In the past 1–2 years, one of the biggest “accelerators” of cyber attacks has not been a new vulnerability, but a tool: generative AI. Attackers did not receive magic, but rather resources, flexibility, and better “quality”: more credible texts, better impersonation, and faster automation.
According to Microsoft’s recent observations, attackers use generative AI, among other things, to scale social engineering, automate lateral movement, and even bypass security controls.
The Google Threat Intelligence Group has already identified malware that uses LLMs during runtime for code generation and obfuscation.
This article does not aim to create panic. The goal is to show which AI-powered attacks most commonly affect SMEs and what actions should be taken now so that your company does not become the next target.
What Counts as an AI-Powered Cyber Attack?
An AI-powered cyber attack refers to any attack where the attacker uses AI:
· to increase the credibility of deception (better phishing, better BEC, deepfakes),
· to automate and accelerate attacks (mass variations, faster iteration),
· or to exploit new attack surfaces specifically related to AI systems (prompt injection, data poisoning).
The key point: in many cases, it is not that “AI hacks the system”, but rather that AI helps human attackers carry out attacks faster and more convincingly.
1) AI-Scaled Social Engineering: Phishing, Spear Phishing, BEC
Generative AI has become particularly “popular” in social engineering because it can:
· create perfectly written, context-aware emails in seconds,
· easily localize messages (even in Hungarian),
· and quickly generate variations (similar to A/B testing: which subject line works better).
Microsoft also highlights the scaling of social engineering as a typical attacker use case.
For SMEs, the most common targets include:
· finance: “new bank account number”, “urgent transfer”
· HR: “CV” / “contract”
· CEO/management: “please approve”
Why is it more dangerous now?
Because attackers leave fewer “professional traces”: poor spelling or awkward writing style no longer gives them away – and far more people can launch “professional-looking” attacks.
2) Deepfake Fraud: Voice, Video, Meetings – “The Boss Asked for It”
Deepfake attacks are particularly effective where processes rely on trust and urgency, such as:
· money transfers
· contract modifications
· data sharing (“send it quickly”)
The ENISA Threat Landscape 2024 report cites a specific example where a multinational company suffered losses exceeding 25 million USD due to a deepfake executive impersonation attack.
SME reality check
You do not need a Hollywood-level deepfake. Often it is enough to use:
· a short voice sample + an urgent “executive” message,
· a Teams/Zoom call with “low-quality” video,
· or a short video message.
What makes defense effective?
Defense does not start with technology, but with processes:
· two-channel verification for transfers (call-back policy)
· approval and limit workflows
· internal “emergency escalation” protocol: who to contact if something seems suspicious
3) “Just-in-Time AI” in Malware: Dynamic Code and Obfuscation
This goes beyond text generation. The Google GTIG 2025 report mentions malware families that use LLMs during runtime for:
· dynamic script generation
· code obfuscation
· generating functions “on demand”
This is important because traditional detection methods based on static patterns may struggle when code can “change shape”.
What does this mean from a business perspective?
Prevention and rapid response become even more valuable:
· logging
· EDR
· incident response procedures
· traceable attack chains (MITRE-based approach)
4) New Attack Surface: Prompt Injection and AI Agents
If a company uses AI systems (chatbots, internal assistants, agents, ticket triage, document summarization), attackers may attempt to:
· trick the AI into revealing sensitive information
· or submit instructions that the AI treats as legitimate commands.
Microsoft highlights prompt injection and training data poisoning as key risks in generative AI systems.
ENISA’s 2024 Threat Landscape also notes that prompt injection attacks can still cause problems even with strong defenses and must be addressed through robust data governance and policies.
Practical example (likely to become very common)
· the company’s AI processes emails or documents,
· an attacker hides instructions within the text (“change the priority”, “send this attachment”, “grant access”),
· the AI executes the instruction “in good faith”.
What Should an SME Do Now? (30-Day Priority List)
1) Close BEC/Deepfake Process Gaps (1–2 weeks)
· call-back policy (verify executive instructions through known phone numbers)
· transfer limits + two-factor approvals
· separate handling of “urgent” requests
2) Email and Identity Hardening (1–3 weeks)
· MFA on all critical accounts
· conditional access and “impossible travel” alerts
· proper DMARC/SPF/DKIM configuration
3) Awareness – but Targeted (2–4 weeks)
· finance and HR deepfake/BEC scenarios
· phishing simulations (not for “shaming”, but for measuring and improving resilience)
4) Technical Foundations
· vulnerability assessment (external attack surface)
· penetration testing (critical systems, web applications, Active Directory)
· logging and monitoring (SOC or properly configured SIEM/EDR)
5) If You Use AI Systems or Agents
· define a list of restricted data (DLP mindset)
· “untrusted input” rule: what the AI must not use for autonomous decisions
· prompt injection threat modeling
How SuperiorPentest Helps Against AI-Powered Cyber Attacks
AI-assisted attacks – such as advanced phishing, deepfake fraud, or automated exploit discovery – require more than simply deploying new tools. The most effective defense is testing systems using real attacker methodologies.
SuperiorPentest helps organizations identify critical security risks and improve their defensive capabilities.
Penetration Testing and Vulnerability Assessment (VAPT)
SuperiorPentest experts evaluate the security of infrastructures, applications, and networks using both manual and automated techniques to identify exploitable vulnerabilities before attackers can take advantage of them.
Web Application Security Testing
Web systems are common entry points for attacks. During web penetration testing, experts identify critical vulnerabilities and configuration weaknesses through specialized testing.
Vulnerability Analysis and Code-Level Testing
Security flaws in internally developed applications and software components can create serious risks. SuperiorPentest vulnerability analysis services help identify these issues early.
Threat-Led Penetration Testing and Red Teaming
Targeted attack simulations demonstrate how far a real attacker – potentially assisted by AI – could progress within an organization’s systems.
NIS2 Compliance and Security Awareness Support
SuperiorPentest supports organizations with the security assessments required for NIS2 compliance, as well as IT security and awareness training to improve employee preparedness.
If you want to understand how resilient your company is against next-generation cyber attacks, it is worth starting with a professional security assessment or penetration test.