AI makes ransomware more effective in Australia study
Fri, 24th Jul 2026 (Today)
Proofpoint has published research showing that two-thirds of Australian organisations hit by ransomware said artificial intelligence made the attacks more effective. The study also found that 70% of Australian victims said data was stolen during the incident.
The findings point to a ransomware environment in which data theft and repeated extortion demands are common, even when companies pay.
In the survey, 67% of Australian organisations affected by ransomware said AI had made attacks either significantly or somewhat more effective. Of that group, 26% said AI had significantly increased the effectiveness of the attack, while 41% said it had somewhat increased it.
The research was based on a survey of 953 full-time security professionals across 12 countries and 20 industries, including Australia, the US, the UK, France, Germany, Italy, Spain, the UAE, Japan, Singapore, India and Brazil.
Human entry points
The Australian findings suggest attackers continue to gain access through tactics aimed at employees and routine business communications. Phishing and email-based social engineering were identified as the initial entry point in 37% of Australian ransomware incidents covered by the study.
Malicious attachments and links were the most common initial threats, cited in 47% of cases. Business email compromise followed at 38%, while conversation hijacking accounted for 26%.
When asked why the attacks bypassed existing controls, 41% of respondents said staff did not suspect the attack because it appeared authentic. Another 42% said users interacted with malicious content.
Ryan Kalember, Chief Strategy Officer at Proofpoint, said the technology had improved the methods that often precede a ransomware attack rather than changing the nature of ransomware itself.
"AI hasn't fundamentally changed ransomware, but it has materially improved the attacks that lead to ransomware," said Ryan Kalember, Chief Strategy Officer at Proofpoint. "Today's attackers are using AI to create highly convincing phishing emails, malware components such as scripts, and credential theft campaigns that exploit human trust at scale. Organisations that continue treating ransomware and data extortion as endpoint or recovery problems are missing what these attacks most frequently begin with: people, identities and trusted communications."
Data theft
The report indicates that encryption is no longer the sole objective in many attacks. In Australia, 70% of ransomware victims said data was stolen during the incident, suggesting attackers are pairing disruption with theft to increase pressure on targets.
That pattern fits a broader shift towards extortion models in which stolen information can be used for repeat demands, sold to other criminals or used in follow-on attacks. The study argues that attacks are becoming less focused on locking systems alone and more focused on obtaining data, identities and ongoing access.
The survey also found that nearly half of affected Australian organisations paid a ransom. Even then, payment did not appear to guarantee the incident was over.
Among Australian organisations that paid, 51% said they were hit with a second extortion demand. The result adds to long-running concerns among law enforcement and cyber agencies that payment may not resolve an attack and can leave victims exposed to further pressure.
Australian results
Adrian Covich, Vice President of Systems Engineering, APJ at Proofpoint, linked the local findings to the growing difficulty of distinguishing malicious messages from legitimate communications.
"Australia's results show that the apparent authenticity of the lure was the most cited reason for a successful ransomware attack," said Adrian Covich, Vice President of Systems Engineering, APJ at Proofpoint. "This does not mean Australians are inherently less security-aware. Instead, it reflects how successfully AI can now mimic the trusted communications that keep businesses moving. The recent ASD warning on state-aligned threat actors targeting critical Australian industries underscores the scale of the threat we are facing."
Covich also pointed to the persistence of extortion after an initial payment.
"The findings also show that paying a ransom does not necessarily end the incident. More than half of Australian organisations that paid were subject to a second extortion demand, demonstrating that attackers can continue to apply pressure with repeated demands and the threat of public disclosure. Social engineering attacks remain a leading entry point for ransomware, so the need for a human-centric approach to cybersecurity has never been higher. Getting it right means protecting people and identities, understanding normal communications behaviour, and stopping deceptive messages before they can lead to a damaging incident."
The figures add to growing evidence that ransomware is increasingly tied to fraud, impersonation and the abuse of trusted channels, rather than only malware delivered to a device. In the Australian sample, only 11% of organisations affected by ransomware said they saw no evidence of AI being used in the attack.
For companies reviewing cyber risk, the findings suggest employee-facing defences, identity protection and scrutiny of routine digital communications are becoming as important as recovery plans and endpoint security. One of the most striking results in the Australian data is that, after years of warnings against paying, 49% of affected organisations still did so, and more than half of those faced another demand.