Ransomware’s new AI tactic could inflate cyber claims

Legal experts warn of a new trend that could pressure cyber victims into making costly mistakes

Ransomware’s new AI tactic could inflate cyber claims

Cyber

By Gia Snape

Organizations hit by ransomware may be worsening their claims exposure by acting too quickly on alarming—and potentially inaccurate—legal risk assessments produced by cybercriminals using artificial intelligence.

Kennedys legal experts warned that established ransomware groups have begun presenting victims with AI-generated analyses purporting to identify stolen data, potential regulatory consequences and other legal liabilities.

The tactic is designed to create urgency during the earliest and most chaotic stages of an incident, when forensic teams may still be working to establish what happened and what information was accessed.

“I would say it’s only in the last couple of months that we’ve really started to see these sorts of legal risk analyses coming to the forefront,” said partner Arran Roberts (pictured on the right).

Threat actors weaponize worst-case legal scenarios

The cases Kennedys has encountered have involved more established threat groups rather than lone actors or lesser-known gangs. By analyzing stolen files, attackers can present victims, customers and business partners with an immediate narrative about the severity of an incident.

These AI-generated analyses could be based on assumptions about the type of information a company would ordinarily hold. But they can leave the affected organization scrambling to respond before it has verified the criminals’ assertions.

The approach is not yet widespread, according to Senior associate Alexandra O’Hare (pictured on the left). But she said one recent threat-actor assessment cited the maximum regulatory penalties that could theoretically apply, without considering the type of data involved or the mitigating factors regulators would normally assess.

“They used the worst-case scenario,” O’Hare said. “It was a real scare tactic in terms of the information they provided.”

Roberts added: “We don’t know how these reports have been produced, whether they’ve been produced while someone is within the network, whether the threat actors actually have access to the documents they say they have access to, and whether the report is giving a realistic picture of the data they’ve taken out of the network and what they have in their possession.”

The reports can nevertheless provide investigative leads. O’Hare said references to particular folders or information can help forensic teams identify where to look and allow organizations to prepare for possible regulatory or data-subject notifications.

Premature notifications can create new problems

One of the most significant mistakes organizations make is notifying individuals before they understand whose information was affected and what happened to it.

Individuals receiving a breach notification will immediately want to know what data was involved and how they may be affected. An organization that notifies too early may be unable to answer those questions or provide meaningful reassurance. “(Business leaders) need to make sure there isn’t a knee-jerk reaction to go out and tell everyone that something has happened without having sufficient information,” O’Hare said.

The same risk applies to communications with regulators. Roberts said organizations can damage their position by reporting unverified claims from a threat actor as though they were established facts.

AI-generated assessments may also prompt victims to engage with attackers or reconsider an earlier decision not to pay a ransom. “It’s designed to get an organization into a position where it will engage and potentially make a payment," Roberts said.

AI could increase long-tail cyber exposure

Already, threat groups are using AI to improve phishing messages, imitate executives through deepfakes and produce fabricated corporate documents that can be used to threaten an organization’s reputation or share price.

“As quickly as we’re harnessing AI on the good side, I think the opposite is happening inside these threat groups,” Roberts said. “They are using it to supercharge the incidents we’re seeing.”

However, the greater concern for insurers may emerge after the immediate response to the cyberattack is over.

Historically, organizations have sometimes argued that stolen data presents a lower risk because ransomware groups obtain large, unstructured data sets that are difficult to navigate. AI could weaken that argument by allowing criminals to rapidly identify personal information, commercially sensitive material and data suitable for phishing or further fraud.

“If you have evidence that criminals are raking through the data and getting a much better sense of what’s there, the capabilities of AI create much more of a risk that they could use those tools to pick out usable information for other malicious purposes,” Roberts said.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!