“TRUST STARTS & ENDS WITH THE TRUTH”
Matt is both the company founder and a nationally renowned private investigator. Matt is an intelligence specialist who excels in detecting and preventing the illegal interception of communications and in providing high-tech covert surveillance. Matt has years of hands on experience in the investigation industry and has developed a reputation for incorporating state of the art technology and innovative ideas to provide effective solutions for his clients. Matt also serves as Treasurer for the Executive Board of Directors of FALI, The Florida Association of Licensed Investigators.
AI and cybersecurity refers to the use of artificial intelligence on both sides of digital defense: attackers use it to automate reconnaissance, clone voices, and generate convincing phishing at scale, while defenders use it to detect anomalies and respond faster. The impact of AI on cybersecurity is speed and volume rather than new categories of crime. Old attacks now arrive faster, cheaper, and far more convincing.
AI changes the speed, cost, and believability of attacks. It has not changed what attackers are after. Wire transfers, credentials, and blackmail material are the same prizes they were ten years ago.
What used to take a criminal a week now takes an afternoon. Researching a target, writing a flawless email in your company’s tone, building a fake login page, testing which version gets clicks: all of that used to require either skill or time. A model handles it in minutes.
The believability shift matters more than the speed. For twenty years, the advice was to look for the tell. Bad grammar. Odd spacing. A greeting that did not sound like your CFO. Those tells are gone. Generative tools write cleaner business English than most executives do.
So the effects of AI on cybersecurity land hardest on the human layer. The filters and firewalls still work. The person reading the message is the one now facing a much better forgery.
Attackers are using AI for four things: impersonation, phishing at volume, faster malware development, and automated attack chains. The FBI’s 2025 Internet Crime Report tracked artificial intelligence as a distinct crime descriptor for the first time in its history, recording 22,364 complaints and $893,346,472 in reported losses. The FBI notes that figure is almost certainly low, because victims only report AI involvement when they recognize it.
Here is how the four tactics break down.
| Tactic | What it looks like | Why it works |
|---|---|---|
| Deepfake impersonation | A video call or voicemail from an executive authorizing a payment | Video and voice used to be proof. They are now generatable. |
| AI-generated phishing and BEC | A clean, well-written email from a vendor with new banking details | Business email compromise drove $3.05 billion in losses in 2025 with no malware attached |
| AI-assisted malware | Code written and revised by a model, then tested against defenses | Lowers the skill floor for people who could not previously write an exploit |
| Agentic attack chains | Software that runs reconnaissance and lateral movement with limited human direction | Machine speed removes the pauses defenders rely on to notice something |
That last row is the newest and the least understood. The Congressional Research Service has documented the shift toward agentic AI in cyberattacks, where the operator’s main job becomes convincing a model to ignore its own safety controls rather than executing the attack personally.
IBM’s 2026 Cost of a Data Breach Report found that one in four malicious breaches was AI-enabled, a 56% jump over the prior year, and that those breaches averaged $6 million against a global average of $4.99 million. Deepfake impersonation was the single largest share.
We see the personal version of this constantly. A cloned voice in a custody dispute. A fabricated recording dropped into a business partnership that was already going badly. If you want the legal side of that, our breakdown of where deepfake law currently stands covers the federal and state picture, and our team handles investigating AI-generated impersonation when a specific file needs to be verified or traced.
Defenders use AI mainly for pattern recognition at a volume no analyst can match. A mid-sized company generates millions of log events a week. A person cannot read those. A model can, and it can flag the login at 3:14 a.m. from a device that has never touched the network.
The practical applications are narrower than the marketing suggests:
The financial case is real. IBM found that organizations using AI and automation extensively in their security operations saved an average of $1.93 million per breach compared with organizations using none.
None of that replaces knowing where your gaps are. That is what a proper security assessment is for, and it is usually cheaper than the tools people buy instead of doing one.
Right now, attackers get more value per dollar, but the reason is governance rather than technology.
An attacker needs access to a model and a target. A defender needs budget, staff, policy, monitoring, and buy-in from people who would rather talk about anything else. Same technology, very different setup cost.
The numbers back that up. AI-enabled breaches added roughly $1 million per incident, while defensive AI saved roughly $1.93 million for the organizations that deployed it properly. The catch is in that last phrase. Most have not.
IBM found that 68% of breached organizations had no policy governing AI use at all, and 92% of organizations that suffered an AI-related breach lacked adequate access controls around their AI tools and data. The role of AI in cybersecurity right now is less a technology race than a paperwork race, and most companies are losing it in the paperwork.
