Blog

Why AI Just Broke Cybersecurity’s Oldest Defense 

For forty years, one defense held against nearly every cyberattack: a person who could sense that something felt wrong. AI just took that defense away. It can now produce a fake invoice, a cloned voice, or a deepfaked colleague that no human can reliably tell apart from the real thing. 

When Everything Goes Down at Once 

It's 8:02 on a Monday morning. Dispatch and routing systems are offline. Card processing is declined. Billing and invoicing show no data. Telemetry from remote sites has gone dark. Nobody in the building can tell yet whether this is an IT failure, a vendor outage, or an attack in progress. 

That uncertainty is the real risk. Cyber incidents rarely start with a headline about stolen data. They start with a business that suddenly can't sell, ship, bill, or keep its own operations running, and a team that has no way to tell why. 

A Pattern That Held for Four Decades 

Every era of cybercrime rhymes with the one before it. A business connects something new for convenience, speed, or savings. Attackers find the trust built into that connection and abuse it. Defenders scramble to catch up, and then the next new thing arrives. 

That loop has run five times since the 1980s: 

  • Misplaced trust (~1980s-90s). Early viruses spread through shared files and floppy disks, riding on people opening things they trusted. Today's version is a fake invoice, a spoofed supplier, or a vendor email that isn't really from the vendor. 
  • The internet connects everything (~late 90s-2000s). Connection became the default, and so did exposure. Remote access, VPNs, and vendor-managed systems widened what any one weak login could reach. 
  • Cybercrime becomes a business (~2000s-2010s). Phishing, credential theft, and payment fraud turned into an organized industry. The FBI's Internet Crime Complaint Center attributed $2.8 billion in reported losses to business email compromise in 2024 alone. 
  • Ransomware goes operational (~2015-2021). The question stopped being “did we lose data” and became “can we still operate.” IBM's 2026 Cost of a Data Breach report put the average breach cost at $4.9 million, with the average breach lifecycle being 258 days. 
  • IT and OT converge (~2018-now). Operational technology, IT systems, and vendor platforms became one interconnected ecosystem. A single compromised tool from a managed service provider can now cascade into hundreds or thousands of downstream businesses, as it did in the 2021 Kaseya incident. 

Through all five eras, one defense kept working: a human who could sense that something was off. An odd login. A grammatically strange email. A payment request that didn't sound like the person who supposedly sent it. That instinct is what the next section takes away. 

The Defense That Just Stopped Working 

For four decades, defenders taught people to spot the fake: bad grammar, the wrong tone, an invoice that looked slightly wrong, a login that felt off. That worked because faking a human convincingly took real effort. 

It doesn't take effort anymore. 

In January 2024, a finance employee at the engineering firm Arup joined a video call with people who appeared to be his CFO and several colleagues, and wired approximately $25 million on their instructions. Every other person on that call was an AI-generated deepfake. He had specifically requested the video call to verify the transaction, and the deepfake defeated the verification step itself. Arup's own CIO later demonstrated how easily this could be replicated, rebuilding a live deepfake of himself using free tools in about 45 minutes. 

This isn't a new problem, either. In 2019, a UK-based energy firm's leadership was targeted by a cloned voice impersonating a parent company executive, moving roughly $243,000 before anyone caught on, using AI voice technology that was primitive by today's standards. What was a novelty six years ago is now a commodity. 

The tells that trained employees use to catch phishing are disappearing along with the fakes. Hoxhunt's 2025 research, run across 70,000 live tests, found that fully AI-automated phishing achieved a 54% click-through rate against an elite human red team, up 24 points and now outperforming traditional phishing's 12% rate, a figure Microsoft's 2025 Digital Defense Report also cites. The economics have inverted too: IBM's X-Force research found that a tailored, convincing spear-phishing message used to take about 16 hours to craft and now takes under five minutes, at machine scale and near-zero cost. Once attackers gain a foothold, Mandiant's 2026 M-Trends report found a median time of just 22 seconds for handing off access to a compromised network to the next stage of an attack. 

Humans can't watch and judge at that speed. That's not a training gap. It's a structural limit on what human judgment was ever built to do. 

