Artificial intelligence may be changing ransomware, but not necessarily by making cybercriminals smarter. The bigger threat could be making their existing attacks dramatically easier to scale.
In the latest episode of CYBR.HAK.CAST, ThreatLocker CTO Michael Jenkins joined hosts Michael Farnum and Phillip Wylie to discuss ransomware, Zero Trust and how AI is changing the economics of cyberattacks.
Full episode and related article:


Jenkins spent part of his career responding to ransomware incidents and helping organizations recover. Asked whether ransomware attacks are becoming more sophisticated, he pushed back on the premise.
“I don't see it getting more sophisticated,” Jenkins said. “Over the course of my career, I've seen a few major jumps, but they're mostly around quantity as opposed to quality.”
AI could accelerate that shift.
AI gives attackers scale without sophistication
Jenkins said attackers can use AI to automate jobs that once consumed hours or days. Rather than developing entirely new attack techniques, criminals can automate reconnaissance, scanning and social engineering while dramatically increasing the number of potential victims they target.
“It's not about AI being special,” Jenkins said. “It's about it doing jobs that attackers used to spend hours or days doing.”
That changes the math. Attackers can use relatively simple prompts to scan companies and firewalls, conduct social engineering and assemble attack packages. They no longer necessarily need a highly effective campaign if automation allows them to launch mediocre campaigns at massive scale.
If an attacker targets 100 organizations, a low success rate may make the campaign unprofitable. Target 100,000 organizations at a fraction of the manual effort, however, and even a small percentage of successful compromises can produce significant returns.
That could be particularly dangerous for small and midsized businesses.
Smaller businesses lose their economic protection
Historically, some smaller organizations benefited from a simple reality: attacking them wasn't always worth the criminal's time.
AI-powered automation can remove some of that friction.
“The only thing that kept them slightly safer is it wasn't worth the risk and the hassle and the research,” Jenkins said. “So if you take that away, you get more smaller companies being hit.”
Those organizations can also face enormous pressure to pay because ransomware may threaten their ability to continue operating.
Meanwhile, ransomware operators continue looking for ways to extract more money from successful compromises. Jenkins described criminals encrypting data, demanding payment for decryption and potentially returning later to threaten publication of the stolen information.
AI therefore doesn't need to produce some revolutionary autonomous ransomware strain to make the threat worse.
It only needs to reduce the time, expertise and money required to find victims.
That leaves defenders facing an uncomfortable equation: When attacking 100,000 organizations becomes almost as practical as attacking 100, being too small to attract an attack stops being much of a defense.


