“TRUST STARTS & ENDS WITH THE TRUTH”

How Does AI Impact Cybersecurity?

How Does AI Impact Cybersecurity?

POSTED August 21, 2026
BY Matt Aubin

Matt is both the company founder and a nationally renowned private investigator. Matt is an intelligence specialist who excels in detecting and preventing the illegal interception of communications and in providing high-tech covert surveillance. Matt has years of hands on experience in the investigation industry and has developed a reputation for incorporating state of the art technology and innovative ideas to provide effective solutions for his clients. Matt also serves as Treasurer for the Executive Board of Directors of FALI, The Florida Association of Licensed Investigators.

AI and cybersecurity refers to the use of artificial intelligence on both sides of digital defense: attackers use it to automate reconnaissance, clone voices, and generate convincing phishing at scale, while defenders use it to detect anomalies and respond faster. The impact of AI on cybersecurity is speed and volume rather than new categories of crime. Old attacks now arrive faster, cheaper, and far more convincing.

Key takeaways

  • AI has not created new crimes. It has made the existing ones cheaper to run and much harder to spot.
  • The FBI logged artificial intelligence as its own crime category for the first time in 2025, with 22,364 complaints and roughly $893 million in reported losses.
  • One in four malicious breaches is now AI-enabled, and those breaches cost about $1 million more than the average.
  • The fastest-growing risk inside most companies is not a hacker. It is staff using unapproved AI tools with company data.
  • AI can flag a fake. It cannot prove who made it, and it cannot testify.

What does AI actually change about cybersecurity?

AI changes the speed, cost, and believability of attacks. It has not changed what attackers are after. Wire transfers, credentials, and blackmail material are the same prizes they were ten years ago.

What used to take a criminal a week now takes an afternoon. Researching a target, writing a flawless email in your company’s tone, building a fake login page, testing which version gets clicks: all of that used to require either skill or time. A model handles it in minutes.

The believability shift matters more than the speed. For twenty years, the advice was to look for the tell. Bad grammar. Odd spacing. A greeting that did not sound like your CFO. Those tells are gone. Generative tools write cleaner business English than most executives do.

So the effects of AI on cybersecurity land hardest on the human layer. The filters and firewalls still work. The person reading the message is the one now facing a much better forgery.

How are attackers using AI right now?

Attackers are using AI for four things: impersonation, phishing at volume, faster malware development, and automated attack chains. The FBI’s 2025 Internet Crime Report tracked artificial intelligence as a distinct crime descriptor for the first time in its history, recording 22,364 complaints and $893,346,472 in reported losses. The FBI notes that figure is almost certainly low, because victims only report AI involvement when they recognize it.

Here is how the four tactics break down.

TacticWhat it looks likeWhy it works
Deepfake impersonationA video call or voicemail from an executive authorizing a paymentVideo and voice used to be proof. They are now generatable.
AI-generated phishing and BECA clean, well-written email from a vendor with new banking detailsBusiness email compromise drove $3.05 billion in losses in 2025 with no malware attached
AI-assisted malwareCode written and revised by a model, then tested against defensesLowers the skill floor for people who could not previously write an exploit
Agentic attack chainsSoftware that runs reconnaissance and lateral movement with limited human directionMachine speed removes the pauses defenders rely on to notice something

That last row is the newest and the least understood. The Congressional Research Service has documented the shift toward agentic AI in cyberattacks, where the operator’s main job becomes convincing a model to ignore its own safety controls rather than executing the attack personally.

IBM’s 2026 Cost of a Data Breach Report found that one in four malicious breaches was AI-enabled, a 56% jump over the prior year, and that those breaches averaged $6 million against a global average of $4.99 million. Deepfake impersonation was the single largest share.

We see the personal version of this constantly. A cloned voice in a custody dispute. A fabricated recording dropped into a business partnership that was already going badly. If you want the legal side of that, our breakdown of where deepfake law currently stands covers the federal and state picture, and our team handles investigating AI-generated impersonation when a specific file needs to be verified or traced.

How are defenders using AI?

Defenders use AI mainly for pattern recognition at a volume no analyst can match. A mid-sized company generates millions of log events a week. A person cannot read those. A model can, and it can flag the login at 3:14 a.m. from a device that has never touched the network.

