Generative AI is rapidly becoming part of everyday business operations. Employees use AI assistants to summarize documents, search enterprise knowledge, draft content and automate routine tasks. Organizations are also beginning to deploy AI agents that interact with business applications and execute workflows with minimal human intervention.
These technologies promise significant productivity gains, but they also introduce new security considerations. As AI gains access to the same identities, business data and systems that cybercriminals already target, it can increase the speed and scale of ransomware attacks if not properly governed.
AI does not create an entirely new ransomware threat. Instead, it amplifies techniques attackers already use, particularly during reconnaissance, credential abuse and data theft. Understanding where AI changes the attack surface is becoming an important part of enterprise cyber resilience.
Two AI threat models organizations should understand
Discussions about AI and ransomware often combine two different threat models:
- Attackers using AI to improve their own operations. Criminal groups increasingly rely on AI to generate phishing emails, write malicious code, automate reconnaissance, analyze stolen information and streamline extortion. AI allows attackers to work faster and operate at greater scale without fundamentally changing how ransomware campaigns unfold.
- Organizations deploying enterprise AI. AI assistants and agents are increasingly connected to document repositories, collaboration platforms, SaaS applications and internal knowledge bases. If attackers compromise the identities or permissions associated with these systems, AI can accelerate their ability to locate sensitive information, navigate connected systems and abuse legitimate access.
These two trends are occurring simultaneously. As attackers become more efficient through AI, organizations must ensure their own AI deployments do not unintentionally expand the attack surface.
Where enterprise AI creates new exposure
Not every AI application presents the same level of risk. AI assistants primarily retrieve information or generate content in response to prompts. AI agents go further by interacting with business applications, invoking APIs and performing actions on a user's behalf.
The greater an application's autonomy and permissions, the greater the potential impact if its associated identity is compromised.
The real issue is delegated authority. Modern ransomware campaigns typically begin with vulnerability exploitation, credential compromise or abuse of trusted third-party access. Attackers then perform discovery, escalate privileges, identify valuable data and exfiltrate information before deciding whether to encrypt systems, extort victims or both.
Microsoft reports analyzing approximately 38 million identity risk detections every day, underscoring how central identity attacks have become. The Cloud Security Alliance has also documented large-scale OAuth device-code phishing campaigns targeting Microsoft 365 users.
AI-enabled applications introduce new security challenges, from prompt injection and unauthorized data access to AI-assisted reconnaissance.
Acronis GenAI Protection helps identify shadow AI usage, monitor prompts and AI interactions, detect policy violations, and provide visibility into AI-related risks alongside endpoint, identity, SaaS, and backup telemetry. Strengthen detection, response, and recovery with a unified cyber resilience platform.
Learn more about Acronis GenAI Protection
How identity compromise turns AI into an attack accelerator
These attacks matter for enterprise AI because AI assistants and agents inherit the identities and delegated permissions under which they operate. When attackers compromise those identities, they may also gain access to the AI services, enterprise data and connected applications available through the same permissions.
An AI assistant connected to enterprise knowledge can dramatically reduce the effort required to locate sensitive information. Rather than manually searching hundreds of folders, an attacker with legitimate credentials could ask an AI assistant to identify backup documentation, administrative procedures, customer information or financial records.
Similarly, if an AI agent has permission to send emails, export files or invoke connected business tools, attackers who compromise its identity could potentially abuse those capabilities to accelerate data theft or unauthorized actions. The underlying risk is excessive access rather than AI itself.
Prompt injection is an AI-specific application-layer vulnerability, but it is only one part of the wider risk created by excessive permissions, insecure integrations and insufficient oversight.
Malicious instructions embedded in documents, emails or web content may influence AI behavior when retrieved by enterprise applications.
The impact depends largely on the permissions granted to the AI system, which is why security guidance from organizations such as OWASP emphasizes layered controls, least privilege and human approval for high-risk actions instead of relying solely on prompt filtering.
AI is already making cybercrime more efficient
Evidence shows AI is making existing cybercrime faster rather than fundamentally changing how attacks work. The Acronis Cyberthreats Report H2 2025 documents several examples of AI supporting different stages of cyber operations:
- The GTG-2002 threat group used AI to generate and debug scripts, assist credential harvesting, analyze stolen information and personalize extortion communications, allowing relatively small attack teams to scale their operations.
