The cybersecurity vendor says AI is making phishing, impersonation and credential theft campaigns convincing, pushing ransomware beyond a malware problem and into a human-centric security challenge.
Ransomware attacks are succeeding by exploiting people’s trust rather than technicalvulnerabilities, as AI helps cybercriminals create more convincing phishing, impersonation and credential theft campaigns, according to Proofpoint.
The cybersecurity vendor said modern ransomware campaigns now rely heavily on trusted communications and social engineering to gain initial access, making it increasingly difficult for users to distinguish malicious messages from legitimate business interactions.
Proofpoint’s India country manager, Bikramdeep Singh, said the findings highlight a broader shift in how ransomware attacks are succeeding.
“India recording the highest user-interaction bypass rate in this ransomware study is sending a clear message to the industry,” Singh said.
“When employees are the reason an attack gets through more often than anywhere else, it confirms that ransomware succeeds by exploiting people’s trust, not just systems,” Singh said.
He added that as AI makes malicious interactions difficult to distinguish from legitimate business communications, organisations need to focus on protecting people and identities alongside technology controls.
Proofpoint’s 2026 AI-Era Ransomware Report suggests that AI is making the attacks that precede ransomware more effective.
Proofpoint chief strategy officer Ryan Kalember said attackers are using AI to improve phishing campaigns, create more realistic impersonation attempts and scale credential theft operations.
“AI hasn’t fundamentally changed ransomware, but it has materially improved the attacks that lead to ransomware,” Kalember said.
According to Proofpoint, AI is enabling attackers to generate more convincing phishing emails, conduct faster reconnaissance and build highly targeted social engineering campaigns that are harder for users to identify.
The company believes this is making traditional ransomware operations more successful because attackers can exploit trust at greater scale before deploying ransomware payloads.
Phishing remains a primary attack path
Proofpoint found that phishing and email-based social engineering continue to be among the most common entry points for ransomware attacks. The company said successful ransomware incidents begin with users interacting with malicious links, attachments or fraudulent communications that appear legitimate.
Rather than relying exclusively on software vulnerabilities or technical exploits, ransomware operators depend on trusted communications to gain access to organisations.
Proofpoint said the findings reinforce the growing importance of email security, identity protection and user-focused cybersecurity measures.
The company also observed that organisations affected by ransomware believed employees trusted malicious messages because they appeared authentic, reflecting how social engineering remains central to modern attack campaigns.
Proofpoint argues that ransomware is evolving beyond system encryption into a broader extortion strategy. According to the company, attackers are stealing sensitive information and credentials before deploying ransomware, allowing them to apply pressure through multiple channels.
This includes threats to release stolen information, continued extortion attempts and the use of compromised identities for future attacks.
The shift means ransomware can no longer be viewed purely as a malware or recovery problem. Instead, organisations need to prevent attackers from accessing data, identities and communications long before ransomware reaches endpoints and critical systems.
Proofpoint said many ransomware incidents now involve data theft, reflecting the growing value cybercriminals place on information and persistent access.
Human-centric security becomes critical
The company believes organisations will need to rethink how they approach ransomware defence as AI continues to improve social engineering techniques.
According to Proofpoint, protecting users, identities and communications is becoming as important as securing infrastructure and endpoints.
The company said modern ransomware campaigns begin with people rather than technology, making human-centric security a critical component of cyber resilience strategies.
For channel partners, MSSPs and cybersecurity providers, the findings point to growing opportunities around identity protection, email security, security awareness and services designed to reduce human risk.
Proofpoint said the broader lesson from the research is that ransomware succeeds long before encryption begins. It starts when attackers convince someone to trust what appears to be a legitimate communication.
The company believes organisations that focus only on endpoint protection and recovery will struggle to address where many ransomware attacks actually begin: with people, identities and trusted communications.
Click Here For The Original Source.
