How Are Cyber Attackers Using AI to Find Their Next Targets?

Artificial intelligence is changing cyber security on both sides of the equation. Businesses are using AI to analyse information, automate routine work, write code and improve productivity. Cyber criminals have access to many of the same capabilities, and they are finding ways to use them to make their own work faster and more efficient.

Much of the discussion around AI and cyber security has focused on whether AI will eventually be capable of carrying out sophisticated cyber attacks autonomously. It is an important question, but it can distract from a change that is already much more relevant to businesses: AI doesn’t need to conduct an entire attack by itself to make cyber crime more effective.

One of the biggest advantages AI offers an attacker is the ability to process information quickly and at scale. It can help with research, interpret technical information, analyse vulnerabilities, generate or adapt code and make sense of large amounts of data gathered about potential targets. Tasks that previously required significant manual effort can increasingly be accelerated or partially automated.

That has implications for the way organisations become targets in the first place.

Cyber criminals don’t always begin by choosing a particular business and then trying to find a way into it. In many cases, the process works the other way around. Attackers search for exposed systems and weaknesses across large numbers of organisations and then focus their attention on those that appear vulnerable.

As AI makes that process faster, the question for businesses is no longer simply whether somebody has a reason to target them. It is also what an attacker could discover about them before they have even decided who to attack.

AI is changing how cyber criminals find targets

The traditional idea of a targeted cyber attack tends to start with the victim. An attacker chooses an organisation, researches it, investigates its systems and then looks for a way to compromise them.

Targeted attacks like this certainly happen, particularly when criminals have a specific financial, political or strategic objective. But a large proportion of cyber crime is much more opportunistic.

Attackers can scan the internet looking for particular technologies, exposed services, weak configurations and known vulnerabilities. Rather than asking, “How can I get into this company?”, they can effectively ask, “Which companies appear easiest to get into?”

This kind of automated reconnaissance isn’t new. Internet-wide scanning, vulnerability scanning and automated exploitation existed long before the current generation of AI tools. What AI changes is the amount of information that can potentially be analysed and acted upon, and the level of expertise required to do so.

An attacker might discover hundreds or thousands of internet-facing systems during a scan. AI can help categorise the results, interpret responses, identify technologies, compare findings with known vulnerabilities and prioritise the systems that appear most promising. Instead of manually investigating every potential lead, the attacker can focus their attention where there appears to be a genuine opportunity.

That makes reconnaissance more efficient and, potentially, makes many more organisations viable targets.

Why “we’re too small to be targeted” is becoming an even weaker defence

Smaller organisations have often taken some reassurance from the assumption that cyber criminals are primarily interested in large, recognisable businesses. If you aren’t a bank, retailer, government department or multinational company, why would a sophisticated attacker spend time trying to break into your systems?

The problem is that they may not need to spend much time at all.

If an attacker can use automated tools to investigate thousands of organisations, your company doesn’t need to be interesting enough to justify hours of manual research. It simply needs to display something that makes further investigation worthwhile.

Imagine an attacker scanning a large number of websites and internet-facing services. Most reveal nothing immediately useful. Some, however, appear to be running vulnerable software. Others expose an administrative interface, an old application or a service that has been incorrectly configured. Those organisations can then be prioritised for further investigation.

The attacker may never have heard of the business before the scan took place. They may know nothing about its turnover, customers or employees. The vulnerability itself is what puts the organisation on their radar.

AI makes this model of cyber crime potentially more powerful because it reduces the amount of human effort involved in sorting through the results. An attacker can cast a wider net without necessarily creating the same increase in workload.

For businesses, that means obscurity provides increasingly little protection. You don’t have to be deliberately selected as a target if your external systems are advertising a reason to attack you.

What can cyber attackers discover about a business?

Most organisations have a larger external digital footprint than they realise. There is usually the main corporate website, but there may also be customer portals, supplier systems, APIs, remote access services, cloud applications, email infrastructure, subdomains, login pages and other internet-facing systems.

Over time, that footprint can become difficult to keep track of. A temporary application created for a project may still be accessible several years later. A subdomain might point to an old system that is no longer actively maintained. A remote access service introduced for a particular team might still be exposed to the internet even though it is rarely used.

