The Democratization of AI-Powered Ransomware: Trend to Watch, Threat to Tackle
- By Sheena Chin, Rubrik
- February 07, 2025

As with all innovations, AI can be a double-edged sword. In Asia-Pacific (APAC) alone, AI investments are projected to hit USD110 billion by 2030, as organizations race to scale this technology enterprise-wide.
But businesses and government agencies aren’t the only ones looking to leverage AI.
Cyber attackers are also keenly implementing AI into their operations. Traditionally, cybercriminals needed advanced technical skills, such as in-depth knowledge of programming and network security, to launch successful attacks. Now, with AI, even individuals with minimal expertise can orchestrate sophisticated attacks with the support of advanced AI weapons like WormGPT and FraudGPT. Designed to facilitate cybercrimes, these technologies make it harder than ever to protect organizations’ crown jewels — data — from falling into the wrong hands.
The rise of Ransomware-as-a-Service (RaaS) further complicates this scenario as cybercriminals increasingly rely on AI tools to turn ransomware into a point-and-click operation. By lowering the technical barriers to entry for cyber extortion, RaaS transforms ransomware into a scalable business model, offering services such as initial access brokering, data exfiltration, and negotiation, which are made even more effective by AI. This democratization of cybercrime not only increases the number of potential attackers but also enhances the effectiveness and reach of these malicious attacks.
The impending surge in AI-powered ransomware attacks poses grave risks in APAC, where at least 59% of enterprises are now targeted. Even before the proliferation of AI, organizations were struggling to keep pace with attackers. According to Rubrik’s 2024 Zero Labs report, 96% of Singapore organizations that fell victim to ransomware paid a ransom demand.
So, how can organizations defend themselves at a time when their susceptibility to cyberattacks has never been greater?
Why payout isn’t the way out
Nobody wants to pay a cyber attacker. Unfortunately, faced with either extensive recovery timelines or no chance of recovering, organizations have had no other choice.

However, trusting the criminal who brought your organization offline to deliver on their promises is fraught with danger. Recent research from Rubrik Zero Labs found only 16% of organizations who paid a ransom to receive a decryption tool were able to recover all their data.
Consider a healthcare organization — managing large volumes of sensitive patient information — falling victim to a ransomware attack. Desperate to regain access and resume operations, the organization decides to pay the ransom — only to receive incomplete decryption keys. Critical systems remain locked, paralyzing recovery efforts and exposing the organization to even greater dangers like patient health. The disruption is prolonged and also signals to cybercriminals that the victim is a prime target, increasing the risk of future, more aggressive breaches.
The unfortunate reality is that malicious cyberattacks are inevitable. In Singapore alone, our Zero Labs report revealed that 41% of organizations endured at least one ransomware attack in 2023. Yet, the true figure is likely much higher, as the Cybersecurity Agency of Singapore (CSA) highlights that many cyberattack incidents go unreported, hiding the full scale of the threat. Each payout doesn't just deplete operational budgets, it also funds the next generation of AI-powered attacks.
Keep your sensitive data within sight
To combat these threats, organizations must develop an effective data security strategy.
By shifting focus from protecting perimeters to protecting data, organizations can continuously identify and monitor sensitive data across their cloud, SaaS, and on-premises environments, ensuring real-time data visibility and control. This can provide a detailed map of where sensitive data lives, giving the clarity needed to apply the right security measures before a breach occurs.
Further, as cybercriminals increasingly exploit compromised credentials — over half of the breaches in APAC are targeting user access credentials — data security posture management (DSPM) becomes even more critical. By enforcing principles like least privileged access and right-sizing permissions, organizations can effectively limit the potential damage of a breach while ensuring business continuity.
Winning the AI fire duel
Organizations today must rethink their strategies as AI adoption surges. While AI offers immense potential, it also puts sensitive data at risk if not carefully managed. Businesses intending to harness AI face a dual threat: securing data from leaks while fending off advanced AI-driven attacks.
To counter this, organizations must fight fire with fire. AI-driven security tools can help businesses proactively detect vulnerabilities, predict attack strategies, and swiftly mitigate threats before they cause significant damage. AI can be leveraged to help mitigate data risks by supporting continuous monitoring for suspicious activity and anomaly detection. AI can also be integrated with Security Operations (SecOps) teams to decipher complex attacks and provide actionable steps to limit exposure to sensitive data. Further, AI copilots can provide prescriptive recovery plans and step-by-step guidance to accelerate recovery following an attack.
However, it’s not a matter of “if” a cyberattack happens, but “when.” Organizations are struggling with extended downtime and revenue loss due to widespread cyberattacks, so they need a partner who can help them swiftly recover from cyber incidents with minimal operational disruption.
As organizations prepare for the new year, they must build cyber resilience with minimum attack surface into their core and not make it an afterthought. Only then can they confidently pursue their goals without the threat of cyberattacks undermining their progress.
The views and opinions expressed in this article are those of the author and do not necessarily reflect those of CDOTrends. Image credit: iStockphoto/Mininyx Doodle
Sheena Chin, Rubrik
Sheena spearheads all go-to-market functions and business growth initiatives for Southeast Asia at Rubrik as managing director for ASEAN. She has more than two decades of leadership experience in ASEAN.