Ai

New Ransomware Data Reveals AI's Real Advantage Is Exploiting Trust, Not Breaking Code

Kasun Illankoon

By: Kasun Illankoon

7 min read

A global survey of ransomware-hit organizations, including the UAE, shows artificial intelligence is winning by perfecting human trust, not by breaking new technical ground, giving defenders a clearer target than they have had before.

[For more news, click here

For years, ransomware defense has been treated as an engineering problem. Patch the servers. Harden the endpoints. Back up the data twice. New global research from Proofpoint, Inc. suggests that framework has been solving for the wrong variable all along. The vulnerability was never primarily technical. It was human. And now, with more data behind that conclusion than the industry has previously had, organizations have something they have long lacked: a precise, addressable target.

Proofpoint's 2026 AI-Era Ransomware Report, based on a survey of 953 cybersecurity professionals across twelve countries including the United Arab Emirates, found that artificial intelligence is not reinventing ransomware so much as sharpening the one weapon that has always worked best against it: convincing human beings that a malicious message is legitimate. In the UAE specifically, 83 percent of organizations that experienced a ransomware attack said AI made that attack more effective. Only 9 percent saw no evidence of AI involvement at all.

That distinction matters more than it might first appear. A threat that lives primarily in software can be patched. A threat that lives in the split-second judgment of an employee opening an email requires a different kind of investment entirely, one aimed at identity, communication and behavior rather than code alone. The report's real contribution is not the discovery that AI helps attackers. It is the specificity of where that help lands, which gives defenders a clearer map than they had a year ago.

Where the Money Actually Gets In

The UAE data is unusually precise about entry points. Malicious attachments were identified as the most common initial threat in 57 percent of incidents, followed by QR code phishing at 55 percent and telephone-oriented attack delivery at 45 percent, with phishing emails and other social engineering serving as the initial vector in 30 percent of cases. Every one of those routes depends on a person doing something reasonable in the moment: opening a file, scanning a code, answering a call that sounds like it is coming from inside the building.

Ryan Kalember, Chief Strategy Officer at Proofpoint, frames the shift plainly. “AI hasn't fundamentally changed ransomware, but it has materially improved the attacks that lead to ransomware,” he said. “Today's attackers are using AI to create highly convincing phishing emails, malware components like scripts, and credential theft campaigns that exploit human trust at scale. Organizations that continue treating ransomware and data extortion as endpoint or recovery problems are missing what these attacks most frequently begin with: people, identities and trusted communications.”

That reframing has an optimistic undertone that is easy to miss in a report about ransomware. If the weak point is identifiable and consistent across incidents, it is also trainable, monitorable and defensible in ways that sprawling software vulnerabilities rarely are. Among UAE respondents, 36 percent said employees did not suspect the attack because it appeared authentic, and 30 percent attributed the breach to users interacting with malicious content. Those are not indictments of employees. They are a diagnosis of where security budgets have historically underinvested, and a clear signal of where the next round of spending is already headed.

A Region Already Responding

The UAE's exposure in this report is real. The country posted the highest rate of AI-enhanced attack effectiveness among the twelve nations surveyed, at 83 percent, alongside the highest ransom payment rate at 81 percent. But that exposure sits inside a national cybersecurity apparatus that has been unusually active in building countermeasures rather than waiting for the next incident. The UAE Cyber Security Council reported that daily attack attempts on the country's digital infrastructure have roughly tripled this year to more than 600,000, and confirmed in early July that the national system had contained a wave of sophisticated financial-sector attacks delivered through phishing and malicious software.

Institutionally, that pressure has translated into visible investment. Abu Dhabi-based CPX, a G42 company, refreshed its brand identity in June around the promise “Secure what's next,” explicitly positioning cybersecurity as a national priority rather than an information-technology line item, and has partnered with the UAE Cyber Security Council on the UAE Cyber Factory initiative to build sovereign, AI-powered security capabilities domestically. Separate industry research reviewed by Tech Revolt has also shown that malware execution rates across UAE organizations declined steadily through 2025 even as phishing exposure remained constant, evidence that detection and response maturity is catching up to the threat even before this latest AI-driven escalation.

A Global Pattern With Local Variations

The report's twelve-country footprint also shows that this human-dependent entry problem is not uniform in shape, even if it is uniform in outcome. User interaction as a bypass factor, meaning employees clicking, scanning or opening something malicious outright rather than being fooled by a convincing impersonation, was highest in Japan and India at 49 percent each, and in Singapore at 48 percent. In those markets, the failure mode looks less like deception and more like direct engagement with malicious content. The UAE's profile looks different: attackers there are winning primarily by appearing authentic rather than by simply getting users to click on obviously suspicious material, which suggests AI-generated impersonation is doing more of the work regionally than raw volume is.

For security teams in North America overseeing global email and identity infrastructure spanning all of these markets at once, that distinction is operationally useful rather than academic. A defense built to catch obvious phishing lures will miss the more convincing, AI-polished impersonation attempts now succeeding in the Gulf, while a defense tuned only for sophisticated impersonation may under-invest in the blunter, higher-volume click-through risks showing up elsewhere in Asia. The report effectively argues for both muscles at once, tuned by region rather than applied as a single global policy.

The Payment Trap

The report's most sobering figure is also its most instructive. More than four in five UAE organizations, 81 percent, paid a ransom after an attack. Nearly half of those, 47 percent, faced a second extortion demand afterward. Encryption itself is increasingly beside the point: 83 percent of UAE organizations surveyed confirmed that data was stolen during the incident, meaning attackers were walking away with leverage that outlasted any single payment.

Read one way, that is grim math. Read another way, it is the clearest possible argument for shifting investment upstream, toward the identity and communication layer where these incidents actually begin, rather than downstream toward negotiation and recovery, where organizations have the least control and the worst odds. A ransom payment treats the symptom. Blocking the phishing email, the spoofed call or the malicious QR code treats the cause, and the data now shows with unusual clarity which of those causes to prioritize first.

Clarity as a Strategy

Ransomware research has spent years describing an amorphous, ever-shifting threat. What this report offers instead is specificity: the same handful of human-dependent entry points, repeated across a majority of incidents, in a country and region under some of the heaviest attack volume in the survey. That kind of consistency is unusual in cybersecurity, where attackers are typically praised, accurately, for constant reinvention.

For chief information security officers in North America managing global email infrastructure, and for their counterparts across the Gulf building sovereign security capacity from the ground up, the takeaway is the same. The fight has not moved outside the reach of existing defenses. It has moved to a layer, people, identity and trusted communication, that is finally measurable in enough detail to be defended on purpose rather than reactively. Proofpoint's own research puts it in stark numbers. The industry's response, if the UAE's institutional buildout is any indication, is already underway. 

Related Articles:

UAE Organisations Show Stronger Resilience Against Cyber Attacks

CPX Holding Rebrands as UAE Cybersecurity Moves from IT Function to National Priority

The AI Systems Enterprises Are Deploying Have Become the New Attack Surface

Share this article

Related Articles