The practical applications are narrower than the marketing suggests:

  • Anomaly detection across network traffic, logins, and file access
  • Alert triage, so a small team spends its hours on the twelve alerts that matter instead of the twelve hundred that do not
  • Email filtering tuned to writing patterns rather than keywords
  • Synthetic media detection, which flags likely deepfakes for human review

The financial case is real. IBM found that organizations using AI and automation extensively in their security operations saved an average of $1.93 million per breach compared with organizations using none.

None of that replaces knowing where your gaps are. That is what a proper security assessment is for, and it is usually cheaper than the tools people buy instead of doing one.

So who is winning, attackers or defenders?

Right now, attackers get more value per dollar, but the reason is governance rather than technology.

An attacker needs access to a model and a target. A defender needs budget, staff, policy, monitoring, and buy-in from people who would rather talk about anything else. Same technology, very different setup cost.

The numbers back that up. AI-enabled breaches added roughly $1 million per incident, while defensive AI saved roughly $1.93 million for the organizations that deployed it properly. The catch is in that last phrase. Most have not.

IBM found that 68% of breached organizations had no policy governing AI use at all, and 92% of organizations that suffered an AI-related breach lacked adequate access controls around their AI tools and data. The role of AI in cybersecurity right now is less a technology race than a paperwork race, and most companies are losing it in the paperwork.

What is shadow AI, and why does it matter more than you think?

Shadow AI is employees using AI tools your company never approved, usually with company data. It is the marketing coordinator pasting a client contract into a chatbot to summarize it. The paralegal running discovery documents through a free transcription tool. Nobody is being malicious. The data still leaves.

IBM found that shadow AI was involved in 43% of security incidents in its 2026 study, up from 20% the year before. It more than doubled in twelve months.

This is the risk I have the hardest time getting executives to take seriously, because it does not feel like an attack. There is no ransom note. There is just a contract sitting in a third-party system that nobody at your company controls, indexed, retained, and outside every agreement you signed with your client.

The fix is boring and it works. Know which tools your people use. Decide which ones are allowed. Put access controls on the data that matters. If you do not know what your team is running, an audit of who is accessing what will tell you before a client’s attorney does.

Not sure whether AI is already being used against your business or your name?

A confidential conversation with a licensed investigator will tell you what you are actually exposed to, before you spend money on tools you may not need.

Talk to an investigator

Confidential. No obligation.

How can you tell if an attack used AI?

You usually cannot tell from the content. You tell from the behavior around it.

A client called us last year about a voicemail from his CFO authorizing a $180,000 vendor payment. The voice was right. The phrasing was right. What was wrong was the sequence: the voicemail came in twenty minutes after a calendar invite got cancelled, and the callback number was one digit off. The audio was cloned from a conference panel the CFO had spoken on, which was sitting on YouTube.

Signals worth paying attention to:

  • Urgency attached to a payment or credential, especially outside normal hours
  • A channel switch, where a request that normally arrives by email suddenly arrives as a voice note or video call
  • Resistance to verification, where the sender has a reason you cannot call them back on a known number
  • Small factual drift, such as a project name that is slightly out of date or a title nobody uses internally
  • Media you cannot source, meaning a recording or image with no clear origin, no metadata, and no witness

On the technical side, a frame-by-frame review will often catch lighting inconsistencies or unnatural blinking, and audio analysis picks up cadence and pause patterns that cloned voices still get wrong. Those checks need to happen on the original file, which brings us to the part most people get wrong.

What should you do if AI was used against you?

Preserve the evidence before you do anything else. Digital evidence degrades fast, and most of it is controlled by someone other than you.

Specifically:

  1. Save the original file, not a screen recording or a forwarded copy. Forwarding strips metadata.
  2. Capture the full email headers, the URL, the posting account, and the timestamps.
  3. Screenshot everything, including the surrounding thread and the profile that sent it.
  4. Do not delete anything, even the messages you find embarrassing.
  5. Do not confront the sender. The moment they know you are looking, accounts get scrubbed and files come down.
  6. Report it, to your bank’s fraud department first if money moved, then to the platform, then to law enforcement.

After that, a forensic examination of the original file can pull metadata, edit history, device information, and generation artifacts. When there is an intrusion behind the fake rather than just a fake, our cyber team works to trace the intrusion back to its source and document the path in a form your attorney can use.

I have watched strong cases fall apart because the client forwarded the file to himself and destroyed the metadata doing it. Speed matters here more than almost anything else.

What can AI never do in cybersecurity?

AI can identify that something is probably fake. It cannot establish who made it, why, or what a court will accept.

