[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fbWVQOs6PLZIom2qLTLfOZ66f2VL1-2puBpYnnq1vrBQ":3},{"article":4,"iocs":56},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":33,"category":34,"article_tags":38},"afbaedd6-5f39-4c4d-a2d6-1c2e8c5bff70","How enterprise GenAI can amplify ransomware risk — and how to contain it","how-enterprise-genai-can-amplify-ransomware-risk-and-how-to-contain-it-6f7429","Enterprise AI can accelerate ransomware attacks when AI assistants and agents inherit excessive permissions or compromised identities. Acronis explains how identity controls, governance, and least-privilege access help reduce AI-enabled ransomware risk while supporting secure AI adoption. [...]","Generative AI, while boosting productivity, can amplify ransomware attacks by inheriting excessive permissions or compromised identities. Attackers can leverage AI to accelerate reconnaissance, credential abuse, and data theft. Organizations must strengthen identity controls, governance, and least-privilege access to mitigate these risks.","Enterprise GenAI can amplify ransomware risks by inheriting excessive permissions or compromised identities.","How enterprise GenAI can amplify ransomware risk — and how to contain it Sponsored by Acronis July 22, 2026 11:30 AM 0 Generative AI is rapidly becoming part of everyday business operations. Employees use AI assistants to summarize documents, search enterprise knowledge, draft content and automate routine tasks. Organizations are also beginning to deploy AI agents that interact with business applications and execute workflows with minimal human intervention. These technologies promise significant productivity gains, but they also introduce new security considerations. As AI gains access to the same identities, business data and systems that cybercriminals already target, it can increase the speed and scale of ransomware attacks if not properly governed. AI does not create an entirely new ransomware threat. Instead, it amplifies techniques attackers already use, particularly during reconnaissance, credential abuse and data theft. Understanding where AI changes the attack surface is becoming an important part of enterprise cyber resilience. Two AI threat models organizations should understand Discussions about AI and ransomware often combine two different threat models: Attackers using AI to improve their own operations. Criminal groups increasingly rely on AI to generate phishing emails, write malicious code, automate reconnaissance, analyze stolen information and streamline extortion. AI allows attackers to work faster and operate at greater scale without fundamentally changing how ransomware campaigns unfold. Organizations deploying enterprise AI. AI assistants and agents are increasingly connected to document repositories, collaboration platforms, SaaS applications and internal knowledge bases. If attackers compromise the identities or permissions associated with these systems, AI can accelerate their ability to locate sensitive information, navigate connected systems and abuse legitimate access. These two trends are occurring simultaneously. As attackers become more efficient through AI, organizations must ensure their own AI deployments do not unintentionally expand the attack surface. Where enterprise AI creates new exposure Not every AI application presents the same level of risk. AI assistants primarily retrieve information or generate content in response to prompts. AI agents go further by interacting with business applications, invoking APIs and performing actions on a user's behalf. The greater an application's autonomy and permissions, the greater the potential impact if its associated identity is compromised. The real issue is delegated authority. Modern ransomware campaigns typically begin with vulnerability exploitation, credential compromise or abuse of trusted third-party access. Attackers then perform discovery, escalate privileges, identify valuable data and exfiltrate information before deciding whether to encrypt systems, extort victims or both. Microsoft reports analyzing approximately 38 million identity risk detections every day, underscoring how central identity attacks have become. The Cloud Security Alliance has also documented large-scale OAuth device-code phishing campaigns targeting Microsoft 365 users. Extend cyber resilience to AI-powered workflows with Acronis AI-enabled applications introduce new security challenges, from prompt injection and unauthorized data access to AI-assisted reconnaissance. Acronis GenAI Protection helps identify shadow AI usage, monitor prompts and AI interactions, detect policy violations, and provide visibility into AI-related risks alongside endpoint, identity, SaaS, and backup telemetry. Strengthen detection, response, and recovery with a unified cyber resilience platform. Learn more about Acronis GenAI Protection How identity compromise turns AI into an attack accelerator These attacks matter for enterprise AI because AI assistants and agents inherit the identities and delegated permissions under which they operate. When attackers compromise