3 min read

Enterprise GenAI Can Speed Up Ransomware Attacks

Acronis says enterprise GenAI can amplify ransomware by accelerating data discovery and abuse of compromised identities.

Image: BleepingComputer

Generative AI is increasingly woven into business workflows, from document summaries and knowledge search to drafting and automation. According to Acronis, that convenience can also make ransomware operations faster and more effective when AI tools are connected to the same identities, data, and apps that attackers already target.

The piece argues that AI is not creating a brand-new ransomware model. Instead, it is amplifying familiar stages of attacks, especially reconnaissance, credential abuse, and data theft.

Acronis separates the problem into two threat models:

  • Attackers using AI to generate phishing emails, write malicious code, automate reconnaissance, analyze stolen data, and streamline extortion
  • Organizations deploying enterprise AI, where assistants and agents are tied to document repositories, SaaS apps, collaboration tools, and internal knowledge bases

The second scenario is where enterprise risk grows quickly. If attackers compromise the identities or permissions tied to those systems, AI assistants and agents can help them find sensitive information and move through connected environments faster. The article points to Microsoft’s approximately 38 million identity risk detections every day as evidence of how central identity attacks have become, and cites Cloud Security Alliance research on large-scale OAuth device-code phishing campaigns targeting Microsoft 365 users.

How AI agents increase exposure

Acronis draws a clear distinction between AI assistants and AI agents. Assistants mainly retrieve information or generate content from prompts. Agents can go further, interacting with business apps, calling APIs, and taking actions on a user’s behalf. The more autonomy and permission an AI system has, the bigger the potential fallout if its identity is compromised.

Recommended reading

Paying ransomware often brings a second demand

That makes delegated authority the core issue. An attacker with valid credentials could ask a connected assistant to surface backup documentation, administrative procedures, customer information, or financial records instead of manually searching through folders. If an agent can send emails, export files, or trigger business tools, those same capabilities could be abused for faster data theft or unauthorized actions.

The article also flags prompt injection as an AI-specific application-layer risk, but says the broader problem is still excessive permissions, insecure integrations, and weak oversight. It cites guidance from OWASP emphasizing layered controls, least privilege, and human approval for high-risk actions rather than relying only on prompt filtering.

Six controls Acronis recommends

Acronis says organizations should extend existing cyber resilience programs to cover AI workflows with six steps:

  • Keep an inventory of approved and unauthorized AI applications, models, and integrations
  • Enforce least-privilege access for users, service accounts, AI apps, and APIs
  • Apply controls to AI-related traffic and data movement with tools such as secure web gateways, CASB, and DLP
  • Monitor and audit AI activity alongside endpoint, SaaS, cloud, identity, and other telemetry in SIEM or XDR systems
  • Prepare for containment and recovery, including revoking tokens, disabling integrations, and suspending AI workflows
  • Require human or policy-based authorization for high-risk actions like bulk exports, admin changes, external communications, and code execution

To show how AI is already being used in attacks, the article cites several examples from the Acronis Cyberthreats Report H2 2025 and other research: GTG-2002 using AI for scripts, credential harvesting, stolen-data analysis, and extortion messaging; GLOBAL GROUP deploying an AI chatbot for ransom negotiations; and Anthropic researchers documenting a Chinese state-sponsored group using agentic AI for reconnaissance, vulnerability research, credential harvesting, and data collection.

The article was sponsored and written by Acronis, and centers on the company’s pitch for Acronis GenAI Protection, which it says can discover shadow AI usage, inspect prompts for sensitive data, enforce usage policies, and review GenAI activity inside the broader Acronis platform.

Sophia Reynolds

Security Editor

Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.

via BleepingComputer

// Keep reading