Assume AI cybersecurity attacks are the future: 43% of companies have already experienced it
Follow ZDNET: Add us as a preferred source on Google.

Follow ZDNET: Add us as a preferred source on Google.
Forty-three percent of organizations have experienced AI-enhanced or AI-generated phishing attacks, and 37% have encountered AI-augmented malware, according to a new survey.
CDW's 2026 Security Research Report is based on a survey of 951 IT decision-makers across a variety of industries. Published Monday, the research reveals what appears to be an AI arms race between cyberattackers and defenders. Many organizations are considering investing in AI threat detection, training, and controls to combat the new face of modern cyber threats: AI techniques, tactics, and technologies.
There are serious numbers in the report that deserve our particular attention. One or two cyber incidents against high-profile organizations involving a sophisticated AI model is one thing, but there's an undercurrent of quiet, malicious AI attack development that is far more likely to impact the average company.
Also: AI agents are fast, loose, and out of control, MIT study finds
In addition, when survey respondents were asked which AI-enabled cybersecurity threats pose the greatest risk to their organizations, 25% said AI-generated phishing and social engineering attacks were most concerning, followed by AI-powered malware and automated attack tools (21%). These attack vectors appear to have overshadowed worries about deepfakes, with only 8% of respondents citing deepfake impersonation as the biggest risk to their companies.
For years, security experts have warned companies to adopt the mindset that they will experience a security breach at some stage -- it's a matter of when, not if.
With the rapid emergence of AI-backed, fully autonomous, agentic attacks, this message is more pertinent than ever.
Also: OpenAI's attack agent did exactly what it was told - just more relentlessly than expected
It was only this month that Hugging Face revealed an intrusion by agentic AI . Although the organization's own AI defenses caught it, the case highlights what companies face in keeping their systems, data, and customer records safe.
In total, 41% of respondents to the CDW survey said they planned to deploy AI-driven threat detection systems in the near future, with 49% focusing on threat and anomaly detection, 47% exploring threat intelligence analysis, and 42% opting for phishing and fraud detection.
Source: ZDNet