Criminals with no technical coding skills can now use artificial intelligence to make digital attacks more sophisticated and scale them up. That was one of the central points made by Gabriel Pato, an ethical hacker and creator of Brazil’s largest ethical hacking channel, during Conexão Certta.
The numbers help put the scale of the problem in perspective. 2025 data from TransUnion shows companies lost roughly 8% of their revenue to fraud. The World Economic Forum’s Global Cybersecurity Outlook 2025 found that 72% of organizations experienced an increase in cyber risk over the past year, with digital fraud, phishing, and identity theft among the top threats.
How AI Eliminated the Barriers to Entry for Digital Attacks
What changed in recent years wasn’t just how sophisticated attacks became. It was accessibility. AI gives attackers two advantages that used to be mutually exclusive: scale and quality. One concrete signal of this shift came from XBOW, a system that claims to be the first autonomous penetration-testing agent to reach the top of HackerOne’s U.S. ranking, delivering results 80 times faster than a human tester.
Gabriel Pato summed up this shift during his talk: “‘Vibe Hacking’ has arrived. There are already attackers using AI as the operator, not just as a copilot. Criminals can even manipulate the AI itself to exploit vulnerabilities and gain access to sensitive information.”
The techniques gaining ground in this landscape include:
- Prompt injection: manipulates LLM-based systems into ignoring their original rules or revealing sensitive information
- RAG poisoning: corrupts AI systems by inserting malicious data into their knowledge bases
- AI-driven phishing: according to the Unit 42 Global Incident Response Report 2026, phishing and vulnerability exploitation tied as the most common initial attack vectors in 2025, at 22% each. AI makes it possible to produce error-free lures with higher conversion rates
- Deepfakes: synthetic content is no longer easy to spot with the naked eye and now requires automated detection
- Synthetic identities: profiles built by combining real data with information generated by generative AI, which pass traditional registration checks without corresponding to any real person
The Threat That Comes from Within: Shadow AI and an Expanded Attack Surface
This landscape carries an additional layer of risk that tends to be underestimated: companies’ own adoption of AI expands their attack surface when it isn’t paired with governance. According to IBM’s Cost of a Data Breach 2025, 63% of organizations have no policies to govern AI use or contain practices like shadow AI. Among organizations that have already suffered an AI-related security incident, 97% lacked adequate access controls.
Shadow AI isn’t an external threat. It’s the employee who uses an unapproved AI tool to boost productivity and, in the process, exposes the operation’s sensitive data. The leak, in this case, is organic. There’s no breach. There’s miscalibrated trust.
A Worrying Asymmetry: Attacks Evolved, the Defense Model Didn’t
Gabriel Pato brought a perspective to Conexão Certta that goes beyond technique. Over 16 years as an offensive security and red team consultant, with stints at companies like Microsoft, Mastercard, and Meta, he watched up close how the offensive side adapted far faster than the defensive one.
The attacker operates with no constraints from SLAs, compliance, or user experience impact. Defense doesn’t have that luxury. Before AI, offensive work was always about context: understanding the environment, mapping the surface, and exploiting gaps. AI didn’t change that mindset. It eliminated the barriers to entry that once made this work slow and expensive. Scale and quality, once mutually exclusive, now coexist on the attacker’s side. The defensive side is still processing what that means in practice.
The market recognizes the pressure to revisit security strategies, but response capacity still hasn’t caught up. While 66% of leaders expect AI to have a direct impact on cybersecurity in the next 12 months, only 37% say they feel prepared to use it safely, according to the World Economic Forum. Another 54% point to managing risk with partners and vendors as a main vulnerability.
How a Verification Intelligence Hub Solves Fragmentation
This mismatch has a structural explanation. Most protection operations grew by accumulation: one tool for biometrics, another for document analysis, another for authentication, each running on its own logic with no real-time context sharing. Orchestrating multiple tools emerged as an alternative, but it showed its limits, demanding a high level of configuration and ongoing curation from teams.
This model’s evolution gave rise to a new category: verification intelligence hubs that, instead of simply connecting tools, analyze transaction context and adjust decisions automatically and dynamically, with far less operational dependency.
See how Certta’s hub solves the fragmentation problem
The Failure Is on the Inside
Gabriel Pato closed his talk with a direct thesis: the market’s problem isn’t a lack of tools, but how security layers connect to each other and what they’re able to see together.
While the attacker operates as a unified system, exploiting every gap between tools that don’t talk to each other, defense still responds piece by piece. That mismatch doesn’t get fixed with one more verification layer. It gets fixed when existing layers start sharing context and making decisions together, across the entire user journey, not just at the point of entry.
The race between attack and defense has no finish line. But the distance between the two sides is, in large part, an infrastructure decision.
Sources
TransUnion: H2 2025 Top Fraud Trends Report
World Economic Forum: Global Cybersecurity Outlook 2025
Unit 42 Global Incident Response Report 2026


