How AI Is Changing Cyberattacks - And Why Old Vulnerabilities Still Matter

Artificial intelligence is changing cybersecurity, but perhaps not in the way many businesses expect.

When organisations think about AI cyber threats, it is easy to imagine entirely new forms of malware or autonomous attacks that require completely new defences. In reality, one of the biggest impacts of AI is that it helps cybercriminals make existing attacks faster, more convincing and easier to scale.

Phishing, social engineering, business email compromise and credential theft are not new. What is changing is the quality and efficiency with which attackers can execute them.

ESET's research suggests that the practical impact of AI today is less about autonomous malware and more about enabling higher volumes of convincing phishing campaigns, faster malware development and scalable abuse of AI tools.

For businesses, particularly smaller organisations without large security teams, this creates an important lesson: AI does not make old vulnerabilities irrelevant. It makes them more valuable to attackers.

AI is making familiar attacks harder to spot.

Traditional phishing attacks often contain obvious warning signs such as spelling mistakes, awkward grammar, generic greetings or suspicious-looking email addresses. Those once easy-to-spot clues are becoming less reliable.

Generative AI can produce polished, contextually appropriate messages in seconds. Attackers can use it to adapt language, imitate professional communication and create convincing content at scale. This is one reason why AI phishing is becoming such an important part of the modern threat landscape.

The result is not necessarily a new type of phishing attack. Instead, it is a better version of an old one.

This matters because employees are often expected to identify suspicious messages based on subtle inconsistencies. When those inconsistencies disappear, relying on awareness alone becomes increasingly difficult.

ESET's 2026 SMB Cyber Readiness Index reinforces the point. While 45% of surveyed SMBs experienced a cybersecurity incident during the previous 12 months, phishing remains one of the major causes of incidents reported by smaller businesses. At the same time, 87% of SMBs consider employee education very important, or critical to cyber resilience.

Training remains essential. But in an era of AI-assisted attacks, it needs to be combined with technology that can identify threats beyond obvious spelling mistakes or suspicious wording.

Social engineering gets more personal.

The effectiveness of social engineering has always depended on one thing: understanding the victim. AI can make that process considerably easier.

Attackers can use publicly available information to create messages that appear relevant to a particular employee, supplier or organisation. They can also generate variations of the same scam for different targets, increasing the likelihood that someone will respond.

This is particularly concerning for AI-powered phishing attacks targeting businesses, where the objective may not simply be to steal a password. A convincing message might attempt to persuade an employee to transfer money, open a malicious file, disclose confidential information or approve an unexpected request.

The underlying manipulation is familiar. The difference is that AI can help attackers make it look legitimate.

ESET's recent threat report research also shows how attackers are exploiting people's growing trust in AI itself. In the H1 2026 report, detections of ClickFix, a social engineering technique that tricks users into carrying out malicious actions themselves, increased by 108% compared with H2 2025. New variants include AI-themed lures designed to make malicious instructions look like legitimate troubleshooting advice.

The danger hiding in the reply chain

One particularly effective example of an old weakness becoming more difficult to detect is the email reply-chain attack.

Rather than sending a completely new message, an attacker can insert themselves into an existing conversation. Because the email appears to belong to an established thread, the recipient may be less suspicious.

AI could make these attacks even more convincing by helping criminals imitate the writing style, tone and context of previous communications. This is a powerful combination. An established attack technique supported by technology that can help reproduce the appearance of legitimate human communication.

It also illustrates why email security cannot depend solely on identifying known malicious links or obvious spam. Security controls need to consider context, behaviour, sender authenticity and the potential payload of messages.

AI is creating new threats too, but the old ones haven't disappeared

None of this means that genuinely new AI cybersecurity risks should be ignored.

ESET's H1 2026 Threat Report highlights the rapidly expanding AI attack surface. Between March and May 2026, ESET analysed around 900,000 AI skills from popular repositories and identified more than 25,000 suspicious and over 3,000 malicious ones. ESET also observed PromptSpy, an Android malware strain that actively uses generative AI at runtime.

At the same time, familiar threats remain firmly in the picture.

Phishing continues to be a major risk. QR-code phishing, or quishing, reached record levels in H1 2026, while ransomware continued to grow.

For South African organisations, ESET's research shows the same pattern. Phishing and social engineering remain significant risks, while attackers are increasingly incorporating AI into established techniques rather than abandoning them for entirely new attack methods.

This is the central challenge of business cybersecurity in the AI era: organisations need to defend against tomorrow's threats without forgetting the vulnerabilities that attackers have been exploiting for years.

Why old vulnerabilities still matter

AI does not need to discover a new vulnerability if an organisation still has an existing weakness that works.

An employee who clicks an unsafe link, reuses a password, trusts an unexpected payment request or opens a malicious attachment can still provide an attacker with an entry point. Poor patching, inadequate email protection and excessive user permissions can still increase the impact of a successful attack.

AI simply makes it easier for criminals to exploit human and technical weaknesses at scale.

This is why SMB cybersecurity strategies should focus on reducing opportunities for attackers across multiple layers rather than trying to predict exactly what the next AI attack will look like.

That means:

  • Protect email and cloud applications against phishing, malware and spoofing.
  • Keep operating systems and applications patched to reduce exploitable weaknesses.
  • Use layered endpoint protection rather than relying on a single detection technology.
  • Train employees regularly to recognise social engineering and suspicious requests.
  • Establish clear processes for financial and sensitive requests, including independent verification.
  • Control the use of AI tools and understand what information employees are sharing with them.
  • Prepare for new attack techniques while continuing to address established cyber risks.

How businesses can protect against AI phishing

There is no single technology that can make an organisation immune to AI cyber threats. The more effective approach is layered protection that combines people, processes and technology.

This is where ESET PROTECT Complete can help. The solution combines multilayered endpoint protection with protection for Microsoft 365 and Google Workspace, including anti-phishing, anti-malware and proactive threat defence. It also provides Advanced Threat Defence designed to help protect against ransomware and previously unseen threats.

That layered approach is particularly relevant as attackers combine familiar techniques with AI. A suspicious email should not have to be identified by an employee alone. Protection at the email, cloud application, and endpoint levels can provide additional opportunities to detect and block a threat.

The future of cybersecurity isn't about AI versus humans

AI will continue to change the threat landscape. Attackers will find new ways to automate reconnaissance, generate convincing content and manipulate users. Defenders will use AI and other technologies to detect suspicious behaviour and respond more quickly.

But the fundamentals of cybersecurity remain remarkably consistent. Businesses still need strong email security. Employees still need effective security awareness training. Vulnerabilities still need to be patched. Endpoints still need protection. Suspicious requests still need to be verified.

The key difference is that attackers now have more powerful tools for exploiting weaknesses that already exist.

So, when considering how AI is changing cyberattacks, the most important question may not be “What completely new attack should we expect?”

It may be: “How much more effective can an attacker become at exploiting the weaknesses we already have?”

For organisations looking at how businesses can stay secure in the age of AI, the answer starts with the basics, but with stronger, more intelligent layers of protection around them. AI may be changing the speed, scale and sophistication of cyber threats, but securing the fundamentals remains one of the most effective ways to reduce risk