Cybercrime is entering a new phase.
For decades, the most effective cyberattacks required technical expertise, specialized tools, or access to sophisticated criminal networks. While cybercrime evolved alongside technology, there was generally a direct relationship between attacker skill and success of the attack. Complex attacks required knowledgeable operators.
Generative AI is changing that equation.
Today, attackers can use AI tools to create convincing phishing emails, generate malicious code, impersonate trusted individuals, and automate social engineering campaigns at a scale that was previously unimaginable. Tasks that once required substantial expertise and time can now be performed faster, with less skill, and more cost effectively.
This marks a fundamental shift in the economics of cybercrime. AI lowers the cost of launching attacks while dramatically increasing their speed, personalization, and reach.
At the same time, AI is shifting the battlefield from technology to trust. As AI-generated emails, messages, voice recordings, and digital personas become increasingly difficult to distinguish from legitimate communications, human judgment itself is becoming a primary target.
Organizations of all sizes face this challenge, but the consequences are particularly significant for small businesses, nonprofits, schools, and local governments that often lack dedicated cybersecurity resources. Addressing this reality requires more than stronger defenses inside individual organizations. It also requires continued efforts to strengthen the Internet’s underlying infrastructure so malicious activity is identified, filtered, and disrupted before it reaches potential victims.
The Democratization of Attack Sophistication
From Specialized Skills to Accessible Tools
Historically, developing phishing campaigns, malware, or social engineering operations required time, expertise, and resources.
Today, AI systems can draft persuasive phishing messages, mimic communication styles, generate scripts, and accelerate research on potential targets. Attackers can quickly create multiple versions of content, test what works, and refine campaigns with minimal effort.
The most sophisticated attacks still require planning and technical knowledge. However, AI has significantly reduced the effort required to conduct many common forms of cybercrime, expanding the pool of individuals capable of launching effective attacks.
This creates a growing imbalance. Defenders must secure every user, device, and system, while attackers need only one successful opportunity.
Scale Changes Everything
The most transformative impact of AI may be its ability to scale operations.
Rather than sending generic phishing emails to thousands of recipients, attackers can now generate customized messages that reference an individual’s role, employer, recent activities, or professional interests. The personalization once associated with highly targeted attacks can now be applied across entire campaigns.
As a result, organizations face a difficult combination: more attacks, delivered more frequently, with content that appears increasingly legitimate.
Why Small Organizations Face Outsized Risk
Limited Resources, Growing Exposure
Small businesses, nonprofits, schools, and community organizations often rely on limited IT resources while depending heavily on email, cloud services, contractors, volunteers, and distributed workforces. These technologies create enormous benefits but also expand the potential attack surface.
Many organizations lack dedicated security teams, formal incident response plans, or budgets for advanced cybersecurity capabilities. AI-powered attacks further widen that gap by allowing criminals to produce convincing communications that appear to come from donors, customers, vendors, executives, or trusted partners.
For organizations built on relationships and trust, these attacks can be particularly effective, with devastating consequences.
The Ripple Effect
The impact of cybercrime extends far beyond a single victim.
A cyber incident affecting a nonprofit can disrupt services, expose sensitive information, and undermine donor confidence. A compromise at a small business can affect customers, suppliers, and business partners throughout its supply chain.
Cybersecurity is therefore not solely an IT issue. It is increasingly a global economic and societal challenge.
Because organizations are interconnected, a successful attack against one entity can create consequences across entire communities and sectors. This reality highlights the importance of improving security not only within organizations but across the global Internet ecosystem that connects them.
Human Trust is the New Attack Surface
The Rise of AI-Powered Impersonation
Many of today’s most effective attacks target people, not technology.
AI is making impersonation attacks more convincing and accessible through realistic emails, voice cloning, synthetic audio, and increasingly sophisticated deepfakes. These capabilities enable executive impersonation schemes, payment diversion fraud, fake support requests, and other forms of social engineering designed to bypass traditional security controls.