Four things stay human:

  • Attribution. Detection software tells you a video is likely synthetic. Finding the person behind it takes subpoenas, account records, device analysis, and old-fashioned investigative work.
  • Intent. A model cannot tell the difference between a prank, a parody, and extortion. Those are legal distinctions with very different outcomes.
  • Chain of custody. Evidence has to be collected and handled in a documented way or it does not survive challenge. There is no automating that responsibility.
  • Testimony. Somebody has to sit in a chair, explain the findings in plain English, and defend them under cross-examination.

Our team has worked more than 1,000 cyber investigations, and the pattern holds across almost all of them. The technology narrows the question. A person answers it.

TL;DR

AI has made cyberattacks faster, cheaper, and far more convincing without inventing new crimes. Attackers use it for deepfake impersonation, high-volume phishing, malware development, and increasingly for automated attack chains, and the FBI recorded roughly $893 million in AI-linked losses in its first year of tracking the category. Defenders use it for anomaly detection and triage, saving nearly $2 million per breach when it is deployed with real governance behind it. The biggest unmanaged risk for most companies is shadow AI, now involved in 43% of security incidents. The role of AI in cybersecurity is to narrow the question quickly. Proving who did it, and making that proof hold up, still takes a licensed human investigator.

If a deepfake, a cloned voice, or an AI-written email has already cost you money or credibility, the evidence is still recoverable, but not for long.

Southern Recon Agency documents what happened, traces who did it, and delivers findings your attorney can use.

Request a confidential consultation

Florida licensed, License #A1400197. Call 844-307-7771. Serving Orlando, Tampa, Sarasota, and Osceola County.

Frequently Asked Questions

Is AI good or bad for cybersecurity?

AI helps both sides. Defenders use it to detect threats faster across huge volumes of data, and attackers use it to automate reconnaissance and create convincing fakes. The deciding factor is governance. Organizations with clear AI policies and access controls tend to benefit from it, while organizations without them tend to be harmed by it.

Can AI replace cybersecurity professionals?

No. AI can automate detection, triage alerts, and flag suspicious patterns, but it cannot establish intent, maintain chain of custody, identify who is behind an attack, or testify in court. Cybersecurity still depends on people who understand context and can defend their findings under scrutiny.

How is AI used by hackers?

Attackers use AI to clone voices and faces for impersonation, write phishing and business email compromise messages without the usual grammatical tells, develop and revise malware faster, and run automated attack chains that carry out reconnaissance with limited human direction. The FBI logged 22,364 AI-related complaints and roughly $893 million in losses in 2025.

Can you prove a deepfake or AI-generated message is fake?

Often, yes. Forensic examination of the original file can recover metadata, edit history, device details, and generation artifacts, and frame-by-frame video and audio waveform analysis can surface flaws that synthetic media still produces. The critical factor is preserving the original file quickly, because forwarding or re-saving it usually destroys the metadata that matters.

What is shadow AI?

Shadow AI is the use of artificial intelligence tools that an organization has not approved, typically by employees handling company or client data. It was involved in 43% of security incidents in IBM’s 2026 breach study, more than double the previous year. The risk is data leaving the organization into systems it does not control, rather than a deliberate attack.

WHAT CLIENTS SAY ABOUT US
Mark A., Tampa, FL | Attorney, 16 years

I have worked with Southern Recon on several investigations. He is an excellent investigator who always gets the job done no matter how complex or dangerous the situation. His fees are very reasonable and he usually puts in more hours than he gets paid for in order to make sure he does a professional job. I highly recommend Southern Recon Agency.

Tina G., Ontario, Canada

Matt provided me with superior service. He handled my investigation in a very professional manner and was always available for me 24/7. He helped solve my case and provided me with accurate evidence proving the suspicion of my husband’s infidelity. I highly recommend his services. Words cannot express the gratitude I have for his services!

Chris G., Tampa, Fl

I requested a background investigation on person that I was looking to conduct business with. I corresponded with the professionals at the Agency over email and the telephone. At no time, was I confused or concern about the process of this investigation. The process was thoroughly explained. Matt Aubin potentially saved me thousands of dollars by giving me an accurate understanding of who I was looking to do business with. Needless to say, I will not be conducting any business with this individual. I am extremely grateful for the work performed by Matt and the agency. It was worth every penny. The level of service provided exceeded my expectations.

Donnie C., Orlando, Fl

These folks are professional and will get results for you quickly. They are not the run of the mill grinding hours for billing people that often fill this profession. Thanks!