Shadow AI is employees using AI tools your company never approved, usually with company data. It is the marketing coordinator pasting a client contract into a chatbot to summarize it. The paralegal running discovery documents through a free transcription tool. Nobody is being malicious. The data still leaves.
IBM found that shadow AI was involved in 43% of security incidents in its 2026 study, up from 20% the year before. It more than doubled in twelve months.
This is the risk I have the hardest time getting executives to take seriously, because it does not feel like an attack. There is no ransom note. There is just a contract sitting in a third-party system that nobody at your company controls, indexed, retained, and outside every agreement you signed with your client.
The fix is boring and it works. Know which tools your people use. Decide which ones are allowed. Put access controls on the data that matters. If you do not know what your team is running, an audit of who is accessing what will tell you before a client’s attorney does.
Not sure whether AI is already being used against your business or your name?
A confidential conversation with a licensed investigator will tell you what you are actually exposed to, before you spend money on tools you may not need.
Confidential. No obligation.
You usually cannot tell from the content. You tell from the behavior around it.
A client called us last year about a voicemail from his CFO authorizing a $180,000 vendor payment. The voice was right. The phrasing was right. What was wrong was the sequence: the voicemail came in twenty minutes after a calendar invite got cancelled, and the callback number was one digit off. The audio was cloned from a conference panel the CFO had spoken on, which was sitting on YouTube.
Signals worth paying attention to:
On the technical side, a frame-by-frame review will often catch lighting inconsistencies or unnatural blinking, and audio analysis picks up cadence and pause patterns that cloned voices still get wrong. Those checks need to happen on the original file, which brings us to the part most people get wrong.
Preserve the evidence before you do anything else. Digital evidence degrades fast, and most of it is controlled by someone other than you.
Specifically:
After that, a forensic examination of the original file can pull metadata, edit history, device information, and generation artifacts. When there is an intrusion behind the fake rather than just a fake, our cyber team works to trace the intrusion back to its source and document the path in a form your attorney can use.
I have watched strong cases fall apart because the client forwarded the file to himself and destroyed the metadata doing it. Speed matters here more than almost anything else.
AI can identify that something is probably fake. It cannot establish who made it, why, or what a court will accept.
Four things stay human:
Our team has worked more than 1,000 cyber investigations, and the pattern holds across almost all of them. The technology narrows the question. A person answers it.
AI has made cyberattacks faster, cheaper, and far more convincing without inventing new crimes. Attackers use it for deepfake impersonation, high-volume phishing, malware development, and increasingly for automated attack chains, and the FBI recorded roughly $893 million in AI-linked losses in its first year of tracking the category. Defenders use it for anomaly detection and triage, saving nearly $2 million per breach when it is deployed with real governance behind it. The biggest unmanaged risk for most companies is shadow AI, now involved in 43% of security incidents. The role of AI in cybersecurity is to narrow the question quickly. Proving who did it, and making that proof hold up, still takes a licensed human investigator.
If a deepfake, a cloned voice, or an AI-written email has already cost you money or credibility, the evidence is still recoverable, but not for long.
Southern Recon Agency documents what happened, traces who did it, and delivers findings your attorney can use.
Request a confidential consultation
Florida licensed, License #A1400197. Call 844-307-7771. Serving Orlando, Tampa, Sarasota, and Osceola County.
AI helps both sides. Defenders use it to detect threats faster across huge volumes of data, and attackers use it to automate reconnaissance and create convincing fakes. The deciding factor is governance. Organizations with clear AI policies and access controls tend to benefit from it, while organizations without them tend to be harmed by it.
No. AI can automate detection, triage alerts, and flag suspicious patterns, but it cannot establish intent, maintain chain of custody, identify who is behind an attack, or testify in court. Cybersecurity still depends on people who understand context and can defend their findings under scrutiny.
Attackers use AI to clone voices and faces for impersonation, write phishing and business email compromise messages without the usual grammatical tells, develop and revise malware faster, and run automated attack chains that carry out reconnaissance with limited human direction. The FBI logged 22,364 AI-related complaints and roughly $893 million in losses in 2025.
Often, yes. Forensic examination of the original file can recover metadata, edit history, device details, and generation artifacts, and frame-by-frame video and audio waveform analysis can surface flaws that synthetic media still produces. The critical factor is preserving the original file quickly, because forwarding or re-saving it usually destroys the metadata that matters.
Shadow AI is the use of artificial intelligence tools that an organization has not approved, typically by employees handling company or client data. It was involved in 43% of security incidents in IBM’s 2026 breach study, more than double the previous year. The risk is data leaving the organization into systems it does not control, rather than a deliberate attack.