• Support
  • Log In
  • Sign Up
ANZIIF Logo
Go back
Professional Development

Need help with professional development?

Contact Support

View by Kind
Go back
View by Kind
Short Courses Qualifications Skills Units Compliance Webinars Events Articles Videos Activities Whitepapers Ask an Expert
View by Sector
Go back
View by Sector
Claims General Insurance Insurance Broking Reinsurance Risk Management Life and Retirement Income
All Professional Development The Journal Recognition of Prior Learning Your Career in Insurance
Studying with ANZIIF
Go back
Studying with ANZIIF Enrol Academic Calendar Assessments FNS20 Training Package Student Support
For Companies
Go back
For Companies Train your staff Life Insurance Professional Standards General Insurance Claims Handling Framework Reference books Government Training Incentives
Go back
Membership

Need help with your membership?

Contact Support

Member Tools
Go back
Member Tools
Login Become a member Renew or Reinstate your membership
Members Centre - Professional Development
About membership
Go back
About membership
Your Membership Guide Member Levels Benefits Certified Insurance Professionals Digital Badge Member Directory
Scholarships and Awards
Go back
Scholarships and Awards
Australian Industry Awards New Zealand Industry Awards Academic Awards Lloyds Scholarship Turks Bright Light Award ICNZ and ANZIIF Scholarship
Go back
About ANZIIF

ANZIIF is the leading membership, training and professional development organisation for the insurance and finance industry in the Asia-Pacific region. We partner with a broad range of organisations and government to provide services that support professional excellence. We help enhance standards and improve community understanding of insurance and finance.

Overview
Go back
Overview History Boards and Councils Annual Reports Media Governance Corporate Sponsorship Partners Careers at ANZIIF Contact
Community Initiatives
Go back
Community Initiatives
Your Career in Insurance Careers in Insurance Corporate Supporter Making a Difference Awards Donna Walker Awards Life Insurance Professional Standards General Insurance Claims Handling Framework Generation i
ANZIIF Logo
Professional Development Articles
Article
0.1CIP Points

Ask an Expert: How is AI being used in cyberattacks?

Dan Elliott, Head of Cyber Resilience for Australia and New Zealand, Zurich Resilience Solutions
24 Apr 2025 - Reading time 2 minutes
Ask an Expert How is AI being used in cyberattacks

 

AI is transforming cyberattacks by supercharging long-standing human vulnerabilities with speed, scale, and believability.

While artificial intelligence won’t cause all problems — nor solve them — it is making existing risks more effective and harder to detect. Human error remains the root cause of most breaches, with 84% involving manipulation or mistakes, and AI is increasingly being used to exploit this weak link.

In phishing, smishing (SMS-based phishing), business email compromise, and wire fraud, the attacker still needs a human target to fall for the trap.

But AI is making these attacks more sophisticated and harder to spot. Tools for AI-generated emails, cloned voices, and deepfake videos are boosting the speed of influence attacks  —flooding inboxes with believable messages faster than ever.

Some reports show users receive around 88 emails a day, many carrying links or attachments that appear trustworthy thanks to AI-assisted writing and formatting.

AI also enables scale. In recent attacks on Australia’s superannuation funds, compromised credentials, sourced from the dark web or elsewhere, were rapidly used to access systems en-masse.

Threat actors can now process vast datasets to identify vulnerable targets more efficiently. The same machine learning techniques used by security teams for risk analysis are being leveraged by attackers to plan high-return operations.

Perhaps most alarming is how AI enhances believability. It can craft messages and interactions that mimic trusted colleagues, exploiting emotional and psychological triggers.

We have seen multiple examples of victims transferring funds due to an AI-generated communication that mimicked a known associate or superior. These tactics build on social engineering principles regularly used in influence operations and are now being automated.

Looking ahead, AI’s growing ability to find vulnerabilities in code, including "zero-day exploits", poses an even greater technical threat. These are flaws that haven't yet been discovered by software makers, and AI's speed in locating them could outpace human-led patching.

The most concerning future use? AI agents that autonomously engage in back-and-forth social engineering conversations, adapting their approach in real-time to manipulate victims. This would mark a shift from human-led to machine-driven persuasion.

Ultimately, AI isn’t replacing human risk — it’s amplifying it. As attackers harness AI to increase trust in false messages, organisations must double down on awareness, behavioural training, and adaptive cybersecurity controls.

Strengthen your organisation’s "human firewall" through tailored, ongoing social engineering training—not just generic phishing simulations. Training should evolve beyond "don't click links" to helping staff, executives, and boards recognise psychological manipulation and influence tactics.

Other tactics include

  • Role-based access controls (RBAC) are critical to prevent escalation.
  • Move beyond static plans to dynamic playbooks for specific attack types and test regularly with tabletop exercises that include executives.

  • Implement layered controls like multi-factor authentication (MFA), segmentation, immutable backups, and managed endpoint detection and response solutions (an MDR or full security operations centre) 

  • Organisations should implement dual approvals, slow down fund transfers, and require secondary verifications — especially for account changes.
  • Attackers now move faster and smarter. The goal isn’t to be unbreachable — it's to avoid being the slowest target and to recover quickly.
  • Culture plays a key role. Including HR, communications, and marketing leaders in cyber discussions helps embed security into everyday business.

Attributable to Dan Elliott, Head of Cyber Resilience for Australia and New Zealand, Zurich Resilience Solutions

Ask An Expert How is AI being used in cyberattacks?

Have a question? Ask an Expert here

This is Worth

0.1 CIP Points

Login to Collect Points & Comment
What are CIP Points? About ANZIIF Membership
Professional Development

Related Resources

  • Others

    Ask an Expert

    Get insider insights on the topics that matter to you — weekly.
    Get insider insights on the topics that matter to you — weekly.
  • Premium

    Video
    0.75 CIP Points

    Webinar: Emerging Cyber Risks - From Humans to AI

    In this on-demand webinar, join Dan Elliott, Head of Cyber Resilience at ZRS, and delve into the lat
    10 Apr 2025
    60 min view
  • Article
    0.1 CIP Points

    Ask an Expert: What does a Cyber Liability Insurance policy cover and what does it exclude?

    In this edition of Ask an Expert, Melissa Tan, Partner, Lander & Rogers discusses the nuances of sta
    11 Apr 2025
    2 min read
  • Whitepaper
    0.25 CIP Points

    Cyber Protection Gap Widens for SMEs

    A new report from the Actuaries Institute, Cyber Protection Gap Widens for SMEs, reveals an increa
    15 Nov 2024
    40 min read
  • Premium

    Activity
    0.5 CIP Points

    Cyber resilience

    What do you need to do to protect yourself and your organisation from a cyber attack? Would your org
    30 Jan 2024
    20 min read
  • Your comment has been successfully posted

    Comments

    Loading comments

    Remove Comment

    Are you sure you want to delete your comment?
    This cannot be undone.

    kitchen sink logo
    • About
    • Professional Development
    • Membership
    • Compliance
    • Contact Us
    • Enrol
    • Become a Member
    • Login
    • Privacy Statement
    • Terms & Conditions

    © Copyright The Australian and New Zealand Institute of Insurance and Finance Inc. 2021

    RTO NO. 3596