Skip to content
News update

AI Is Accelerating the Cyber Threat

Cybercrime is now an industrial‑scale, AI‑driven assault that is outpacing defenders through speed and coordination - turning breaches into a test of discipline, resilience and decision-making, not just technology.
Dr Saba Bagheri
Dr Saba Bagheri at the Cyber security and Privacy session at Governance and Risk Management Forum in Sydney

The Gentlemen

The Gentlemen, a Russian-speaking hacking group, has reportedly claimed responsibility for a cyber attack on Australia’s second-largest raw sugar producer.   It is a global scourge.  In June, the heads of the Five Eyes cybersecurity agencies, including Australia, issued a rare joint statement warning that artificial intelligence is reshaping cyber risk in months rather than years. It urged business and governments to act immediately.

Defence vs. Attack

Another Good Decision speaks with Saba Baghari, Cyber Threat Intelligence Manager, Technology Security, for Bupa APEC.  She was a panellist at the NSW Governance and Risk Management Forum in Sydney in May.

To what extent has the scale of cybercrime become industrialised, and how sophisticated are the criminal gangs?

Cyber crime has matured into a genuine economy, not a collection of opportunists. Groups like LockBit and ALPHV/BlackCat operate ransomware-as-a-service models with affiliate programs, profit-sharing (typically a 20–30% cut to the operator), victim negotiation functions, and even customer service-style support for affiliates. The barrier to entry is now near zero.  Anyone with a few thousand dollars can rent attack infrastructure that would once have required a skilled technical team.

What has changed most is specialisation: criminals who sell access to compromised systems sell footholds, while separate groups handle data theft and negotiation. AI tools (FraudGPT, WormGPT) have lowered the technical skill needed to exploit vulnerabilities to almost nothing. Critical infrastructure — healthcare, utilities, financial services — is targeted deliberately because downtime is unacceptable, which makes payment more likely. Medibank (2022) is the textbook Australian example: $46m+ in direct costs, 9.7 million Australians’ health data exposed, weeks of undetected lateral movement after the compromise of third-party credentials.

How is AI being used both by attackers and defenders – and who is winning?

Right now, attackers are getting more value from AI than defenders are, because they face no governance overhead. They can deploy a new AI capability overnight; defenders sit inside risk committees, legacy infrastructure and change-management cycles.

Attack side: automated reconnaissance that maps an attack surface in minutes; polymorphic malware that rewrites itself to evade signature detection; hyper-personalised phishing generated at scale with cultural and linguistic precision; deepfake-enabled social engineering (there is a notorious case in Hong Kong where a finance worker transferred AUD$39m on a video call where every participant, including the CFO, was a deepfake).

Defence side: monitoring for unusual behaviour instead of signature matching, AI-assisted threat hunting (Microsoft reports ~22% faster triage with Copilot for Security, though gains depend entirely on underlying data quality), and automated response playbooks compressing containment from hours to seconds.

The asymmetry is structural, not technical — it’s a governance speed problem, not a capability gap. The fix isn’t less governance, it’s tiered governance: fast-track approval for low-risk AI security tools, heavier scrutiny reserved for high-consequence automation.

What should organisations be doing?

Treating this as a discipline problem rather than purely a technology problem:

  • Decide things in advance, not under pressure. Who owns cyber risk at the executive level, what you will and won’t do when hit by ransomware, and what data you need to retain.
  • Design for resilience, not just prevention. Zero Trust, least-privilege, micro-segmentation — assume compromise and limit blast radius.
  • Build psychological safety to report. The first 24 hours of any compromise depend on someone feeling safe enough to say, “I think I clicked something.”
  • Govern AI adoption in tiers, fast-tracking low-risk tools so legitimate defensive AI isn’t stuck behind the same approval cycle that attackers ignore entirely.
  • Rehearse the hard decisions, not just the technical playbook — pay/don’t pay, shut down a revenue system, disclose before scope is known — with legal, comms, the CFO and CEO in the room, because those are the people making the calls during a real incident.
  • Move from compliance to resilience as the test. Passing yesterday’s audit says nothing about surviving tomorrow’s attack.

AI Success Depends on Governance, Not Technology Alone

Next article