- The GLOBAL GROUP ransomware operation introduced an AI chatbot to automate ransom negotiations after compromise. While the chatbot did not change the ransomware infection chain, it enabled operators to manage more victims simultaneously while reserving human negotiators for complex cases.
- Anthropic researchers have documented a Chinese state-sponsored group using agentic AI to execute much of a cyberespionage campaign, including reconnaissance, vulnerability research, credential harvesting and data collection.
Meanwhile, ransomware-as-a-service operators increasingly advertise AI-assisted automation for defense evasion and operational efficiency. Those advertisements signal how ransomware operators are positioning AI and where they expect it to deliver efficiency gains, although individual capability claims may not be independently verified.
Taken together, these examples show AI functioning primarily as an operational force multiplier rather than creating entirely new attack techniques.
Six controls that reduce AI-enabled ransomware exposure
Organizations do not need to replace their existing security strategy for enterprise AI. However, they do need to extend it with AI-specific governance, access controls and monitoring. Acronis security experts advise that organizations should extend existing governance, identity and data protection practices to cover AI applications and workflows by:
- Maintaining an inventory of approved and unauthorized AI applications, models and integrations. Every AI workflow should have a defined owner, business purpose and appropriate risk classification.
- Granting least-privilege access to users, AI applications, service accounts and APIs. Regularly review delegated permissions, revoke unused credentials and limit AI access to only the systems and information required for each task.
- Applying controls to AI-related traffic and data movement. Use secure web gateway, CASB and DLP capabilities to discover AI services, restrict access to unauthorized tools and prevent sensitive information from being uploaded or transferred.
- Monitoring and auditing AI activity. Correlate AI application usage, identity events, data access, exports and agent actions with endpoint, SaaS and cloud telemetry in SIEM or XDR systems. Maintain audit trails showing which user or service account initiated an action, what resources were accessed and whether approval was required.
- Preparing for containment and recovery. Security teams should be able to revoke compromised tokens, disable affected integrations and suspend AI workflows when malicious activity is detected. Immutable backups and tested recovery procedures remain essential for restoring operations after destructive attacks, although they cannot reverse data theft or eliminate extortion risk.
- Implementing human or policy-based authorization for high-risk actions, such as bulk exports, administrative changes, external communications and code execution. OWASP explicitly recommends least privilege and human approval for privileged operations.
Extending cyber resilience to enterprise AI
Enterprise AI will continue expanding because the business benefits are clear. The challenge is ensuring that productivity gains do not come at the expense of security.
The most effective approach is to incorporate AI into existing identity, data protection and incident response strategies rather than treating it as a separate security domain. Organizations should evaluate AI security controls based on how well they integrate with existing governance and security operations while providing visibility into AI usage, permissions and policy violations.
For managed service providers (MSPs) and enterprise security teams, there is an opportunity to extend cyber resilience strategies to include AI governance.
Acronis GenAI Protection, built natively into the Acronis platform, helps organizations discover shadow AI usage, inspect prompts for sensitive data, enforce usage policies and review GenAI activity within the same platform used for other cyber protection services.
This enables organizations to strengthen GenAI governance and make interactions with AI tools safer without introducing another standalone management console.
As enterprise AI adoption accelerates, organizations that combine strong governance with established cybersecurity practices will be better positioned to reduce ransomware risk while realizing AI's productivity benefits.
Try Acronis GenAI Protection now and see how generative AI can help protect your network.
Author: Santiago Pontiroli
Bio: Santiago Pontiroli is the Threat Intelligence Research Lead at the Acronis Threat Research Unit (TRU), where he leads global investigations into advanced threat actors, cybercrime ecosystems, and emerging attack techniques. He specializes in analyzing nation-state actors, criminal organizations, and financially motivated threat groups, focusing on malware analysis, reverse engineering, and developing advanced detection capabilities. With over 15 years of experience in cybersecurity, he has presented original research at leading international conferences including Virus Bulletin, CARO, MITRE ATT\&CK, BlueHat, AVAR, Nuit du Hack, and ekoParty, among others.
Sponsored and written by Acronis.