The Google Gemini, ChatGPT, Microsoft Copilot, Claude by Anthropic, Perplexity and Bing apps logos is displayed on the screen of a smartphone, November 21, 2024- Credit: rafapress / Depositphotos - License: DepositPhotos

Dutch intelligence services warn AI is making cyberattacks faster and easier

Criminals are increasingly using artificial intelligence (AI) to automate and streamline cyberattacks, according to Dutch intelligence services AIVD and MIVD and five other organizations. In an open letter, the organizations urge business leaders and other organizations to “take responsibility and prioritize cybersecurity.”

The open letter was also signed by the National Cyber Security Centre (NCSC), the National Coordinator for Counterterrorism and Security (NCTV), the police, the Public Prosecution Service and CIO Rijk, the central government’s ICT organization.

The organizations warn that AI is making cyber threats faster and lowering the barrier for more malicious actors to launch attacks. They also say AI allows vulnerabilities to be found and exploited more quickly, while existing weaknesses are being magnified.

The organizations are urging businesses and other institutions to strengthen their basic cybersecurity measures. They recommend keeping systems up to date, fixing vulnerabilities, closely monitoring IT networks and making sure executives understand the latest developments.

They also emphasize the importance of the “human factor.” The signatories therefore advise organizations to “invest in awareness, changes in behavior and culture, and report incidents to the authorities.”

Cybercriminals can use AI to create malware that steals or encrypts data and to generate phishing emails aimed at obtaining sensitive information, including passwords.

Cyberattacks can have serious consequences, particularly when large amounts of personal information such as names, addresses and passport details are stolen. However, the damage may not always be apparent right away. Corporate espionage, for example, can lead to problems only at a later stage.

Attackers do not necessarily need sophisticated AI systems to launch cyberattacks, the organizations warn. Commonly available AI models can already provide enough capabilities for malicious purposes. ChatGPT, Claude and Google Gemini are examples of such widely accessible tools. Their developers say they are taking steps to prevent abuse, but security incidents, including hacks, still occur regularly.

The organizations stress that cybersecurity should be a shared responsibility rather than something left solely to IT teams and security experts. “Improving our country’s digital resilience is a task for all of us, in both the public and private sectors,” they wrote.