Proofpoint Research Finds 65% of Organisations in Singapore Affected by Ransomware Say AI Made Attacks More Effective | #ransomware | #cybercrime


Global study reveals that AI is amplifying phishing, impersonation and credential theft, transforming ransomware into a human-centric extortion problem

  • 45% of organisations in Singapore said employees trusted AI-powered attacks, while 48% interacted with malicious content.
  • More than one-quarter (28%) of attacks began with phishing emails or other email-based social engineering.
  • Three-quarters of victims had data stolen, and 45% of those who paid faced additional ransom demands.

SINGAPORE, July 29, 2026Proofpoint, Inc., a global leader in human- and agent-centric security, today released its 2026 AI-Era Ransomware Report, revealing that artificial intelligence is making ransomware significantly more successful by helping attackers create more convincing phishing, impersonation and credential theft campaigns. The global study found that nearly two-thirds (65%) of global organisations affected by ransomware said AI increased the effectiveness of the attack, reinforcing a broader shift in which ransomware increasingly succeeds by exploiting people, identities and trusted communications.

Based on a survey of 953 cybersecurity professionals across 12 countries, the research shows that modern ransomware has evolved beyond an encryption event into a sustained extortion campaign. Attackers are increasingly stealing credentials and sensitive data before deploying ransomware, using trusted communications to gain initial access and applying continued pressure through repeated extortion demands.

“AI hasn’t fundamentally changed ransomware, but it has materially improved the attacks that lead to ransomware,” said Ryan Kalember, Chief Strategy Officer at Proofpoint. “Today’s attackers are using AI to create highly convincing phishing emails, malware components like scripts, and credential theft campaigns that exploit human trust at scale. Organisations that continue treating ransomware and data extortion as endpoint or recovery problems are missing what these attacks most frequently begin with: people, identities and trusted communications.”

Key Singapore findings from Proofpoint’s 2026 AI-Era Ransomware Report include:

  • People are the primary ransomware attack surface, and AI is making it worse. With AI, attackers can create more convincing phishing lures, write more targeted impersonation messages, and do faster reconnaissance of organisational structures and message patterns. Among Singaporean organisations that experienced a ransomware attack, 10% said that AI significantly increased the attack’s effectiveness. Another 58% said that it somewhat increased effectiveness. Combined, 68% said AI made the attack more effective. 3% reported no evidence of AI use at all.
  • The leading entry methods are all human-dependent. When Singaporean organisations identified the primary point of entry for their ransomware incident, the results pointed overwhelmingly to human interaction. Phishing emails and other email-based social engineering attacks were the initial entry vector in 28% of incidents. Malicious links (53%) were identified as the most common initial threat, followed by malicious attachments (38%), and conversation hijacking (38%). This demonstrates that today’s most successful ransomware campaigns continue to rely on trusted communications and user interaction throughout the attack lifecycle.
  • Payment leads to escalation, not resolution. Despite years of guidance from law enforcement and security agencies advising against payment, half (50%) of affected Singaporean organisations paid a ransom. Yet, nearly half (45%) of those that paid faced a second extortion demand, highlighting ransomware’s evolution from a single payment event into an ongoing negotiation in which attackers hold multiple forms of leverage at the same time: continued encryption, stolen data, and the threat of public disclosure. 
  • Encryption is no longer the endgame. Three-quarters (75%) of Singaporean organisations confirmed that data was stolen during the incident. Today’s ransomware campaigns are less about locking systems and more about acquiring data, identities, and persistent access. These can be monetized through repeated demands, sold on criminal marketplaces, or used as launching pads for secondary attacks.
  • Attacks succeed through manipulation. When Singaporean respondents were asked why the ransomware attack was able to bypass their existing controls, 45% of organisations said employees did not suspect the attack because it appeared authentic, while 48% attributed the incident to users interacting with malicious content – evidence that AI is making social engineering increasingly difficult to distinguish from legitimate business communications.
  • Ransomware impact varies by country. Respondents in Singapore reported high rates of AI-enhanced attack effectiveness (68%), ransom payments (50%) and confirmed sensitive data theft (40%). Meanwhile, user interaction as a bypass factor was highest in Japan (49%), India (49%), and Singapore (48%). In these markets, the most common failure mode was users engaging directly with malicious content rather than being deceived by impersonation.

“Ransomware remains highly human-dependent, particularly across Asia Pacific markets such as Singapore, where AI is making attacks appear more authentic and harder to detect,” said George Lee, Senior Vice President, Asia Pacific & Japan, Proofpoint. “Paying a ransom rarely resolves the crisis — more often, it invites a second demand while the stolen data continues to generate risk long after the incident is contained. With sensitive data, regulatory obligations and customer trust all on the line, organisations need to shift from reactive recovery to proactively defending the people and communications attackers are targeting in the first place.”

The findings reinforce that organisations can no longer treat ransomware primarily as a malware problem. As AI makes phishing, impersonation and credential theft increasingly convincing, preventing ransomware means protecting people, identities and trusted communications before attackers ever reach the endpoint.

 

Proofpoint’s 2026 AI-Era Ransomware Report is available at: https://www.proofpoint.com/us/resources/threat-reports/ai-era-ransomware-report

Methodology

Between March and April 2026, 953 full-time security professionals across organisations of varying sizes and industries were surveyed. Respondents represented 20 industries and spanned 12 countries, including the U.S., the U.K., France, Germany, Italy, Spain, the UAE, Australia, Japan, Singapore, India, and Brazil.

About Proofpoint, Inc. 

Proofpoint, Inc. is a global leader in human- and agent-centric cybersecurity, securing how people, data and AI agents connect across email, cloud and collaboration tools. Proofpoint is a trusted partner to over 80 of the Fortune 100, over 14,000 large enterprises, and millions of smaller organisations in stopping threats, preventing data loss, and building resilience across people and AI workflows. Proofpoint’s collaboration and data security platform helps organisations of all sizes protect and empower their people while embracing AI securely and confidently. Learn more at www.proofpoint.com

Connect with Proofpoint on LinkedIn.

Proofpoint is a registered trademark or tradename of Proofpoint, Inc. in the U.S. and/or other countries. All other trademarks contained herein are the property of their respective owners. 



Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW