Generative AI is rapidly becoming an integral part of business operations, promising significant productivity gains. However, as AI gains access to sensitive information and systems, it can increase the speed and scale of ransomware attacks if not properly governed.
Amplifying Ransomware Risk with GenAI
The use of AI in everyday business operations introduces new security considerations. Employees use AI assistants to summarize documents, search enterprise knowledge, draft content, and automate routine tasks. Organizations are also deploying AI agents that interact with business applications and execute workflows with minimal human intervention.
These technologies can amplify techniques attackers already use, particularly during reconnaissance, credential abuse, and data theft. Understanding where AI changes the attack surface is becoming an essential part of enterprise cyber resilience.
Two AI Threat Models to Understand
There are two primary threat models organizations should be aware of:
1. **Attackers using AI to improve their own operations**: Criminal groups increasingly rely on AI to generate phishing emails, write malicious code, automate reconnaissance, analyze stolen information, and streamline extortion.
2. **Organizations deploying enterprise AI**: AI assistants and agents are connected to document repositories, collaboration platforms, SaaS applications, and internal knowledge bases. If attackers compromise the identities or permissions associated with these systems, AI can accelerate their ability to locate sensitive information, navigate connected systems, and abuse legitimate access.
The Real Issue: Delegated Authority
The real issue is delegated authority. Modern ransomware campaigns typically begin with vulnerability exploitation, credential compromise, or abuse of trusted third-party access. Attackers then perform discovery, escalate privileges, identify valuable data, and exfiltrate information before deciding whether to encrypt systems, extort victims, or both.
AI-Powered Workflows: A New Security Challenge
Acronis GenAI Protection helps identify shadow AI usage, monitor prompts and AI interactions, detect policy violations, and provide visibility into AI-related risks alongside endpoint, identity, SaaS, and backup telemetry. Strengthen detection, response, and recovery with a unified cyber resilience platform.
Six Controls to Reduce AI-Enabled Ransomware Exposure
To mitigate the risk of AI-enabled ransomware, organizations should implement the following six controls:
1. **Least Privilege**: Grant AI systems only the necessary permissions to perform their tasks.
2. **Layered Controls**: Implement multiple layers of security, including authentication, authorization, and access control.
3. **Human Approval**: Require human approval for high-risk actions performed by AI systems.
4. **Monitor AI Interactions**: Continuously monitor AI interactions and detect policy violations.
5. **Identify Shadow AI Usage**: Identify and address shadow AI usage, which refers to unauthorized or unapproved use of AI within the organization.
6. **Unified Cyber Resilience Platform**: Implement a unified cyber resilience platform that provides visibility into AI-related risks alongside endpoint, identity, SaaS, and backup telemetry.
Source: Original article