Zscaler Report Reveals Surge in AI-Driven Cyberattacks Targeting Critical Business Operations

2 Sources

Share

Zscaler's 2025 Phishing Report uncovers a shift in cybercriminal tactics, with AI-powered attacks targeting high-impact business functions. The report highlights the need for advanced AI-driven defenses and zero trust architecture to combat evolving threats.

News article

AI-Powered Cyberattacks on the Rise

Zscaler, Inc., a leader in cloud security, has released its ThreatLabz 2025 Phishing Report, revealing a significant shift in cybercriminal tactics. The report, which analyzed over two billion blocked phishing attempts in 2024, highlights the increasing use of Generative AI (GenAI) by attackers to launch sophisticated, targeted attacks against critical business operations

1

2

.

Key Findings

The report uncovered several important trends:

  1. Global phishing decreased by 20%, with a 32% drop in the U.S., partly due to improved email authentication standards

    1

    .
  2. Emerging markets like Brazil, Hong Kong, and the Netherlands saw a surge in phishing activity

    2

    .
  3. Community platforms such as Facebook, Telegram, Steam, and Instagram are increasingly being exploited for phishing campaigns

    1

    2

    .
  4. Tech support scams remained widespread, with over 159 million hits recorded in 2024

    1

    2

    .

AI-Driven Attack Strategies

Cybercriminals are leveraging GenAI to enhance their attack capabilities:

  1. Creating near-flawless phishing lures that can evade AI-based defenses

    1

    .
  2. Generating fake websites and crafting deepfake voice, video, and text for social engineering

    2

    .
  3. Developing new scams that mimic AI tools, such as resume generators and design platforms

    1

    2

    .
  4. Targeting critical departments like payroll, finance, and HR, as well as executives

    2

    .

Shift in Attacker Focus

Deepen Desai, CSO and Head of Security Research at Zscaler, noted, "The phishing game has changed. Attackers are using GenAI to create near-flawless lures and even outsmart AI-based defenses"

1

. This shift represents a move from high-volume email blasts to more targeted, AI-fueled attacks designed to exploit human behavior and evade traditional security measures.

Emerging Threats: Fake AI Assistants

A new trend identified in the report is the creation of fake "AI assistant" or "AI agent" websites. These fraudulent sites offer services like resume generation, graphic design, and workflow automation, capitalizing on the growing trust and integration of AI tools in daily life

1

2

.

Defensive Strategies

To combat these evolving threats, Zscaler recommends a multi-layered approach:

  1. Implementing robust zero trust architecture

    1

    2

    .
  2. Deploying advanced AI-driven phishing prevention systems

    1

    .
  3. Securing public AI use and shielding private AI models

    2

    .
  4. Detecting AI-generated threats

    2

    .

Global Impact and Market Trends

While overall phishing attempts decreased globally, the report highlights a geographical shift in attack focus:

  1. Established targets like India, Germany, and the UK remain under sustained pressure

    2

    .
  2. Emerging markets are seeing increased activity, often where digital adoption outpaces security investment

    1

    2

    .

Conclusion

The Zscaler ThreatLabz 2025 Phishing Report underscores the critical need for organizations to adapt their cybersecurity strategies in the face of AI-driven threats. As cybercriminals continue to leverage advanced technologies, businesses must invest in equally sophisticated defense mechanisms to protect their critical operations and sensitive data.

TheOutpost.ai

Your Daily Dose of Curated AI News

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

© 2025 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo