. If these agents are compromised or misconfigured, the risk is enormous. Javier del Álamo, from Exclusive Networks Iberia, warns that the combination of both technologies is concerning: deepfakes deceive better and agents act faster. Therefore, protection can no longer focus solely on blocking malware, but must encompass identities, behavior, context, cloud security, detection and response, and the governance of AI use itself.

Automation Changes the Attack Economy

Benjamín Zamora highlights that automation is transforming the cybercrime economy: previously, personalizing a campaign required time and resources; now, thousands of variants of messages, domains, and evasion techniques can be generated in minutes. This particularly affects the reconnaissance and exploitation phases, where attackers can analyze large volumes of public information, identify vulnerable targets, and launch tailored attacks at a speed that exceeds the manual capacity of defensive teams. The response, therefore, cannot rely solely on manual processes: organizations need automated detection and response, threat intelligence, event correlation, and complete visibility across endpoints, network, cloud, and identity.

Pablo Chapinal, from Zscaler, provides a revealing fact: although the volume of phishing in Spain decreased by 52.79% in 2025, the country remains among the ten most attacked in the world. This shows that campaigns are more precise and harder to detect thanks to generative AI, which creates fraudulent websites, personalized emails, and advanced social engineering techniques. Additionally, 95.2% of phishing attempts are now hidden in encrypted traffic, making detection with traditional tools difficult. The good news is that AI also strengthens defenses, enabling more accurate anomaly detection and automated responses, but technology alone is not enough.

la-ia-crea-una-nueva-ofensiva-digital-que-supera-a-2.jpg

Who Are the Most Vulnerable?

All organizations are exposed, but the risk increases where there are many identities, cloud services, remote access, or sensitive processes based on digital communications. Guillermo Fernández points out that financial, human resources, procurement, and management areas are especially attractive for impersonation and fraud. SMEs also have high exposure due to their lower monitoring capacity, and MSPs are high-value targets due to access to multiple clients. Ignazio Franzoni clarifies that vulnerability depends on maturity, not just the sector: any organization that adopts AI quickly without adequate visibility, governance, and data protection becomes exposed. The greatest risk occurs when employees or developers use AI tools without security teams having visibility into the data being accessed.

Elisabetta Villa, from ReeVo, adds that organizations with poorly integrated security systems or overwhelmed teams are more vulnerable, because they do not see the full context of the attack or react in time. Regarding sectors, Carlos Baquero, from Serval Networks, highlights finance, health, and public administrations, which handle sensitive information and are perfect for double or triple extortion via AI-driven ransomware. Size no longer determines risk: a company can be a target because of the information it holds or its position in a business ecosystem.

Are Defenses Ready?

Josep Albors, from ESET España, recalls that they have been using machine learning algorithms for decades, and that most AI-powered attacks still reuse known techniques that can be mitigated with basic measures and advanced solutions. Current SOCs already incorporate continuous detection and automated responses, but problems persist such as the exposure window, misconfiguration, and lack of resources. Defense is moving from a reactive model to a proactive and automated one, although maturity is uneven. Rafael de Pablo, from Babel, raises the key question: it is not whether an organization will have a vulnerability, but how long it takes to fix it. If your response is measured in days and the attacker's in hours, you know who is winning.

In short, AI has created a new digital offensive that surpasses traditional defenses, but it also offers tools to combat it. The key is to adopt a proactive, automated approach based on complete visibility, governance, and continuous training. As in other areas of digital transformation, technology is only one part: strategy and organizational culture are equally important. If you want to delve deeper into how AI is transforming other business processes, we recommend reading about the inference paradox or how to implement generative AI in workflows.


Original source: ComputerWorld. Analysis and adaptation by ForgeNEX.

Share: