online

AI Is fuelling cybercrime in South Africa

Artificial intelligence may be helping businesses work faster and smarter, but cybercriminals are also putting the technology to work.

Kaspersky’s Global Research and Analysis Team, known as GReAT, has highlighted the major cybersecurity trends seen during the first half of 2026. The findings were shared at the company’s recent Cyber Security Weekend for the Middle East, Türkiye, and Africa region.

According to Kaspersky, cyberthreats are becoming more varied, sophisticated, and difficult to detect. The rapid adoption of artificial intelligence, combined with geopolitical tension and economic uncertainty, is giving attackers new ways to develop malicious tools, scale their campaigns, and adapt their tactics.

For South African organisations and internet users, the figures offer a timely reminder that online security is no longer something that can be left to chance.

MILLIONS OF ONLINE ATTACKS BLOCKED IN SOUTH AFRICA

Web-based threats remained a significant concern across the region during the first six months of 2026.

These attacks exploit vulnerabilities in websites, emails, online services, and other internet-based resources. They can include phishing pages, malicious downloads, compromised websites, and attempts to trick users into revealing sensitive information.

Kaspersky’s detection systems reportedly blocked 5.7 million attacks originating from various online resources in South Africa during the first half of the year.

Across the wider region, Türkiye recorded the highest percentage of users affected by web-based threats, at 22.8%. It was followed by Kenya at 21.2%, Qatar at 19.3%, Nigeria at 18.4%, and South Africa at 17.2%.

Saudi Arabia, Jordan, and Pakistan recorded the lowest proportions of users targeted by web-borne attacks among the countries included in the research.

Although South Africa did not top the regional list, the volume of detected attacks shows that local individuals and organisations remain attractive targets for cybercriminals.

HOW CRIMINALS ARE USING AI 

Artificial intelligence is increasingly being incorporated into several stages of cybercriminal operations.

Large language models can help attackers create convincing phishing emails, write malicious code, translate messages, and produce supporting content for fraudulent campaigns. This makes it easier to personalise attacks and launch them across different countries, industries, and languages.

Phishing messages created with AI may also contain fewer spelling mistakes and awkward phrases than traditional scam emails. As a result, they can look more professional and may be harder for recipients to identify as fraudulent.

AI is also beginning to play a more substantial role in malware development.

Modern language models can generate large sections of software code, including basic structures and functional modules. While human expertise is still required to produce more advanced malware, AI can reduce the time and effort needed to develop, test, and modify malicious tools.

Kaspersky researchers have already observed signs of AI-assisted malware development in real-world campaigns.

For example, the FunkSec cybercriminal group reportedly used AI while developing Rust-based malware capable of stealing data, encrypting files, and manipulating running processes.

Threat actors involved in the RevengeHotels campaign in 2025 were also found to have used large language models to generate parts of the code for malware infectors and downloaders.

“We expect AI to remain one of the key factors shaping the threat landscape in 2026, as we already see how it is reshaping attacker workflows and accelerating their operations,” said Sergey Lozhkin, Head of the Global Research and Analysis Team in the APAC and META regions at Kaspersky.

“By lowering the time and cost required to develop and adapt malicious tools, AI allows threat actors to iterate faster and scale their efforts. Defenders should be prepared for quicker shifts in tactics.”

MALWARE COULD BECOME MORE DIFFICULT TO DETECT

One of the emerging concerns is the potential for AI to help criminals modify malware more quickly.

Generative AI models can rewrite code in different programming languages or adapt it for different system architectures. Attackers may therefore be able to create several versions of the same malware without rebuilding it entirely from scratch.

These variations could make traditional detection methods less effective, particularly when security systems rely heavily on recognising known code patterns.

AI-assisted development may also help cybercriminals respond more rapidly when defenders discover and block an attack. Instead of abandoning a campaign, attackers could modify the malware and attempt to deploy it again.

LEGITIMATE CLOUD SERVICES ARE USED TO HIDE STOLEN DATA

Cloud platforms and file-sharing services have become essential tools for modern businesses. Unfortunately, attackers are increasingly using these legitimate services to conceal malicious activity.

Rather than transferring stolen information directly to infrastructure associated with cybercrime, attackers may route it through familiar cloud services.

Because businesses regularly exchange information through these platforms, malicious data transfers can blend in with normal network traffic. This can make suspicious activity more difficult for security teams to identify.

The trend highlights the importance of monitoring not only unfamiliar services, but also the way approved cloud tools are being used within an organisation.

RANSOMWARE ATTACKS ARE TARGETING BUSINESS OPERATIONS

Ransomware has traditionally focused on encrypting files and demanding payment for their release. However, some cybercriminal groups are shifting their attention towards disrupting the processes that keep businesses running.

Attackers may interfere with production systems, supply chains, customer services, or other operational technology. The goal is to create enough disruption that the affected organisation feels pressured to pay quickly.

This approach can have serious consequences for sectors such as manufacturing, healthcare, logistics, energy, and financial services, where even a short interruption may lead to substantial financial losses.

It also means that organisations need to think beyond backing up files. Recovery plans should consider how essential services and business processes will continue if systems become unavailable.

AI AGENTS COULD INTRODUCE NEW SECURITY RISKS 

AI agents are increasingly being used to automate tasks, access business systems, retrieve information, and perform actions on behalf of users.

To carry out these responsibilities, some agents are granted extensive access to files, applications, networks, and administrative functions. That access can make them valuable productivity tools, but it may also create a tempting target for attackers.

If an AI agent is compromised, a cybercriminal could potentially alter its instructions or configuration.

For example, an attacker might modify the agent so that it downloads a malicious file whenever the system starts. Because the activity is being performed by a trusted tool, it could be overlooked or mistaken for legitimate behaviour.

Organisations introducing AI agents should therefore apply the same security principles used for human accounts. Access should be limited to what the agent genuinely needs, activity should be monitored, and permissions should be reviewed regularly.

MALICIOUS AI SKILLS COULD BECOME A NEW ATTACK VENDOR 

The skills and integrations used by AI systems represent another emerging area of concern.

AI skills allow agents to interact with other applications and complete tasks, such as accessing documents, sending messages, updating databases, or running commands.

If one of these skills is compromised, attackers could manipulate how the AI agent behaves. This could allow them to steal sensitive data, perform unauthorised actions, or maintain access to a business system over an extended period.

The risk is particularly significant when organisations assume that an AI tool or integration is safe simply because it comes from a familiar platform.

As AI systems gain greater access to enterprise environments, businesses will need to review their AI integrations carefully and treat third-party skills as part of their broader software supply chain.

HOW ORGANISATIONS CAN STRENGTHEN THEIR DEFENCES

The growing use of AI by cybercriminals does not mean that organisations are powerless. Many of the most effective cybersecurity measures remain familiar, although they need to be applied consistently.

Kaspersky recommends continuous vulnerability management and timely software patching to reduce the number of weaknesses attackers can exploit.

Employee awareness training is equally important. Staff should know how to identify suspicious emails, unexpected login requests, unusual attachments, and attempts to create a false sense of urgency.

Organisations should also use threat intelligence to understand the tactics being used against their industry and region. Advanced security platforms, including solutions capable of detecting sophisticated and AI-assisted attacks, can provide another layer of protection.

Strong access controls, multifactor authentication, secure backups, and tested incident-response plans should form part of the wider strategy.

STAYING SECURE IN AN AI-POWERED THREAT LANDSCAPE

AI is helping cybercriminals work faster, adapt their tools, and create more convincing attacks. At the same time, cloud services, automated systems, and connected AI agents are introducing new areas that businesses need to protect.

For South African organisations, the 5.7 million web-based attacks blocked during the first half of 2026 demonstrate the scale of the challenge.

The good news is that the fundamentals still matter. Regular updates, sensible access controls, informed employees, and proactive monitoring can prevent many attacks from succeeding.

As attackers continue to experiment with artificial intelligence, businesses will need to do the same , not only by adopting new security technology, but by making sure that every new digital tool is introduced with security firmly in mind.

 

Previous

AI Is fuelling cybercrime in South Africa

Related posts

Leave a Reply

Required fields are marked *