Global study reveals that AI is amplifying phishing, impersonation and credentials theft

Sunnyvale, California, USA-headquartered Proofpoint, a global leader in human- and agent-centric security, today released its 2026 AI-Era Ransomware Report, revealing that artificial intelligence is making ransomware significantly more successful by helping attackers create more convincing phishing, impersonation and credential theft campaigns.
The global study found that 83% of UAE organizations affected by ransomware said AI increased the effectiveness of the attack, reinforcing a broader shift in which ransomware increasingly succeeds by exploiting people, identities and trusted communications.
Based on a survey of 953 cybersecurity professionals across 12 countries, including the UAE, all from organizations that had experienced a ransomware attack, the research shows that modern ransomware has evolved beyond an encryption event into a sustained extortion campaign.
Sensitive data
Attackers are increasingly stealing credentials and sensitive data before deploying ransomware, using trusted communications to gain initial access and applying continued pressure through repeated extortion demands.
The findings come amid escalating warnings from the UAE Cyber Security Council. In early July, the Council confirmed the national cybersecurity ecosystem had contained a wave of sophisticated attacks on the financial sector, delivered through phishing campaigns and malicious software, and cautioned that criminals are increasingly using AI to develop more advanced techniques.
The Council has also reported that daily attack attempts on the country’s digital infrastructure have roughly tripled this year to more than 600,000 amid heightened regional tensions.
“Organizations that continue treating ransomware and data extortion as endpoint or recovery problems are missing what these attacks most frequently begin with: people, identities and trusted communications,” asserted Ryan Kalember, Chief Strategy Officer, Proofpoint.
Key UAE findings from Proofpoint’s 2026 AI-Era Ransomware Report include:
- People are the primary ransomware attack surface, and AI is making it worse: With AI, attackers can create more convincing phishing lures, write more targeted impersonation messages, and do faster reconnaissance of organizational structures and message patterns.
- The leading entry methods are all human-dependent: When UAE organizations identified the primary point of entry for their ransomware incident, the results pointed overwhelmingly to human interaction.
- Payment leads to escalation, not resolution: Despite years of guidance from law enforcement and security agencies advising against paying a ransom, more than four in five (81%) of affected UAE organizations paid a ransom.
- Encryption is no longer the endgame: More than four in five (83%) of organizations surveyed in the UAE confirmed that data was stolen during the incident. Today’s ransomware campaigns are less about locking systems and more about acquiring data, identities, and persistent access.
- Attacks succeed through manipulation: When UAE respondents were asked why the ransomware attack was able to bypass their existing controls, 36% of organizations said employees did not suspect the attack because it appeared authentic, while 30% attributed the incident to users interacting with malicious content.
- Ransomware impact varies by country: Respondents in the UAE reported the highest rates of AI-enhanced attack effectiveness (83%), in addition to high ransom payments (81%). Meanwhile, user interaction as a bypass factor was highest in Japan (49%), India (49%), and Singapore (48%).
