Two Thirds of Australian Organisations Affected by Ransomware Say AI Made These Attacks More Effective
70% of ransomware victims in Australia confirmed that data was stolen during the incident.
SYDNEY, Australia – July 23, 2026 – Proofpoint, Inc.,a global leader in human- and agent-centric security, today released its 2026 AI-Era Ransomware Report, revealing that artificial intelligence is making ransomware significantly more successful by helping attackers create more convincing phishing, impersonation and credential theft campaigns.
The global study, which surveyed 953 cybersecurity professionals across 12 countries, including Australia shows that modern ransomware has evolved beyond an encryption event into a sustained extortion campaign. Two-thirds (67%) of Australian organisations affected by ransomware state that artificial intelligence has made attacks significantly or somewhat more effective and 70% confirmed data theft.
"AI hasn't fundamentally changed ransomware, but it has materially improved the attacks that lead to ransomware," said Ryan Kalember, Chief Strategy Officer at Proofpoint. "Today's attackers are using AI to create highly convincing phishing emails, malware components like scripts, and credential theft campaigns that exploit human trust at scale. Organisations that continue treating ransomware and data extortion as endpoint or recovery problems are missing what these attacks most frequently begin with: people, identities and trusted communications."
The payment of ransoms remains a problem. Despite years of guidance from law enforcement and security agencies advising against payment, just under half (49%) of affected Australian organisations paid a ransom. Yet, more than half (51%) of those that paid faced a second extortion demand.
“Australia’s results show that the apparent authenticity of the lure was the most cited reason for a successful ransomware attack, said Adrian Covich, Vice President, Systems Engineering, APJ at Proofpoint. “This does not mean Australians are inherently less security-aware, instead it reflects how successfully AI can now mimic the trusted communications that keep businesses moving. The recent ASD warning on state-aligned threat actors targeting critical Australian industries, underscores the scale of the threat we are facing.”
“The findings also show that paying a ransom does not necessarily end the incident. More than half of Australian organisations that paid were subject to a second extortion demand, demonstrating that attackers can continue to apply pressure with repeated demands and the threat of public disclosure.
Social engineering attacks remain a leading entry point for ransomware, so the need for a human-centric approach to cybersecurity has never been higher. Getting it right means protecting people and identities, understanding normal communications behaviour, and stopping deceptive messages before they can lead to a damaging incident.”
Key Australian Findings from the 2026 AI-Era Ransomware Report include:
-
AI is weaponising human trust. Among Australian organisations that experienced a ransomware attack, 26% said AI significantly increased the attack’s effectiveness, and 41% said it somewhat increased it (67% combined). Only 11% reported no evidence of AI being used.
-
The entry methods are overwhelmingly human-dependent. Phishing and email-based social engineering attacks were the initial entry vector in 37% of Australian incidents. Malicious attachments and malicious links (47%) were the most common initial threats, followed by Business Email Compromise (38%) and conversation hijacking (26%).
-
Encryption is no longer the endgame. More than two-thirds (70%) of Australian organisations confirmed that data was stolen during the incident. Today's ransomware campaigns are less about locking systems and more about acquiring data, identities, and persistent access. These can be monetised through repeated demands, sold on criminal marketplaces, or used as launching pads for secondary attacks.
-
Attacks succeed through manipulation. When Australian respondents were asked why the ransomware attack was able to bypass their existing controls, 41% of organisations said employees did not suspect the attack because it appeared authentic, while 42% attributed the incident to users interacting with malicious content - evidence that AI is making social engineering increasingly difficult to distinguish from legitimate business communications.
The findings reinforce that organisations can no longer treat ransomware primarily as a malware problem. As AI makes phishing, impersonation and credential theft increasingly convincing, preventing ransomware means protecting people, identities and trusted communications before attackers ever reach the endpoint.
Proofpoint’s 2026 AI-Era Ransomware Report is available at: https://www.proofpoint.com/us/resources/threat-reports/ai-era-ransomware-report
Methodology
Between March and April 2026, 953 full-time security professionals across organisations of varying sizes and industries were surveyed. Respondents represented 20 industries and spanned 12 countries, including Australia, the U.S., the U.K., France, Germany, Italy, Spain, the UAE, Japan, Singapore, India, and Brazil.
About Proofpoint, Inc.
Proofpoint, Inc. is a global leader in human- and agent-centric cybersecurity, securing how people, data and AI agents connect across email, cloud and collaboration tools. Proofpoint is a trusted partner to over 80 of the Fortune 100, over 14,000 large enterprises, and millions of smaller organisations in stopping threats, preventing data loss, and building resilience across people and AI workflows. Proofpoint’s collaboration and data security platform helps organisations of all sizes protect and empower their people while embracing AI securely and confidently. Learn more at www.proofpoint.com.
Connect with Proofpoint on LinkedIn.
Proofpoint is a registered trademark or tradename of Proofpoint, Inc. in the U.S. and/or other countries. All other trademarks contained herein are the property of their respective owners.