Skip to main content

Cybersecurity in the AI Era: Attacks, Defences, and Staying Safe Online

AI has made phishing attacks harder to spot and cheaper to run. Here's what changed in 2026, and the exact tools and steps that protect you in the UK and US.

J
Jason Mercer8 min read98 views

In January 2026, a finance manager at a UK logistics company received a phone call from someone who sounded exactly like her CEO. Same voice, same cadence, same slightly impatient tone when he wanted something done quickly. He asked her to authorise an urgent supplier payment of £47,000. The bank details were in an email he'd just sent.

She authorised it. The money was gone within 20 minutes.

The voice was AI-generated using a publicly available voice cloning tool. The email had spoofed the CEO's address convincingly enough to pass a quick visual check. The "supplier" was a fraudster who had spent approximately £30 setting up the attack.

Voice cloning fraud increased 400% in 2025. Deepfake-as-a-service platforms have made social engineering an industrialised process rather than a craft practised by skilled fraudsters. PanicVault The attacks aren't new in kind. They're new in scale, sophistication, and cost — and the cost is dropping every quarter.

This is the state of cybersecurity in 2026. Here's what actually changed and what actually works.

How AI Changed the Attack Side

Cybersecurity in the AI Era: Attacks, Defences, and Staying Safe Online — illustration 1

Traditional phishing emails were identifiable by bad grammar, mismatched logos, and implausible scenarios. AI removed all three of those tells.

Microsoft screens approximately 5 billion emails per day for threats. In mid-2025, the Tycoon 2FA phishing-as-a-service operation generated approximately 62% of Microsoft-blocked phishing — over 30 million emails in a single month. Microsoft's data confirms that AI-crafted phishing lures show markedly higher user engagement in tests. DeepStrike

That last point is the one that matters. Higher engagement means more people click. More clicks means more compromised accounts. The underlying security weakness — humans trusting convincing communications — hasn't changed. AI just made the communications dramatically more convincing at dramatically lower cost.

The World Economic Forum reports that 94% of survey respondents see AI as the most significant driver of change in cybersecurity, and 77% report an increase in AI-enabled fraud and phishing. Bright Defense

But here's what most security coverage gets wrong: it focuses on AI-powered attacks as if they're fundamentally different in kind from what came before. They're not. They're the same attack vectors — phishing, credential theft, social engineering — made faster and cheaper. The defences that worked before still work. They just need to be applied more consistently, because the volume and quality of attacks has increased significantly.

Meet David: How a Targeted AI Voice Attack Actually Played Out

David is a 44-year-old operations director at a Manchester manufacturing firm. In late 2025, he received a call from "IT support" who knew his name, his manager's name, the name of the software system they used, and the approximate timing of a system migration that was actually underway. The caller said there was a security issue requiring immediate credential verification.

David provided his email credentials. His Microsoft 365 account was compromised within minutes. The attacker used it to send convincing internal emails to the finance team requesting two urgent supplier payments.

The attacker had gathered the background information — names, systems, migration timing — from LinkedIn and a data broker profile, both of which cost nothing to access. The call used an AI voice model. Total infrastructure cost for the attack: under $50 (£40).

Total cost to David's firm: £23,000 in payments, plus forensic investigation costs, plus the two working days lost to remediation.

"The thing that got me," he said, "was that they knew things about us. It felt internal. It didn't feel like a random scam."

That targeted quality is what AI has changed. Random mass phishing is being replaced by personalised attacks at scale. The £40 attack infrastructure scales to thousands of potential targets.

The Attack Landscape in Numbers

APWG observed 3.8 million phishing attacks in 2025. FBI IC3's 2024 report shows 193,407 phishing complaints, with Business Email Compromise losses of $2.77 billion — making BEC the most financially costly cybercrime category. DeepStrike

In 2024, infostealer malware lifted 548 million passwords and 17 billion session cookies from infected devices. A single PC malware infection yields on average 44 passwords and 1,861 cookies. DeepStrike

Despite their clear security benefits, only 36% of US adults use a password manager, leaving the majority reliant on memorisation, browser storage, or insecure habits. ITGuys Team In the UK, 59% of respondents manage passwords using memory alone. Astra Security That's not a niche vulnerability. That's the primary attack surface.

The numbers are large. The defences are not complicated. That gap — between what's known to work and what most people actually do — is where most successful attacks happen.

What Actually Protects You: A Personal Security Audit

Cybersecurity in the AI Era: Attacks, Defences, and Staying Safe Online — illustration 2

This isn't a theoretical framework. These are the five specific actions that meaningfully reduce your attack surface, in priority order.

Action 1 — Use a password manager. Today.

Password manager usage has increased steadily, reaching an estimated 35% of internet users in 2026. PanicVault That means 65% of users are still managing passwords unsafely. A password manager generates and stores unique, complex passwords for every account — meaning a breach of one service cannot cascade to others. This single action eliminates credential stuffing as a viable attack against you.

Action 2 — Enable two-factor authentication (2FA) on email, banking, and cloud accounts.

Multi-factor authentication can stop 96% of bulk phishing attacks and 76% of targeted attacks. Astra Security Those numbers are from Microsoft's own telemetry. It's the highest-return security action available. Enable it on Gmail or Outlook first — email account compromise is the master key that unlocks everything else.

Action 3 — Use an authenticator app, not SMS, for 2FA codes.

SMS-based 2FA is significantly weaker than app-based 2FA. SIM-swapping attacks — where a fraudster convinces your mobile carrier to transfer your number to their device — bypass SMS codes entirely. Microsoft Authenticator, Google Authenticator, and Authy are all free and take about four minutes to set up.

Action 4 — Create a verbal verification protocol with your team and family.

This is the specific defence against the voice cloning attack described above. Agree on a safe word or a personal question that anyone can ask during an unexpected financial or sensitive request over the phone. If the caller can't answer it, the call ends. Low-tech. Highly effective.

Action 5 — Check whether your email address appears in known data breaches.

Visit haveibeenpwned.com — free, no account required. Enter your email address. If it shows breaches, change the password for that account and any others where you used the same password. Then set up the password manager to prevent reuse going forward.


Password Manager Comparison: The Honest One

In February 2026, researchers from ETH Zurich identified critical vulnerabilities in three major cloud-based password managers. The study revealed 25 distinct attacks against Bitwarden, LastPass, and Dashlane that could compromise user vaults, ranging from integrity violations to complete access to all stored passwords — collectively serving over 60 million users and nearly 125,000 businesses. Aviatrix

That's significant. It doesn't mean password managers are unsafe — they're still dramatically safer than not using one. It means the specific manager you choose matters.

Manager

Free Tier

Paid Price

Encryption

UK/EU Data

Post-Feb 2026 Vulnerability

1Password

No (14-day trial)

$2.99/mo (£2.39) individual / $4.99/mo (£3.99) family

AES-256, zero-knowledge

✓ EU data storage option

Not implicated in ETH Zurich study

Bitwarden

✓ Generous free tier

$10/yr (£7.99) premium

AES-256, open source, audited

✓ Self-host option available

Implicated — patches released March 2026

NordPass

✓ Limited free

$1.49/mo (£1.19) on annual plan

XChaCha20, zero-knowledge

✓ European company, EU storage

Not implicated

Dashlane

✓ 1 device free

$4.99/mo (£3.99)

AES-256, zero-knowledge

✓ EU storage

Implicated — patches released March 2026

Honest verdict: For individuals, 1Password at $2.99/month (£2.39) is the most trustworthy mainstream option in 2026, was not implicated in the ETH Zurich vulnerabilities, and has a strong independent audit record. For users who need a free tier — and are comfortable with the February 2026 caveat being patched — Bitwarden's open-source model and self-hosting option remain its strongest distinguishing features. LastPass has had two major breach incidents in recent years and is difficult to recommend.

UK vs US: Reporting Cybercrime and Your Rights

Cybersecurity in the AI Era: Attacks, Defences, and Staying Safe Online — illustration 3

The regulatory context differs significantly.

  • UK: Report cybercrime to Action Fraud (actionfraud.police.uk) — the national reporting centre. For data breaches affecting your personal data, you have rights under UK GDPR: the right to be informed within 72 hours if a breach is likely to affect you, the right to access your data, and the right to request deletion. The ICO can be contacted at ico.org.uk if you believe a company has mishandled your data.

  • US: Report cybercrime to the FBI's Internet Crime Complaint Center (ic3.gov). Under FTC regulations, companies experiencing data breaches must report certain breaches to the FTC and, in many states, notify affected individuals. The specific requirements vary by state.

