How AI and ransomware are reshaping cybersecurity | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


Digital Content Editor, Eve Goode speaks exclusively with Dr Darren Williams, Founder and CEO of BlackFog about AI, ransomware and cybersecurity challenges.

Can you tell us a little about your role at BlackFog and what you’re seeing as the biggest cybersecurity challenge facing organisations today?

I’ve been building technology companies for the best part of three decades, and BlackFog is probably the most important thing I’ve worked on.

We founded the company back in 2015 on a fairly simple premise: everyone in cybersecurity was focused on stopping attackers from getting in, but nobody was watching what was leaving.

We called that anti-data exfiltration (ADX) and, since then, it’s grown to become a defining challenge of the industry.

The biggest problem I see right now is that the industry has spent years perfecting the art of keeping attackers out, but far less time thinking about what happens once they’re already in.

It all comes back to data and always has.

Attackers know that. They’re not breaking into organisations to admire the architecture; they’re there to take something.

Until security leaders make data movement the primary lens through which they assess their risk, they’ll always be solving the wrong problem.

How has the combination of AI-powered attacks and Ransomware-as-a-Service changed the cyber-threat landscape over the past few years?

The advent of accessible RaaS was the moment ransomware stopped being a specialist activity.

Before these platforms existed, launching a credible ransomware campaign required real technical expertise and resources.

RaaS changed that by packaging up everything an attacker needs, from infrastructure to payloads, and even tech support.

It’s all available on a subscription basis, turning cyber-crime into a service industry.

AI has taken that further still. It’s compressed attack timelines, automated the kind of reconnaissance that used to take days and made phishing campaigns far more convincing and scalable than anything we saw even three or four years ago.

When we started tracking ransomware activity back in 2020, we were recording around 40 publicly disclosed attacks a quarter.

By 2025, that figure had grown nearly eightfold.

In our latest research, we identified at least 79 active ransomware groups operating simultaneously.

We’re effectively seeing ransomware become industrialised.

Why do AI and RaaS make it easier for less experienced threat actors to launch sophisticated ransomware attacks at scale?

What we’re seeing in our threat intelligence is tooling that removes almost every technical obstacle that used to keep less experienced actors stuck in the minor leagues.

Take Lotus C2, a command-and-control framework that emerged earlier this year, pre-configured and ready to deploy.

Or Venom Stealer, which turns a basic social engineering lure into a continuous data exfiltration pipeline.

Then there’s Steaelite RAT, which combines remote access, data theft and extortion in a single control panel.

These aren’t tools for experts, they’re designed to get someone from initial compromise to monetisation as quickly as possible.

As a result, we’re seeing a growing number of players entering the field.

The Gentlemen ransomware group is a notable example, emerging in 2025 and claiming 273 attacks in a quarter.

New entrants are hitting the ground running in a way we simply didn’t see before.

Your latest report found that 96% of ransomware incidents now involve data exfiltration. Why has data theft become such a central part of modern ransomware campaigns?

It comes down to leverage.

If an attack is centred on encryption alone, it gives the victim some potential ways out if they refuse to pay, whether restoring from backups or rebuilding systems.

With stolen data, once an attacker has your most sensitive files, your customer records, your intellectual property, they have something you can never fully recover.

The threat of publication or sale creates pressure that doesn’t go away even if you get your systems back online.

In the incidents we tracked, attackers are averaging 743GB of stolen data per incident, and they’re giving victims an average of just 7.7 days to respond.

That combination of volume and time pressure is designed to force a decision before organisations have properly assessed their options.

But if you can stop that data from leaving your systems in the first place, you’re taking away any leverage they have entirely.

Which sectors are currently most at risk from these evolving threats, and what should security leaders be prioritising to reduce their exposure?

Healthcare, manufacturing, logistics and government are among the primary targets right now, for different reasons but with the same outcome.

Healthcare attracts attackers because of the sensitivity of the data and the operational pressure those organisations are under.

Manufacturing and construction are targeted because disruption hits hard and fast, and the pressure to restore operations is immediate.

Logistics saw a 200% year-on-year surge in the first quarter, as attackers lean into the leverage that supply chain disruption gives them.

Government sits in the mix for a similar reason: the data is high-value and the pressure to keep public services running hands attackers their leverage.

What’s interesting is that the picture shifts significantly depending on whether you’re looking at disclosed or undisclosed activity.

Healthcare dominates what gets reported publicly, but manufacturing leads the table in terms of undisclosed figures.

That gap means some sectors are carrying a much heavier burden than the headlines suggest.

When it comes to priorities, visibility has to come first, because you cannot stop data exfiltration if you can’t see it happening.

And while external attackers are the biggest threat, that visibility and control need to extend to internal processes too.

Shadow AI is a growing issue, with employees sharing sensitive data through unsanctioned tools and creating exfiltration pathways that have nothing to do with any ransomware group.

Most organisations have no visibility over that at all.

Looking ahead, how do you expect AI-powered ransomware and cyber-extortion tactics to evolve in 2026 and beyond, and what should organisations be doing now to prepare?

Agentic AI is the next frontier, and I don’t think the security industry has fully reckoned with what that means yet.

We’re talking about AI agents running locally on devices, reading files, calendars and emails, and communicating continuously with external systems, often without the user having a clear picture of what’s being sent or where.

It’s changing how data is accessed and moved, and the controls simply aren’t keeping pace.

Frontier AI is the other piece of this.

A model like Anthropic’s Mythos wasn’t built as an attack tool, it’s designed for legitimate engineering work, but the same capabilities that let it read an entire codebase and chain vulnerabilities together autonomously are exactly what an attacker would want.

Access to that particular model is tightly restricted, and rightly so, but it’s a clear signal of where the capability curve is heading.

The line between a frontier research tool and an offensive weapon is thinner than most people are comfortable admitting and the attack surface is expanding in ways traditional defences were never built to handle.

But here’s what I keep coming back to.

AI can accelerate every stage of an attack, from reconnaissance and exploitation to lateral movement and execution.

What it can’t do is make ransomware profitable without data leaving your environment.

Whether the attacker is a novice using a Ransomware-as-a-Service (RaaS) subscription or an autonomous AI agent operating at machine speed, the campaign ends the same way: your data has to be exfiltrated.

That constant is what defenders should build their strategy around. If your only objective is to keep attackers out, you’re fighting a battle you’ll eventually lose, because someone—or something—will eventually get in.

But if you prevent attackers from removing your data, you eliminate the payoff.

No matter how quickly attack tools evolve, ransomware only succeeds when data can be taken.

——————————————————–


Click Here For The Original Source.

.........................

National Cyber Security

FREE
VIEW