Collectively, these systems form part of an organisation’s external attack surface: the technology and services somebody outside the business can potentially discover and interact with.

Cyber criminals can see that attack surface too.

They may be able to identify which technologies are being used, determine whether particular software appears to be outdated, find publicly accessible login interfaces and look for signs of insecure configuration. Information from one source can then be combined with information from another to build a much clearer picture of the organisation.

This is where AI becomes particularly useful. Gathering information is only one part of reconnaissance. Somebody also has to interpret it. AI systems can help attackers process larger amounts of technical information, understand what individual findings might mean and determine which deserve further attention.

The important question for a business, therefore, isn’t simply whether its website is secure. It is whether it has an accurate understanding of everything an attacker can see from outside the organisation.

AI makes cyber reconnaissance faster

Reconnaissance is one of the earliest stages of many cyber attacks. Before trying to compromise an organisation, an attacker wants to understand the systems available to them and identify possible routes in.

Some of that work can be highly repetitive. An attacker may need to examine responses from different applications, identify technologies, research software versions, compare findings against vulnerability information and determine which systems are worth investigating in more detail.

Generative AI is particularly well suited to helping with this type of work because it can interpret and summarise technical information quickly. It can explain what an unfamiliar technology does, help understand an error message, analyse code or suggest why a particular response from a system might be significant.

The result isn’t necessarily an autonomous AI system independently hacking its way through thousands of companies. A more realistic near-term risk is an attacker using AI as an assistant throughout the process.

This means that an AI tool doesn’t need to replace a skilled cyber criminal to make attacks more dangerous. If it allows that person to complete the same work in half the time, investigate ten times as many potential targets or automate tasks they previously had to perform manually, it has already increased their capability.

The same applies at different levels of expertise. AI may help an inexperienced attacker understand technical information that would previously have been beyond them. It may allow an intermediate attacker to write scripts or troubleshoot problems more quickly. For a sophisticated attacker, it may provide another way to scale processes that already work.

In each case, AI acts as a force multiplier rather than a replacement for the attacker.

AI is lowering some of the barriers to cyber crime

Technical knowledge has traditionally been one of the barriers to carrying out more sophisticated cyber attacks. Finding an exposed system is relatively easy; understanding exactly what is wrong with it, how serious the vulnerability is and how it might be exploited can require much greater expertise.

AI can help narrow that gap.

Modern AI tools are capable of explaining technical concepts, analysing snippets of code, assisting with scripting and helping troubleshoot errors. Used legitimately, these capabilities are valuable to developers, IT teams and cyber security professionals. Used maliciously, they can also help attackers perform tasks that might otherwise have taken them longer or required knowledge they didn’t possess.

There are limits. AI systems make mistakes, generate unreliable code and can misunderstand technical environments. They do not instantly turn somebody with no cyber security knowledge into an expert attacker.

But that isn’t the threshold that matters.

An attacker only has to become more capable than they were before. If AI makes relatively inexperienced criminals more competent while simultaneously making experienced attackers faster, the overall volume and sophistication of malicious activity can increase without AI ever becoming capable of completely autonomous hacking.

Known vulnerabilities may become more dangerous in an AI-enabled world

There is a tendency for conversations about AI cyber attacks to focus on futuristic scenarios: autonomous hacking systems, previously unknown vulnerabilities being discovered instantly or highly sophisticated attacks carried out without human involvement.

Those developments are worth watching, but the immediate danger to many businesses is considerably less exotic.

AI can make it easier to find and act upon vulnerabilities we already know about.

Suppose a business has an internet-facing application that hasn’t been updated and contains a known security vulnerability. Information about that vulnerability may already be publicly available, including details of affected software versions and how the weakness works.

The challenge for an attacker is identifying organisations that are still running the vulnerable software and determining whether the vulnerability can be exploited in each particular environment.

Automation has long helped with the first part. AI can increasingly help with the second.

It can assist with interpreting scan results, researching the vulnerability, understanding technical documentation and adapting approaches when something doesn’t work exactly as expected. The amount of manual effort required to move from “this system might be vulnerable” to “this organisation is worth investigating” can therefore decrease.