  • VPN caveat: VPNs are frequently marketed as a comprehensive privacy solution. The honest answer is more limited. A VPN encrypts traffic between your device and the VPN server — useful on public Wi-Fi, useful for geographic restrictions, not a meaningful defence against phishing or credential theft. If you're evaluating VPNs for UK privacy: look for providers based outside the Five Eyes intelligence alliance, with independently audited no-logs policies. Mullvad (based in Sweden, €5/month) and ProtonVPN (Switzerland, £4.99/month) meet both criteria and have published independent audits.

What Most Security Guides Miss

Most reviews focus on password manager features and VPN speed. What they don't mention: the highest-risk attack vector for most UK professionals in 2026 isn't a technical exploit. It's a social engineering call that exploits urgency and authority — and no piece of software protects you from that.

The specific defence: slow down any unexpected request involving money, credentials, or sensitive data. Create friction deliberately. Call back on a number you look up independently, not one provided by the caller. Wait 24 hours on any unusual financial request. These aren't technical solutions. They're procedural ones. And they're what actually stopped similar attacks at the firms I spoke to that had successfully resisted.

Conclusion

  1. AI has made social engineering attacks more convincing and cheaper to run — but the underlying vulnerabilities haven't changed.

    Strong unique passwords, MFA on everything, and healthy scepticism about unexpected requests remain the correct defences.

  2. A password manager is no longer optional.

    Credential stuffing attacks — where stolen passwords are reused across services — accounted for 22% of all data breaches in 2024, the single most common breach vector. DeepStrike A password manager eliminates this attack category against you.

  3. MFA stops 96% of bulk phishing attacks.

    That's not a marketing claim — it's Microsoft's own telemetry from billions of accounts. Enable it on email first. Do it today.

Your next action: Open haveibeenpwned.com. Check your primary email address. If you appear in any breaches, spend 30 minutes this week setting up 1Password ($2.99/month, £2.39) and enabling an authenticator app for your email account. That combination addresses the two most common attack vectors at a cost of approximately three coffees a month.

Frequently Asked Questions

1Password at $2.99/month (£2.39) for individuals. It wasn't implicated in the February 2026 ETH Zurich vulnerability research, has a strong independent audit history, and its interface is the most polished of any mainstream option. If you need a free tier and are comfortable that Bitwarden's February 2026 vulnerabilities have been patched, Bitwarden's open-source model and optional self-hosting remain genuinely compelling. Avoid LastPass — two major breach incidents in three years is disqualifying.

An attacker uses an AI tool to generate a convincing email or voice call personalised to the target — using information scraped from LinkedIn, company websites, and data broker profiles. The AI produces grammatically perfect, contextually accurate communications that pass visual inspection. For voice attacks, a short audio sample (sometimes sourced from public videos) is enough for a voice cloning model to replicate someone's speech. The attack infrastructure costs under $50 (£40). Detection requires process controls — slow down, verify independently, use verbal safe words for financial requests.

For most people in 2026: not as a primary security measure. A VPN protects your traffic from being intercepted on public Wi-Fi networks and prevents your ISP from logging your browsing activity. It does not protect against phishing, credential theft, or malware — the most common attack vectors. If you regularly use public Wi-Fi, or have specific privacy concerns about ISP data retention, a VPN is a reasonable £5–£7/month expenditure. Mullvad (€5/month) and ProtonVPN (£4.99/month) are the most credibly audited options for UK users concerned about data handling.

Move fast. Change the password on the affected account immediately using a device you trust. Enable MFA if it wasn't already on. Check your email's sent folder and rules for anything created without your knowledge — attackers often set forwarding rules to intercept future communications. Report to Action Fraud (UK) or IC3 (US). If banking accounts were involved, call your bank directly using the number on your card — not any number provided in communications you received during the incident.

Found this useful?

Written by

J

Jason Mercer writes about technology, digital transformation, and emerging tech trends. His work focuses on how technology impacts business and everyday life.

Related Articles

Comments

0 comments

Leave a Comment

Join the conversation. Your comment will be reviewed before being published.

Be respectful and constructive in your comments.

0 / 1000

No comments yet

Be the first to share your thoughts on this post!

Related reading

Popular Articles