those identities, they may also gain access to the AI services, enterprise data and connected applications available through the same permissions. An AI assistant connected to enterprise knowledge can dramatically reduce the effort required to locate sensitive information. Rather than manually searching hundreds of folders, an attacker with legitimate credentials could ask an AI assistant to identify backup documentation, administrative procedures, customer information or financial records. Similarly, if an AI agent has permission to send emails, export files or invoke connected business tools, attackers who compromise its identity could potentially abuse those capabilities to accelerate data theft or unauthorized actions. The underlying risk is excessive access rather than AI itself. Prompt injection is an AI-specific application-layer vulnerability, but it is only one part of the wider risk created by excessive permissions, insecure integrations and insufficient oversight. Malicious instructions embedded in documents, emails or web content may influence AI behavior when retrieved by enterprise applications. The impact depends largely on the permissions granted to the AI system, which is why security guidance from organizations such as OWASP emphasizes layered controls, least privilege and human approval for high-risk actions instead of relying solely on prompt filtering. AI is already making cybercrime more efficient Evidence shows AI is making existing cybercrime faster rather than fundamentally changing how attacks work. The Acronis Cyberthreats Report H2 2025 documents several examples of AI supporting different stages of cyber operations: The GTG-2002 threat group used AI to generate and debug scripts, assist credential harvesting, analyze stolen information and personalize extortion communications, allowing relatively small attack teams to scale their operations. The GLOBAL GROUP ransomware operation introduced an AI chatbot to automate ransom negotiations after compromise. While the chatbot did not change the ransomware infection chain, it enabled operators to manage more victims simultaneously while reserving human negotiators for complex cases. Anthropic researchers have documented a Chinese state-sponsored group using agentic AI to execute much of a cyberespionage campaign, including reconnaissance, vulnerability research, credential harvesting and data collection. Meanwhile, ransomware-as-a-service operators increasingly advertise AI-assisted automation for defense evasion and operational efficiency. Those advertisements signal how ransomware operators are positioning AI and where they expect it to deliver efficiency gains, although individual capability claims may not be independently verified. Taken together, these examples show AI functioning primarily as an operational force multiplier rather than creating entirely new attack techniques. Six controls that reduce AI-enabled ransomware exposure Organizations do not need to replace their existing security strategy for enterprise AI. However, they do need to extend it with AI-specific governance, access controls and monitoring. Acronis security experts advise that organizations should extend existing governance, identity and data protection practices to cover AI applications and workflows by: Maintaining an inventory of approved and unauthorized AI applications, models and integrations. Every AI workflow should have a defined owner, business purpose and appropriate risk classification. Granting least-privilege access to users, AI applications, service accounts and APIs. Regularly review delegated permissions, revoke unused credentials and limit AI access to only the systems and information required for each task. Applying controls to AI-related traffic and data movement. Use secure web gateway, CASB and DLP capabilities to discover AI services, restrict access to unauthorized tools and prevent sensitive information from being uploaded or transferred. Monitoring and auditing AI activity. ","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fhow-enterprise-genai-can-amplify-ransomware-risk-and-how-to-contain-it\u002F","https:\u002F\u002Fwww.bleepstatic.com\u002Fcontent\u002Fposts\u002F2026\u002F07\u002F22\u002Fai-prompt-acronis.jpeg","2026-07-22T15:30:00+00:00","2026-07-22T16:00:12.65061+00:00",7,[18,21,24,27,29,31],{"name":19,"type":20},"GenAI","product",{"name":22,"type":23},"Acronis","vendor",{"name":25,"type":26},"AI assistants","technology",{"name":28,"type":26},"AI agents",{"name":30,"type":26},"OAuth",{"name":32,"type":20},"Microsoft 365","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":33,"icon":35,"name":36,"slug":37},null,"Malware","malware",[39,44,49,51],{"category":40},{"id":41,"icon":35,"name":42,"slug":43},"2c8f44d4-b56e-47cf-9677-04f22c9ee78d","Identity & Access","identity-access",{"category":45},{"id":46,"icon":35,"name":47,"slug":48},"839da5c1-3c34-47e2-9499-f7201640e3ac","AI Security","ai-security",{"category":50},{"id":33,"icon":35,"name":36,"slug":37},{"category":52},{"id":53,"icon":35,"name":54,"slug":55},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[]]