A new 2026 AI-Era Ransomware Report from Proofpoint, based on a survey of 953 security professionals across 12 countries, delivers a sobering verdict: artificial intelligence isn’t creating new attack methods; it’s making the old ones nearly impossible to catch.
The Numbers Tell The Story
Among organisations that suffered a ransomware attack in the past year, 65% confirmed that AI made the attack more effective. Just 9% found no evidence of AI involvement at all. The report frames this clearly: AI isn’t inventing new tactics; it’s supercharging tried-and-tested ones like phishing, impersonation, and credential theft, making them harder to detect and easier to scale.
People Remain The Weakest Link
Despite years of investment in technical defences, the report found that the leading causes of ransomware entry are all human-dependent. Malicious links topped the list at 47%, followed closely by malicious attachments at 46%, credential harvesting at 36%, and business email compromise at 35%. In short, attackers aren’t breaking through firewalls; they’re walking through the front door because someone clicked, opened, or trusted something that looked legitimate.
Ransom Payment Doesn’t Mean The Story Ends
More than half (54%) of affected organisations paid a ransom globally, but payment rarely resolved anything. Of those who paid, 37% faced a second extortion demand. The United States stood out sharply, with 93% of affected organisations paying up, nearly double the global average, alongside the highest rates of confirmed data theft and AI-driven attack sophistication.
Data Theft Is Now The Norm
Roughly two-thirds of affected organisations experienced some form of data exfiltration. The report argues this signals a shift: ransomware isn’t just about locking systems anymore; it’s about stealing identities and data that can be resold, leveraged, or used to launch follow-up attacks.
Why Existing Security Tools Are Failing
Perhaps the most telling finding: when asked why attacks slipped past their defences, organisations didn’t primarily blame missing patches or misconfigured tools. Instead, 40% said the attack looked too legitimate to raise suspicion, and 38% said a user directly interacted with the malicious content. Traditional security tools are built to spot obviously “bad” signals, but AI-crafted attacks are engineered to look exactly like normal business communication.
The Bottom Line
The report’s message for security leaders is blunt: buying more tools won’t solve this. The organisations that will fare best are those that unify protection around people, identities, and every channel where trust is exploited, rather than treating ransomware as purely a technical problem to patch away.
