What Happened

Proofpoint has published research showing that two-thirds of Australian organisations struck by ransomware believe artificial intelligence made those attacks more effective. The study surveyed 953 full-time security professionals across 12 countries and 20 industries, including Australia, the United States, the United Kingdom, France, Germany, Italy, Spain, the UAE, Japan, Singapore, India and Brazil.
In the survey, 67% of Australian organisations affected by ransomware said AI had made attacks either significantly or somewhat more effective. Of that group, 26% said AI had significantly increased the effectiveness of the attack, while 41% said it had somewhat increased it. The study also found that 70% of Australian victims said data was stolen during the incident.
Why It Matters
The findings point to a ransomware environment in which data theft and repeated extortion demands are common, even when organisations pay. The threat is no longer confined to encrypting files and waiting for a ransom transfer. Attackers are now routinely walking away with sensitive data, which gives them ongoing coercive power.
Proofpoint's research makes clear that the entry points are human, not purely technical. Phishing and email-based social engineering were identified as the initial entry point in 37% of Australian ransomware incidents covered by the study. Malicious attachments and links were the most common initial threats, cited in 47% of cases. Business email compromise followed at 38%, while conversation hijacking accounted for 26%.
When asked why attacks bypassed existing controls, 41% of respondents said staff did not suspect the attack because it appeared authentic, and 42% said users interacted with malicious content. Those two figures together describe a workforce that is being deceived, not simply careless.
Key Details
The research includes direct attribution on what AI is actually doing to ransomware campaigns. As one Proofpoint spokesperson noted: "AI hasn't fundamentally changed ransomware, but it has materially improved the attacks that lead to ransomware."
The same source elaborated: "Today's attackers are using AI to create highly convincing phishing emails, malware components such as scripts, and credential theft campaigns that exploit human trust at scale. Organisations that continue treating ransomware and data extortion as endpoint or recovery problems are missing what these attacks most frequently begin with: people, identities and trusted communications."
On the Australian-specific results, the research noted: "Australia's results show that the apparent authenticity of the lure was the most cited reason for a successful ransomware attack."
Background and Context
The research also addressed why Australian organisations appear particularly exposed to authenticity-based deception. As the report stated: "This does not mean Australians are inherently less security-aware. Instead, it reflects how successfully AI can now mimic the trusted communications that keep businesses moving. The recent ASD warning on state-aligned threat actors targeting critical Australian industries underscores the scale of the threat we are facing."
The Australian Signals Directorate has previously warned about state-aligned actors targeting critical sectors, a concern that sits alongside the commercial ransomware threat documented in this study.
What Comes Next
The Proofpoint findings put pressure on Australian security teams to reconsider where they concentrate their defences. Endpoint and recovery controls remain necessary, but the data suggests the decisive moment in most attacks is earlier: an employee receives a convincing message and acts on it. Organisations that do not address that human layer face continued exposure regardless of their technical stack.
The full Proofpoint report covers all 12 surveyed countries and 20 industries. Australian security teams can use the country-specific breakdowns to benchmark their own incident histories against the broader survey population.