Updated October 2026. Originally published January 30, 2025.
Artificial intelligence is no longer a future concern for cybersecurity; attackers are using it today. Verizon’s 2026 report found threat actors using generative AI at every stage of an attack, from choosing targets and gaining access to building malware (Verizon DBIR). In 2025 the FBI received 22,364 complaints involving AI, with adjusted losses of more than $893 million (FBI IC3). Businesses need defenses that can keep up.
How attackers are using AI
AI makes old scams faster, cheaper and more convincing:
Phishing and business email compromise. Chat tools can write official-sounding emails that mimic a CEO or other leader and ask for a wire transfer. Businesses reported more than $30 million in losses to AI-involved business email compromise in 2025 (FBI IC3).
Voice cloning and deepfakes. Criminals use cloned voices to request wire payments, and voice spoofing, possibly using deepfakes, has appeared in online job interviews (FBI IC3). In phishing simulations, click rates on voice and text message lures run 40% higher than email (Verizon DBIR).
Faster attack development. The median threat actor used AI assistance across 15 documented attack techniques, and some used it for 40 or more (Verizon DBIR).
People remain the main target: the human element was present in 62% of breaches (Verizon DBIR).
Where AI helps defenders
As Adam from Starfish Computer explains in the video, partnerships with security leaders like Barracuda let us put AI to work on the defensive side:
Smarter email filtering. Traditional spam filters look for known markers, so a plain, friendly message from what appears to be a real contact can slip through. AI-based filtering evaluates the content and the normal conversation patterns between people, and it can stop social engineering emails before they reach the inbox.
Network monitoring. AI learns what normal traffic looks like and flags or blocks unusual data transfers. Speed matters: the average breach now takes 247 days to identify and contain, and breaches lasting more than 200 days cost an average of $5.65 million (Baker Donelson).
Behavior-based endpoint protection. Signature-based antivirus only recognizes threats it has seen before. AI-driven tools watch for suspicious behavior, which helps catch new and modified malware.
Govern your own use of AI
Your employees are adopting AI too, approved or not. Verizon found 45% of employees now use AI regularly on corporate devices, up from 15% a year earlier, and 67% of users reach AI services through non-corporate accounts (Verizon DBIR). IBM’s 2026 research found incidents involving employee shadow AI more than doubled, to 43% (Baker Donelson).
Set an AI use policy. Decide which tools are approved and what data may never be pasted into them, such as client records or source code.
Use a recognized framework. The NIST AI Risk Management Framework, with its Govern, Map, Measure and Manage functions and a Generative AI Profile, gives businesses a voluntary structure for managing AI risk (NIST).
Back up AI with strong authentication. No filter catches everything. CISA calls phishing-resistant MFA the gold standard and urges organizations to make it a high priority (CISA).
Put AI to work with Starfish Computer
AI gives defenders a real advantage when it is chosen carefully, configured well and paired with sound policies. Starfish Computer combines AI-driven email protection, monitoring and endpoint security from proven partners with practical guidance on how your team uses AI. Contact us to review your current defenses and see where AI can close the gaps.
Protect your business: start with an assessment
The question isn’t whether your business will face a cyber threat, but whether you’ll be ready when it does. Since 1994, Starfish Computer Corporation has helped businesses across Northeast Ohio:
Assess current security posture and risk
Plan a cybersecurity roadmap aligned to NIST CSF 2.0
Implement the right tools and processes for your size and budget
Train your team on today’s threats, including AI-driven scams
Support and improve your security over time
Call (440) 808-0468 or visit starfishcomputer.com to schedule a security assessment.
About the author
R.J. Arhar is President of Starfish Computer Corporation. He has more than 35 years of experience in IT, served as a consultant to the National Institutes of Health, led IT operations for an international security company with more than 8,000 users, and is the author of Attack or Defend – When is Enough Cybersecurity Enough?
This post provides general cybersecurity guidance. Requirements vary by industry and business. Statistics are current as of October 2026; consult Starfish Computer Corporation for a plan tailored to your risk profile.

