Proofpoint has published its 2026 AI-Era Ransomware Report, which found that 68% of affected organisations in Singapore said artificial intelligence made attacks more effective.
The report argues that ransomware attacks are increasingly driven by phishing, impersonation and credential theft rather than encryption alone. Based on a survey of 953 full-time security professionals across 12 countries, it identifies Singapore as one of the markets where user interaction remains central to successful attacks.
Among Singapore respondents that experienced a ransomware incident, 10% said AI significantly increased the attack’s effectiveness and 58% said it somewhat increased effectiveness. Only 3% reported no evidence of AI use.
The findings suggest attackers are using AI to make social engineering attempts more convincing. In Singapore, 45% of respondents said employees did not suspect the attack because it appeared authentic, while 48% said the incident occurred because users interacted with malicious content.
Email remained a common route into organisations. In Singapore, 28% of incidents began with phishing emails or other email-based social engineering. Malicious links were the most common threat vector at 53%, followed by malicious attachments and conversation hijacking, both at 38%.
The report also points to the growing role of data theft in ransomware incidents. Three-quarters of Singapore organisations affected by ransomware said data was stolen during the attack, indicating that extortion is increasingly tied to access to sensitive information as well as system disruption.
Payment did not necessarily end the incident. Half of affected organisations in Singapore said they paid a ransom, yet 45% of those that paid were then hit with a second extortion demand.
That pattern reflects a broader shift in how ransomware groups operate. Rather than relying only on locking systems, attackers are increasingly stealing credentials and data first, then using those assets to press repeated demands.
Globally, 65% of organisations affected by ransomware said AI increased the effectiveness of the attack. The survey covered respondents in the US, UK, France, Germany, Italy, Spain, the UAE, Australia, Japan, Singapore, India and Brazil.
Human focus
The results support the view that ransomware has become a human-centred security problem. Proofpoint argues that trusted communications, employee behaviour and identity access now play a larger role in the early stages of attacks than traditional malware delivery alone.
Singapore stood out on several measures, recording high levels of AI-enhanced attack effectiveness, ransom payments and user interaction as a factor in bypassing defences.
The report also compared Singapore with other markets on user engagement with malicious content. User interaction as a bypass factor was highest in Japan and India at 49%, followed closely by Singapore at 48%.
Those figures suggest technical controls alone are often not enough to stop modern ransomware campaigns. Attackers continue to rely on routine-looking messages and files to persuade staff to click links, open attachments or hand over credentials.
Ryan Kalember, Chief Strategy Officer at Proofpoint, described AI as an amplifier rather than a wholly new form of attack.
“AI hasn’t fundamentally changed ransomware, but it has materially improved the attacks that lead to ransomware. Today’s attackers are using AI to create highly convincing phishing emails, malware components like scripts, and credential theft campaigns that exploit human trust at scale. Organisations that continue treating ransomware and data extortion as endpoint or recovery problems are missing what these attacks most frequently begin with: people, identities and trusted communications,” said Ryan Kalember, Chief Strategy Officer at Proofpoint.
Regional picture
The report places Singapore within a wider Asia Pacific context in which organisations face strong pressure from socially engineered attacks. It says businesses in the region are dealing with incidents that are harder to detect because messages and impersonation attempts appear more authentic.
George Lee, Senior Vice President of Asia Pacific & Japan at Proofpoint, said the regional picture shows why organisations need to pay closer attention to staff, communications and identity systems.
“Ransomware remains highly human-dependent, particularly across Asia Pacific markets such as Singapore, where AI is making attacks appear more authentic and harder to detect. Paying a ransom rarely resolves the crisis – more often, it invites a second demand while the stolen data continues to generate risk long after the incident is contained. With sensitive data, regulatory obligations and customer trust all on the line, organisations need to shift from reactive recovery to proactively defending the people and communications attackers are targeting in the first place,” said Lee.
The survey covered organisations of varying sizes and industries, with respondents drawn from 20 sectors. In Singapore, the results point to a consistent theme: ransomware attacks succeed when malicious messages reach users who trust what they see and act on it.