For businesses, this potentially shortens the window between a weakness becoming known and somebody attempting to exploit it. Patch management, vulnerability scanning and secure configuration become more important, not less.

Can AI discover new cyber security vulnerabilities?

The next stage is the ability of AI systems to identify vulnerabilities that haven’t already been documented.

AI is increasingly being used by legitimate security researchers to analyse software, find coding errors and identify potential security weaknesses. These capabilities can help organisations discover vulnerabilities earlier and improve software security.

The concern is that attackers can benefit from advances in the same underlying technology.

As AI models become more capable of reasoning about software, interacting with applications and analysing code, searching for vulnerabilities could become faster and cheaper. An attacker may be able to investigate more software and test more possible weaknesses than would be practical through manual work alone.

That doesn’t mean businesses should assume an AI system can currently point at any website and immediately discover a new way to compromise it. Vulnerability research remains difficult, and real-world systems are complex.

But the direction of travel is important.

If the cost of finding vulnerabilities falls, organisations may have less time to discover and remediate weaknesses before somebody else finds them.

Cyber security therefore increasingly becomes a question of speed. How quickly can you identify a vulnerability? How quickly can you understand its significance? And how quickly can you fix it?

AI is changing phishing and social engineering too

Technical vulnerabilities aren’t the only way into an organisation. Attackers also research people.

A surprising amount of information about a business and its employees is publicly available. Company websites, LinkedIn profiles, job advertisements, press releases and social media posts can reveal names, roles, reporting structures, suppliers, technologies and current projects.

A determined attacker has always been able to use that information to create convincing phishing emails. The difference is that personalised research and writing traditionally took time.

Generative AI reduces that cost.

An attacker can use AI to process publicly available information and produce messages tailored to a particular organisation, role or individual. It can improve grammar, imitate different writing styles and translate messages into other languages. That makes some of the traditional warning signs of phishing – such as unusual phrasing or poor spelling – increasingly unreliable.

The risk isn’t simply that AI can write a better phishing email. It is that personalisation can potentially be applied to much larger numbers of messages.

An attacker no longer has to choose between sending a generic message to thousands of people and spending significant time crafting a highly targeted message for one person. AI can begin to narrow the gap between the two.

The real impact of AI is across the whole attack process

It is tempting to think of an “AI cyber attack” as a distinct new category of threat. In practice, AI may be more significant because it can be applied at multiple stages of attacks businesses already understand.

It can help criminals research organisations and employees. It can assist with reconnaissance and the analysis of internet-facing systems. It can help interpret vulnerabilities and technical documentation. It can support scripting and code development. It can generate more convincing social engineering messages and help process information gathered after an attacker gains access.

None of those activities depends entirely on AI. Cyber criminals were doing all of them before generative AI became widely available.

What changes is the productivity of the attacker.

If each stage becomes slightly faster, cheaper or easier, the effect accumulates across the attack. More organisations can be investigated, more vulnerabilities can be assessed and more attacks can be attempted with the same amount of human resource.

For businesses, that is arguably a more immediate concern than the prospect of a completely autonomous AI hacker.

How should businesses protect themselves from AI-powered cyber attacks?

There is no single security product that makes a business “protected from AI”. The underlying weaknesses AI-assisted attackers are looking for are often the same weaknesses cyber security teams have been dealing with for years.

The difference is that organisations may have less room for error.

A sensible starting point is to understand your external attack surface. Businesses should know which websites, applications, cloud services, remote access systems and other services are accessible from the internet. Old or forgotten systems are particularly important because they may no longer receive the same level of maintenance or scrutiny as core infrastructure.

Those systems then need to be assessed for vulnerabilities. Regular vulnerability scanning can identify many known vulnerabilities and configuration weaknesses, while penetration testing can provide deeper assurance by investigating whether weaknesses can actually be exploited and what an attacker might be able to achieve.

Patching is equally important. Internet-facing systems containing known vulnerabilities can be attractive targets precisely because attackers can search for them at scale. Organisations need a process for identifying security updates, assessing their importance and applying critical patches quickly.

