cyber resilience framework
Threatonomics

How AI shaped the cyber threat landscape in 2024

by Emma McGowan , Senior Writer
Published

Artificial Intelligence (AI) has become a cornerstone of modern innovation, driving unprecedented advancements across industries. From streamlining customer service with digital assistants to bolstering cybersecurity with intelligent tools, the global AI market is on a trajectory to surpass $826 billion by 2030. Yet, as this transformative technology integrates deeper into our lives, it brings with it a shadow: AI cyber threats.

In 2024, AI’s dual nature was on full display, reshaping industries while also enabling more sophisticated cyber threats. Here’s a closer look at how AI evolved this year, the challenges it posed, and the countermeasures emerging to defend against its darker applications.

Widespread adoption of AI

By mid-2024, AI saw widespread adoption across sectors, particularly in customer service, cybersecurity, and digital personal assistants. Innovations such as multimodal AI allowed machines to process data from diverse sources, unlocking new capabilities for handling complex tasks. This adoption wasn’t just about novelty; it was a calculated investment. Surveys revealed that many businesses allocated at least 5% of their budgets to AI initiatives.

But with great innovation comes great risk. AI’s integration into everyday technologies, from IoT devices to autonomous systems, has also expanded the attack surface for cybercriminals.

AI cyber threats

As AI matured, so too did the sophistication of cyberattacks leveraging its capabilities. Threat actors exploited generative AI for activities like:

  • Deepfake fraud: AI-powered impersonation tools enabled criminals to bypass traditional security protocols, manipulate organizations, and conduct fraud on an unprecedented scale.
  • Social engineering: Generative AI tools produced convincing phishing campaigns and AI-generated credentials, as seen in a North Korean hacker’s infiltration of a U.S. cybersecurity firm.
  • Disinformation campaigns: State-backed actors weaponized AI to influence political discourse and elections. Deepfake videos and AI-generated content became powerful tools for manipulating public opinion, particularly during the 2024 U.S. elections.

The RansomHub ransomware group and other malicious actors used AI to breach sensitive platforms, demonstrating that even advanced AI-enabled technologies were not immune to attack. Meanwhile, criminal forums buzzed with over 4 million discussions about using AI for illicit activities, from bypassing KYC protocols to orchestrating large-scale fraud.

AI fighting back

Despite the growing threats, AI also emerged as a formidable ally in cybersecurity:

  • Real-time threat detection: Google’s AI-powered Safe Browsing feature added robust protections against malicious files.
  • Innovative countermeasures: Tools like “Mantis” were developed to turn the tables on AI-driven attacks, redirecting automated threats away from networks.
  • AI vs. AI: Security professionals increasingly deployed AI to preemptively identify vulnerabilities, detect suspicious behavior, and neutralize risks before they escalated.

The arms race between attackers and defenders is intensifying, with AI at the center of both offensive and defensive strategies.

What we can expect in 2025 and beyond

As AI technologies continue to evolve, their potential for innovation remains vast. Advancements in machine learning and autonomous systems promise to reduce errors and expand AI applications. However, the rise in AI-enabled threats will necessitate equally advanced defenses.

Organizations must strike a balance—embracing AI’s benefits while preparing for its risks. In this ongoing battle, one thing is clear: AI will not only shape the future of industries but also redefine the frontlines of cybersecurity.

At Resilience, we’re committed to empowering businesses to navigate this evolving landscape. Whether it’s through advanced risk modeling or comprehensive cyber insurance, we’re here to help you stay secure in an AI-driven world.

You might also like

How Scattered Spider’s vertical-focused strategy creates industry-wide security emergencies

This post is based on a threat intelligence report by Resilience Director of Threat Intelligence Andrew Bayers. Scattered Spider has emerged as a sophisticated threat actor whose advanced social engineering tactics blur the lines between common cybercrime and nation-state tradecraft. Their tendency to tackle specific verticals at a time – as they did in the […]

The essential guide to cyber incident response leadership and decision making

When 43% of UK businesses report experiencing a cyber breach or attack in just the past year, the question isn’t whether your organization will face a cyber incident—it’s how well you’ll respond when it happens.  This stark reality was at the center of a recent webinar hosted by Resilience, featuring insights from Scott Tenenbaum, Head […]

Navigating the growing personal liability facing CISOs

Let’s not mince words: The threat of personal liability and potential criminal charges for CISOs has become a legitimate concern. At a recent “CISOs Off the Record” panel hosted by Resilience at the 2025 RSA Conference, three experienced CISOs talked about the growing trend of CISOs being found personally liable for actions they take at […]

Does the proposed UK ransomware payment ban take things too far?

Cowritten with Henry Westwood, Resilience Cyber Underwriting Manager Simon West, Resilience Head of Customer Engagement The UK government recently launched a consultation on legislative proposals to combat ransomware attacks, one of the most significant cyber threats facing organisations today. As cybersecurity professionals working with organisations across various sectors, we’ve carefully examined these proposals and offered […]

North Korea is targeting the job interview process to infiltrate US companies

This post is based on threat intelligence compiled by Resilience Intelligence Analyst Steph Barnes, published May 8, 2025. North Korean hackers have turned the interview chair into a staging ground for cyberattacks. Two sophisticated campaigns—Contagious Interview and WageMole—are actively targeting job seekers and employers alike, with a clear endgame: funneling money back to the North […]

Scattered Spider strikes again in recent UK retail attacks

In the past two weeks, the UK retail industry has faced an unprecedented wave of sophisticated cyberattacks, exposing critical vulnerabilities across the sector. The high-profile breaches at Marks & Spencer, Harrods, and others have sent shockwaves through the industry, with M&S alone suffering an estimated £3.8 million in lost online sales per day and seeing […]