Cyber criminals use AI to sharpen attacks

MONTINO ROBERTS, Executive Chairman of Proficient Business Services; Emmanuel Oscar, Senior Systems Engineering Manager at Fortinet; and Frank Gomez, Technical Account Manager at Kaseya, were among the presenters at the Fortify AI Cybersecurity Summit on Thursday at Margaritaville. Photo: Shawn Hanna

MONTINO ROBERTS, Executive Chairman of Proficient Business Services; Emmanuel Oscar, Senior Systems Engineering Manager at Fortinet; and Frank Gomez, Technical Account Manager at Kaseya, were among the presenters at the Fortify AI Cybersecurity Summit on Thursday at Margaritaville. Photo: Shawn Hanna

By EARYEL BOWLEG

Tribune Staff Reporter

ebowleg@tribunemedia.net

CYBER criminals are increasingly using artificial intelligence to launch sophisticated, personalised attacks against businesses at a speed and scale that would have been impossible just years ago, cybersecurity experts warned yesterday, with small and medium-sized companies emerging as particular targets.

Frank Gomez, a cybersecurity specialist with Kaseya, said AI has dramatically expanded the capabilities of malicious actors, allowing people to overcome limitations in their own technical knowledge and even language barriers.

“Now with AI and all these different models that are coming out,” Mr Gomez said, “the threats are rising, and the threats are rising exponentially.”

He said the change over the past two to three years has made malicious activity harder to identify while allowing attackers to develop highly personalised campaigns much faster.

“A bad actor a year ago is almost ten years advance in simply one year,” Mr Gomez said, “simply because of the tools that are available to them and the threats that they now have access to.”

The warnings came on the sidelines of the Fortify AI Cybersecurity Summit at Margaritaville, where technology and cybersecurity professionals discussed the risks of rapidly adopting AI and showed how organisations could better protect themselves.

Mr Gomez cited one case in which all 300 employees at an organisation received individually tailored phishing emails. He said producing a campaign on that scale would have taken about a month several years ago.

Small and medium-sized businesses are increasingly being targeted because attackers may assume they lack the security protections of larger organisations, he said.

“As it stands right now, a lot of the targeted attacks, targeted attacks that I've been seeing have been straight to mid-sized and small businesses,” Mr Gomez said, “and the reason for that is mostly because these bad actors they assume that they don't have these guardrails in place.”

Those businesses may lack email security platforms or applications that can analyse login activity and other information moving through their systems, he said.

Mr Gomez also said more than 50 percent of end users hit with ransomware ultimately pay because they have no other choice.

Emmanuel Oscar, senior systems engineering manager at Fortinet, similarly warned that the rapid development of AI is expanding the cyber threat landscape, with defenders increasingly having to use the technology against attackers who are also exploiting it.

“Using AI to help the defenders defend against a very sophisticated threat actor that’s also leveraging AI,” Mr Oscar said. “They are more coordinated in their efforts than we are.”

He said cybersecurity companies are examining how AI can be used to defend against AI-enabled attacks, assist cybersecurity professionals and protect AI models themselves against techniques such as prompt injection and jailbreaking.

But Mr Oscar said vulnerabilities among Bahamian companies are not necessarily caused by shortcomings in technology.

“Sometimes it’s not even a technical issue; it’s more of governance. It’s leadership,” he said. “Culture starts from the top and works itself down.”

He called for leadership and collaboration between the public and private sectors to protect the country's continuing digital transformation.

Montino Roberts, executive chairman and founder of Professional Business Services, said the summit was intended to move organisations beyond discussing the risks posed by AI and towards understanding how attacks happen and how to respond.

He warned that AI can be relatively easily weaponised and has the potential to cause significant disruption.

“This entire environment today is about teaching those who are responsible,” Mr Roberts said, “from the higher executive level all the way to the IT professionals, on how to protect against AI.”

Rather than relying solely on lectures, he said the summit included live demonstrations of different tools and allowed participants to try to attack an AI model themselves before learning how such attacks can be defended against.

Mr Roberts compared the approach to the principles behind the construction of Fort Charlotte.

“We could talk about Fort Charlotte, who had been sitting here for 200 years,” he said. “It wasn't built. It didn't last because no one attacked it. It was just built so it could support those attacks. In the digital world, we're trying to teach the same thing today”

Noelle Russell, CEO of the AI Leadership Institute, which partnered with PBS, said organisations also need to rethink how they view AI itself.

She said people frequently treat AI as a friend or co-pilot when it should instead be regarded as “a zero trust contractor”.

Ms Russell compared governing AI systems to establishing rules and consequences for employees, arguing that organisations need similar policies and safety precautions for AI agents.

“Can we even control it?” she said. “And the reality is, is you got to think of it kind of like your employees. We don't control humans, but we definitely give them guardrails.”

She said organisations now need to apply the same basic principle to AI.

“We just have to get everyone's mind focused on the same principles we apply to humans,” Ms Russell said. “We do now need to create the same policies and safety precautions for agents as well.”

Comments

Use the comment form below to begin a discussion about this content.

Sign in to comment