Multi-factor authentication should also be used wherever appropriate, particularly for systems accessible remotely. Passwords can be compromised through phishing, credential theft and breaches elsewhere, so relying on a password alone creates unnecessary exposure.

Businesses should also consider whether every internet-facing system actually needs to be there. Removing an unnecessary application, account or service eliminates the risk associated with it altogether.

Alongside preventative measures, organisations need effective monitoring. It isn’t realistic to assume every attack can be stopped at the perimeter. Appropriate logging and security monitoring can help identify suspicious behaviour if somebody does gain access, allowing the organisation to respond before the incident develops further.

Finally, employee awareness needs to evolve alongside phishing techniques. Training based primarily on spotting spelling mistakes or badly written emails is becoming less useful. Employees need to understand the importance of verifying unusual requests, particularly those involving payments, credentials or sensitive information, regardless of how convincing the message appears.

Do businesses need specialist AI cyber security software?

Not necessarily.

The rapid growth of interest in artificial intelligence has inevitably produced a growing market for products promising protection against AI-powered threats. Some of those technologies may provide useful capabilities, particularly where AI is being used to improve threat detection, security monitoring or analysis.

But businesses should be cautious about treating AI as an entirely separate cyber security problem.

If an AI-assisted attacker discovers an unpatched server, the underlying problem is still an unpatched server. If AI helps create a convincing phishing email and an employee’s credentials are compromised, identity security still matters. If automated reconnaissance identifies an exposed application containing a vulnerability, vulnerability management and penetration testing still matter.

AI changes the speed and scale at which those weaknesses can potentially be found and exploited. It doesn’t change the need to address them.

For many organisations, improving fundamental cyber security controls will therefore provide considerably more protection than simply buying something with “AI security” in its name.

What would an AI-assisted attacker find if they looked at your business today?

This may be the most useful question for organisations concerned about AI and cyber security.

Trying to predict exactly how cyber criminals will use AI in two or three years is difficult. The technology is moving quickly, and both offensive and defensive capabilities will continue to develop.

But businesses can assess what an attacker can see today.

What systems are accessible from the internet? Are there applications you have forgotten about? Can somebody identify the technologies you’re using? Are any of those technologies outdated? Are known vulnerabilities visible? Are administrative interfaces unnecessarily exposed? Are there weaknesses that would give an automated scanner a reason to investigate your organisation further?

If you don’t know the answers to those questions, finding out is a sensible first step.

Depending on the organisation, that might involve vulnerability scanning, penetration testing or an assessment specifically focused on external threat exposure. The appropriate level of testing will vary according to the systems involved, the organisation’s risk and the assurance required.

The important thing is to see the organisation from the attacker’s perspective rather than relying solely on what you believe is there.

AI is making cyber attackers more productive

AI gives cyber criminals another way to automate repetitive work, process information, understand technical problems and operate at greater scale. That can make it cheaper to investigate potential targets and easier to identify organisations displaying weaknesses.

As those capabilities improve, businesses should expect the gap between becoming vulnerable and being discovered to get smaller.

The answer isn’t to try to outguess every possible use of AI by cyber criminals. It is to reduce the opportunities available to them.

Know what is exposed to the internet. Identify vulnerabilities before attackers do. Patch systems quickly. Remove unnecessary services. Test whether your security controls actually work. Monitor for signs of compromise.

Most importantly, understand what somebody looking at your organisation from the outside can already see.

Because in an environment where attackers can investigate thousands of potential targets increasingly quickly, they may not need to choose your business first.

They may find the vulnerability first – and find your business because of it.

Find out what attackers can see

Securious’s Threat Exposure Review(opens in new tab) looks at an organisation’s external digital footprint from an attacker’s perspective, identifying visible vulnerabilities and weaknesses that modern automated tools could use to identify potential targets.

It provides a practical starting point for organisations that want to understand their external exposure and where their most immediate risks lie.

For organisations that require deeper technical assurance, Securious also provides CREST-accredited penetration testing(opens in new tab) and vulnerability scanning(opens in new tab), alongside wider cyber security assessment and compliance services.