AI Policy & Regulation

AI Makes Ransomware More Effective, Two-Thirds of Australian Organisations Say

New Proofpoint research finds 67% of Australian organisations hit by ransomware say AI made attacks more effective, with data stolen in 70% of incidents.

AI Makes Ransomware More Effective, Two-Thirds of Australian Organisations Say

Key takeaways

  • 67% of Australian organisations hit by ransomware say AI made the attacks more effective, with 26% saying it significantly increased effectiveness.
  • Data was stolen in 70% of Australian ransomware incidents, pointing to a pattern of extortion beyond simple encryption.
  • Phishing and email-based social engineering were the entry point in 37% of Australian cases; malicious attachments and links appeared in 47%.
  • The research surveyed 953 full-time security professionals across 12 countries and 20 industries.

What Happened

In-body image for: AI Makes Ransomware More Effective, Two-Thirds of Australian Organisations Say
Illustrative AI-generated image by Mindiam (Flux 1.1 Pro Ultra)

Proofpoint has published research showing that two-thirds of Australian organisations struck by ransomware believe artificial intelligence made those attacks more effective. The study surveyed 953 full-time security professionals across 12 countries and 20 industries, including Australia, the United States, the United Kingdom, France, Germany, Italy, Spain, the UAE, Japan, Singapore, India and Brazil.

In the survey, 67% of Australian organisations affected by ransomware said AI had made attacks either significantly or somewhat more effective. Of that group, 26% said AI had significantly increased the effectiveness of the attack, while 41% said it had somewhat increased it. The study also found that 70% of Australian victims said data was stolen during the incident.


Why It Matters

The findings point to a ransomware environment in which data theft and repeated extortion demands are common, even when organisations pay. The threat is no longer confined to encrypting files and waiting for a ransom transfer. Attackers are now routinely walking away with sensitive data, which gives them ongoing coercive power.

Proofpoint's research makes clear that the entry points are human, not purely technical. Phishing and email-based social engineering were identified as the initial entry point in 37% of Australian ransomware incidents covered by the study. Malicious attachments and links were the most common initial threats, cited in 47% of cases. Business email compromise followed at 38%, while conversation hijacking accounted for 26%.

When asked why attacks bypassed existing controls, 41% of respondents said staff did not suspect the attack because it appeared authentic, and 42% said users interacted with malicious content. Those two figures together describe a workforce that is being deceived, not simply careless.


Key Details

The research includes direct attribution on what AI is actually doing to ransomware campaigns. As one Proofpoint spokesperson noted: "AI hasn't fundamentally changed ransomware, but it has materially improved the attacks that lead to ransomware."

The same source elaborated: "Today's attackers are using AI to create highly convincing phishing emails, malware components such as scripts, and credential theft campaigns that exploit human trust at scale. Organisations that continue treating ransomware and data extortion as endpoint or recovery problems are missing what these attacks most frequently begin with: people, identities and trusted communications."

On the Australian-specific results, the research noted: "Australia's results show that the apparent authenticity of the lure was the most cited reason for a successful ransomware attack."


Background and Context

The research also addressed why Australian organisations appear particularly exposed to authenticity-based deception. As the report stated: "This does not mean Australians are inherently less security-aware. Instead, it reflects how successfully AI can now mimic the trusted communications that keep businesses moving. The recent ASD warning on state-aligned threat actors targeting critical Australian industries underscores the scale of the threat we are facing."

The Australian Signals Directorate has previously warned about state-aligned actors targeting critical sectors, a concern that sits alongside the commercial ransomware threat documented in this study.


What Comes Next

The Proofpoint findings put pressure on Australian security teams to reconsider where they concentrate their defences. Endpoint and recovery controls remain necessary, but the data suggests the decisive moment in most attacks is earlier: an employee receives a convincing message and acts on it. Organisations that do not address that human layer face continued exposure regardless of their technical stack.

The full Proofpoint report covers all 12 surveyed countries and 20 industries. Australian security teams can use the country-specific breakdowns to benchmark their own incident histories against the broader survey population.

Sources & citations

  1. Sean Mitchell, "AI makes ransomware more effective in Australia study," *SecurityBrief Australia*, 24 July 2026
  2. Australian Cyber Security Centre / Australian Signals Directorate, advisories and threat intelligence
JUST THE WEEKLY ROUNDUP

One Friday email. The five things AU operators actually need to know.

Operator-tested, primary-source linked, citation-first. Written by an operator, not a marketing team. Or, for a personalised view first, take our 90-second quiz.

Unsubscribe anytime. No spam. See our privacy policy.