The Shift: Verify by Process, Not by Eye 

If a person can no longer reliably tell real from fake, the fix isn't a sharper-eyed person. It's removing the human from the detection loop and replacing intuition with process and machine-speed visibility. That shift has three parts: 

  1. Verify out of band. Confirm any money or instruction change using a phone number or contact method you already had on file, never the one included in the message or call itself. The Arup employee tried to verify by video call, and the attacker owned that channel too.
  2. Go identity-centric and zero-trust. Assume authenticity itself can be faked, and prove access through strong identity controls instead of how someone looks or sounds. Microsoft reports that more than 99% of roughly 600 million daily identity attacks are password-based, which is exactly the layer weak MFA and shared accounts leave exposed. 
  3. Detect at machine speed. Since people can't watch a 22-second attack unfold, detection and response have to run automatically, continuously, and across every system, not just the ones a person happens to be watching. 

      Where This Breaks Down in Practice: Colonial Pipeline 

      The clearest illustration of what happens when this shift doesn't happen in time is the Colonial Pipeline attack of May 2021. 

      Attackers got in through one compromised legacy VPN account, using a password that had been reused elsewhere and no multi-factor authentication in place. No phishing was even required. DarkSide ransomware, a variant later widely assessed to be the predecessor of BlackCat/ALPHV, shut down roughly 5,500 miles of pipeline carrying about 45% of the East Coast's refined fuel supply. The outage lasted six days, from detection on May 7 to restart on May 12. Colonial paid a $4.4 million ransom in Bitcoin within hours of the attack, though the Department of Justice later recovered about $2.3 million of it. The fallout included panic buying across 17 states and Washington, D.C., thousands of stations running dry, a federal emergency declaration, and average gas prices topping $3.00 a gallon for the first time since 2014. 

      One reused password with no MFA behind it took down a critical piece of national infrastructure for six days. Nothing about that attack required advanced AI. It required exactly the kind of gap this pattern has exposed for forty years: a trusted credential nobody was watching closely enough. 

      The Root Causes Behind Most of These Incidents 

      Across the incidents referenced here and across most breaches like them, a small set of root causes shows up again and again: 

      • Shared or legacy accounts that outlive the employee or vendor relationship they were created for 
      • Remote access and VPN credentials without multi-factor authentication 
      • Vendor and managed-service-provider access that isn't inventoried or monitored as part of the attack surface 
      • No out-of-band process for verifying payment or instruction changes 
      • Backups that exist but have never actually been tested, or that stay continuously connected to the network they're meant to protect 
      • No continuous, automated visibility into what's normal across the network, so anomalies go unnoticed for months 

      Why Detection Speed Is the Whole Game 

      Speed matters because the alternative is measured in months, not minutes. IBM's 2026 research puts the average time to identify and contain a breach at 258 days. In one of the more extreme real-world examples, malware sat undetected on point-of-sale registers for roughly nine months, quietly exposing more than 30 million payment cards, and that breach predated the AI-driven attacks described above. If a business couldn't out-watch a threat like that with human eyes before AI, it certainly can't now. 

      Where Most Teams Get Stuck 

      Two patterns show up consistently in organizations that fall behind here. First, teams keep training people to look for tells (bad grammar, an odd tone, a slightly-wrong login) years after those tells stopped being reliable. Second, many organizations still treat vendor and managed-service-provider connections as outside their own security perimeter, even though a single compromised vendor tool can cascade into hundreds of downstream businesses. 

      A related problem is tool sprawl. When compiling our NetOps Field Guide, we found that 39% of organizations manage between 11 and 30 separate monitoring systems. Fragmented tooling makes it harder, not easier, to see the one anomaly that matters across all of it. 

      Where Plixer Fits 

      Machine-speed detection depends on actually seeing what's happening across the network in real time, not on a dashboard a person has to remember to check. Plixer's network visibility platform continuously analyzes flow data across on-premises, cloud, and hybrid environments to establish what normal looks like for every device, account, and connection, then surfaces the anomalies that fall outside it: unusual authentication patterns, lateral movement between systems, or traffic to a destination nobody expects. 

      That's the practical version of “verify by process, not by eye.” Instead of asking a person to notice that a login looks unusual, Plixer's platform flags the behavioral change automatically and gives investigators the flow-level evidence to confirm it fast. In a real customer case, a school district used this kind of visibility to isolate more than 100 infected machines in under an hour, a response window that simply isn't possible when detection depends on someone happening to notice something felt off. 

      Key Takeaways 

      The pattern behind cyberattacks hasn't changed in forty years, but the one defense that always caught it has stopped working. 

      • Every era of cybercrime follows the same loop: new connection, abused trust, defenders catching up. 
      • Human judgment (“this doesn't feel right”) was the constant that made that loop survivable for four decades. 
      • AI-generated deepfakes, cloned voices, and automated phishing have eliminated the tells people were trained to spot. 
      • Attackers now move from initial access to lateral movement in a median of 22 seconds, far faster than any human-in-the-loop process can respond to. 
      • The fix is procedural, not perceptual: verify out of band, adopt identity-centric zero trust, and detect continuously at machine speed. 
      • Visibility into what's actually normal across your network is what makes machine-speed detection possible in the first place. 

      Next Steps 

      Once machine-speed detection is the goal, the next question is usually how to actually spot the behavior that matters inside all that traffic. Our guide on how to detect lateral movement, ”How To Detect Lateral Movement: A Step-by-Step Guide,” walks through how to baseline normal behavior and flag lateral movement before it turns into a full incident, using the same flow-data approach described above. 

      If flow data and network visibility are new territory for your team, our NetFlow overview, “What is NetFlow? A 2025 Overview” covers the fundamentals: what flow records actually capture, and why they're the foundation for detecting anomalies at machine speed rather than relying on someone noticing something felt wrong. covers the fundamentals: what flow records actually capture, and why they're the foundation for detecting anomalies at machine speed rather than relying on someone noticing something felt wrong. 

      See what this looks like against your own network: a Plixer demo walks through how flow-based visibility surfaces unusual authentication activity and lateral movement in your environment, using your own traffic patterns rather than a generic sample.

      Book a Demo

      FAQ

      What is a deepfake cyberattack? 

      A deepfake attack uses AI-generated audio or video to impersonate a real person, such as an executive or vendor, convincingly enough to authorize a fraudulent payment or instruction. The 2024 Arup case, where an employee wired $25 million after a video call with AI-generated colleagues, is the highest-profile example to date. 

      Why can't employees just be trained to spot AI-generated phishing? 

      Because the tells that training relies on, like bad grammar or an unnatural tone, are the exact things AI has eliminated. Research from Hoxhunt in 2025 found AI-generated phishing already outperforming an elite human red team across 70,000 live tests, which suggests the problem is with the detection method, not the training. 

      What does “verify out of band” actually mean? 

      It means confirming a request, especially one involving money or a system change, using a contact method you already had on file before the request came in, rather than the phone number or reply address included in the message itself. Attackers who compromise a communication channel can otherwise control both the request and its “verification.” 

      How is this different from normal ransomware protection? 

      Traditional ransomware protection focuses on stopping malware from executing. This shift is about closing the identity and visibility gaps, like unmonitored vendor access or unmonitored logins, that let attackers in before ransomware is ever deployed, which is exactly what happened in the Colonial Pipeline incident. 

      Do smaller businesses need to worry about this, or is it just an enterprise problem? 

      Smaller businesses are frequently the entry point rather than the target. The 2021 Kaseya incident spread through a single compromised IT management tool to an estimated 800 to 1,500 downstream businesses, most of them not the intended target at all. 

      What's the fastest first step for a team that hasn't done any of this? 

      Turning on multi-factor authentication for email, remote access, admin accounts, and financial systems closes the single most exploited gap. Microsoft reports that over 99% of roughly 600 million daily identity attacks are password-based, meaning MFA alone blocks the overwhelming majority of them. 

      How do you detect an attack that moves in 22 seconds? 

      You can't, if detection depends on a person noticing. It requires continuous, automated monitoring of network behavior that flags anomalies like unusual authentication or lateral movement the moment they happen, rather than waiting for a scheduled review or a manual alert. 

      Can network visibility tools actually stop a deepfake-driven fraud attempt? 

      Not directly. Visibility tools don't detect a fake voice on a phone call. What they can do is flag the downstream behavior, like an unusual login or unexpected data movement, if that fraudulent instruction leads to follow-on account or network activity, giving a security team a chance to catch it before it becomes a full incident. 

      Adam Howarth

      Data Scientist

      Adam Howarth is a Data Scientist and Field Engineer at Plixer with nearly ten years of experience developing advanced analytics and machine learning solutions for network operations and cybersecurity teams. He focuses on behavioral analysis, real-time detection, and scalable data systems.