The challenge is these attacks exploit one of the most fundamental elements of communication: trust.
People naturally trust familiar names, recognizable voices, and established relationships. AI is making it easier for attackers to imitate all three.
Verification Becomes Essential
Cybersecurity awareness programs remain important, but awareness alone is no longer enough.
Even highly trained individuals may struggle to distinguish legitimate communications from AI-generated deception. Organizations must therefore move beyond security models that rely primarily on human detection. Instead, they should establish verification procedures that allow users to confirm legitimacy before taking action.
In the AI era, trust cannot be based solely on appearance. It must be reinforced through independent verification.
Rethinking Cybersecurity for the AI Era
Security Must Assume Deception
One of the most important shifts organizations can make is to adopt the assumption that digital communications may be deceptive until independently verified.
Verification-based security models focus on confirming identity rather than evaluating appearances. Examples include callback procedures for financial requests, independent confirmation of vendor payment changes, and formal approval processes for sensitive transactions.
Strong identity protections are equally important. Multi-factor authentication (MFA), identity verification controls, and modern access management practices help reduce the impact of compromised credentials and make impersonation attacks more difficult to execute successfully.
Building Organizational Resilience
Organizations should focus on resilience as much as prevention.
Effective cybersecurity programs combine technical controls, user education, monitoring capabilities, and incident response planning. Employees should understand not only how attacks occur but also how to verify requests, escalate concerns, and respond when something appears suspicious.
Preparation matters, because some attacks will inevitably succeed. Organizations that establish clear response procedures and recovery plans are better positioned to contain incidents and minimize disruption.
Strengthening the Internet’s Foundations
Organizations cannot solve this problem alone.
Many AI-enabled attacks rely on weaknesses in the broader Internet ecosystem. Malicious actors depend on fraudulent domains, compromised infrastructure, insecure routing practices, and other gaps that allow harmful traffic and deceptive content to reach potential victims.
As AI enables attackers to operate at greater scale, strengthening the Internet’s foundations becomes increasingly important. Stopping every attack at the user level is neither realistic nor sustainable. The Internet itself must become better at identifying and limiting malicious activity before it reaches people and organizations.
This requires continued investment in infrastructure-level security measures, including stronger routing security, improved domain trust mechanisms, threat intelligence sharing, and coordinated efforts to identify and disrupt malicious activity. It also requires a ‘security by design’ mentality when creating new tools and software. These efforts help reduce the volume of harmful traffic circulating online and increase the cost and complexity of operating cybercriminal infrastructure.
The goal is to create an Internet where fewer attacks reach users in the first place.
For years, cybersecurity strategies have placed responsibility on end users to identify and avoid threats. While education remains essential, AI is making deception increasingly difficult to detect. The more effective long-term approach combines user awareness with infrastructure improvements to remove malicious content, block fraudulent activity, and make abuse more difficult to scale.
In practice, cybersecurity resilience depends on both sides of the equation: strengthening the Internet’s underlying infrastructure to reduce threats and equipping people with the tools and knowledge needed to navigate the threats that remain.
Adapting Before the Gap Widens
AI is accelerating innovation across the global economy. Unfortunately, it is also accelerating cybercrime.
As AI lowers barriers for attackers and increases the scale of deception, cybersecurity strategies must evolve accordingly. Organizations must strengthen identity protections, implement verification-based workflows, improve incident preparedness, and reduce dependence on human judgment alone.
At the same time, governments, technology providers, infrastructure operators, and the cybersecurity community must continue working together to strengthen the Internet’s underlying architecture, disrupt malicious activity, and improve trust across the digital ecosystem.
Cybersecurity is not solely a technology challenge. It is a trust challenge.
Meeting that challenge will require action at every level—from the individual user and the small business to the systems and infrastructure that power the Internet itself. Organizations that recognize this shift and adapt accordingly will be best positioned to navigate the next phase of the digital economy.


