Microsoft: AI speeds up familiar tradecraft rather than inventing new attacks

Microsoft has published a report on how threat actors are adopting artificial intelligence in their operations. The main finding is that AI is currently used mostly to accelerate and simplify existing tradecraft rather than to introduce entirely new attack techniques. Observed uses include translation, generating phishing emails and creating convincing but fraudulent personas and resumes. Generative AI is also used to summarise stolen information and prioritise targets after a breach. Fully AI-generated malware remains rare, but the tools are used to debug and rewrite code and to help deploy infrastructure.

What this means for your business

The classic tells of fraud, such as clumsy language, wrong tone and odd phrasing, can no longer be relied on. That hits recruitment, supplier management and payment processes hardest, where a credible identity does half the attacker's work. At the same time this is not a new threat but a faster version of one you have already assessed, which means controls should rest on verification and process rather than linguistic gut feel.

Berigo recommends

  • Require out-of-band verification for changes to bank details and other payment information, however credible the request appears.
  • Tighten identity checks in recruitment, particularly for roles with access to systems or data.
  • Update security training so it stops teaching people to look for language errors.
  • Address your own use of AI tools in the same round. Governing internal use and understanding the threat belong together.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch