Summary is AI-generated, newsdesk-reviewed
  • Hornetsecurity report shows AI and automation boosting ransomware and phishing threats.
  • 77% of CISOs see AI phishing as serious; 68% invest in AI defense by 2025.
  • AI misuse impacts: synthetic identity fraud, voice cloning, deepfakes, and model poisoning concern CISOs.

The Hornetsecurity annual Cybersecurity Report highlights a year marked by rapid development in cyber threats, with attackers leveraging automation, artificial intelligence, and social engineering. In response, defenders have been quick to adapt their governance and resilience strategies.

The report, which examines over six billion emails monthly (totaling 72 billion annually), confirms that emails remain a prevalent vector for cyberattacks in 2025. Notably, emails containing malware surged by 131% compared to the previous year, accompanied by a rise in email fraud attempts by 34.7% and phishing incidents by 21%.

Email Vector in Cyber Threats

Advancements in generative AI have made phishing attacks more convincing, with over 77% of Chief Information Security Officers (CISOs) now considering AI-generated phishing a significant and escalating threat. Concurrently, defense strategies are improving, with 68% of organizations expected to invest in AI-based detection and protection systems by 2025.

Daniel Hofmann, CEO of Hornetsecurity, remarked that "AI is both a tool and a target," emphasizing the rapid spread of attack vectors and the ensuing machine learning-driven arms race.

AI's Role in Cybersecurity Threats

Attackers have increasingly utilized generative AI and automation to pinpoint vulnerabilities

Attackers have increasingly utilized generative AI and automation to pinpoint vulnerabilities, craft compelling phishing lures, and execute complex multi-stage attacks with minimal human intervention. 

The influence of AI misuse on the threat landscape is evident, with 61% of CISOs acknowledging AI's role in heightening ransomware risks. Concerns are mounting over synthetic identity fraud, involving AI-generated credentials; voice cloning and deepfake videos to impersonate individuals; model poisoning that corrupts internal AI systems; and the improper use of publicly accessible AI tools by employees.

Challenges with Traditional Security Controls

The integration of new technologies blurs the line between legitimate and malicious actions, reducing the effectiveness of traditional security measures.

Cybercriminals now prefer undermining trust rather than direct breaches. Despite strengthened recovery capabilities, many companies still face the risk of protecting obsolete targets. Future attacks are expected to target less tangible yet more influential aspects, such as institutional trust.

AI-Related Risk Awareness

This year, CISOs identified a significant variance in executive understanding of AI-related risks

This year, CISOs identified a significant variance in executive understanding of AI-related risks. Responses ranged from "deep awareness" to "limited understanding" of AI's impact on such attacks. 

Generally, it was found that awareness varied widely among companies. Looking forward to 2026, successful cybersecurity is expected to focus on resilience, characterized by a cultural shift rather than just prevention.

Importance of Cyber Crisis Preparedness

Hofmann continued: “Our latest cybersecurity report shows that companies are learning to recover from attacks without paying ransom." However, the pace of internal security awareness efforts must match AI advancements.

Currently, few executive boards conduct cyber crisis simulations, and comprehensive playbooks remain rare. As AI-driven misinformation and deepfake extortion grow more frequent, fostering a security-centric culture with a strong understanding of AI's risks and opportunities will be crucial by 2026.

In case you missed it

Responsible AI Adoption Starts With Governance
Responsible AI Adoption Starts With Governance

The eagerness to adopt AI in physical security is increasing as teams want to implement technology solutions for faster, smarter operations. At the same time, the conversations sur...

How AI-Enabled Cameras Are Becoming Operational Sensors That Power Safety, Automation, And Business Intelligence
How AI-Enabled Cameras Are Becoming Operational Sensors That Power Safety, Automation, And Business Intelligence

The biggest return on investment from an AI-enabled camera might have nothing to do with security. Organizations are increasingly discovering that the same cameras installed to pro...

Solink's AI Agents Boost Efficiency Of Existing Infrastructure With Automation
Solink's AI Agents Boost Efficiency Of Existing Infrastructure With Automation

Deploying artificial intelligence (AI) tools should be seen as a business initiative rather than a technology initiative, says Martin Soukup, CTO of Solink, a cloud-based video sec...