AI & Cyber Threats

Nate, Director of Cybersecurity, recaps a webinar on how threat actors weaponize AI to run efficient underground businesses, using it to speed up phishing, malware creation, data parsing after account compromise, and to lower the skill needed for attacks, including deepfakes. He emphasizes AI itself isn’t “bad,” but intent matters, and the best protections are fundamentals: vigilance, validation, and strong financial controls. 
Check out the full series right here

AI & Cyber Threats

Watch the Episode

AI & Cyber Threats

TLDR

  • Threat actors run their own underground businesses — complete with ransomware-as-a-service and phishing-as-a-service — and AI is lowering their costs and skill requirements the same way it’s lowering yours.
  • Deepfakes get the headlines, but the real scam detector is simpler: did this message make you feel scared, urgent, or worried? That emotional reaction is the tell.
  • Phishing-resistant MFA is a real step forward, but “evil proxy” attacks can still steal a valid session token — always check the URL you’re actually logging into.
  • Banning AI outright doesn’t stop AI use. It just pushes employees to shadow AI on their own devices with your data. Guardrails work better than bans.

Every business is trying to use AI to move faster and cut costs. So is the business you’ve never heard of, run by people who want your data.

That’s the uncomfortable parallel Nate Schmitt, CIT’s Director of Cybersecurity, laid out on a recent Tech for Business episode recapping CIT’s webinar on how threat actors are weaponizing AI. Threat actors aren’t a faceless abstraction. They’re running a market — with services, specialization, and the same efficiency incentives as any other business.

The Underground AI Economy

While your team is using AI to write cleaner emails and build new tools, someone else’s team is using it to write better phishing emails and build new malware. “Instead of writing good emails, they write phishing emails,” Nate explained. “Instead of writing cool new cloud software, they’re writing malware.”

That’s not a metaphor. There are entire businesses built around ransomware-as-a-service and phishing-as-a-service — packaged offerings that let less-skilled attackers rent expertise they don’t have. AI accelerates two things at once: the cost of developing new malware drops, and the skill required to do it drops too. An attacker who once needed years of technical training can now lean on AI to close the gap. The result is faster phishing campaigns, faster parsing of a compromised inbox to find where a wire transfer might be redirected, and more attackers who qualify to run the attack in the first place.

Deepfakes Aren’t the Real Problem — Your Emotions Are

Deepfakes make for a great headline. They’re also not where Nate would spend your training budget first.

“Why do people fall for deepfakes in the first place?” he asked. The answer isn’t the technology — it’s the same reason people fall for a plain old phishing email. Circumstantial timing plays a role: a scam lands better when it happens to line up with something real, like a deal you were already discussing that “just happened” to need urgent funding. But the single biggest tell, in any format, is your own emotional reaction. Did the message make you feel scared? Urgent? Worried you’re about to lose your data?

That reaction is the point. Scammers aren’t trying to make you feel good — they’re trying to bypass the logical part of your brain and trigger the autonomic, emotional part instead. Nate’s advice: treat a strong emotional reaction to any email, call, or video as your first red flag, not an afterthought. He pointed to a sign he’d seen posted right next to the gift card rack at his local Walgreens: “If someone requested you to buy gift cards, you are likely in a scam right now.” Simple. Direct. And aimed at the same emotional trigger every scam relies on.

Protect the Money With Two Signatures

Large wire fraud almost always traces back to one person having full authority to move money without a second set of eyes. Nate’s fix is straightforward: decide how much loss your business can tolerate, then require two layers of approval for anything above that threshold.

Set the bar too low — flagging a $5 transfer — and you’ll slow the business down for no reason. Set it at the right number, and the transfers that matter get a second human review before the money leaves. Nate still sees organizations skip this step entirely, and it’s usually the reason a large wire transfer gets out the door before anyone catches it.

Passkeys Help — Until You Land on an “Evil Proxy”

Moving off SMS codes and phone calls toward phishing-resistant multi-factor authentication, like passkeys, is a real win. Microsoft is already pushing the industry in that direction. But Nate flagged a wrinkle worth knowing about: the “evil proxy.”

An evil proxy is a fake login page that looks exactly like a real Microsoft or Okta login screen. You get redirected to it, you go through a completely legitimate authentication flow — Microsoft really does send your push notification — and everything feels normal. The catch is that the attacker’s page sits in the middle of that flow and steals your session token as it passes through, then uses that token to log in as you. No new MFA prompt required, because the token itself is valid.

The fix isn’t a new tool. It’s a habit: check the actual URL before you authenticate. It needs to be portal.office.com, admin.microsoft.com, your Okta domain, or whatever your real login destination is. Anything else, stop — even if the MFA prompt looks completely normal.

Don’t Ban AI. Guide It.

A year ago, plenty of organizations tried banning AI outright. Nate’s read on that approach: it doesn’t work, and it backfires. Ban it, and employees just buy their own ChatGPT account and start feeding it corporate data anyway — what Nate calls shadow AI.

The better move is guardrails, not prohibition. Pick the tools you’re comfortable with — Microsoft Copilot, Claude, OpenAI, whatever fits your risk tolerance — and funnel usage toward those. Then define what’s actually appropriate: no healthcare information, no credit card data, nothing going into a “deep pipeline with sensitive data.” Use AI as a thought partner and a content generator. Just don’t hand it the keys to your most sensitive systems.

Have Your Incident Response Plan Ready Before You Need It

When an incident happens, Nate’s team’s first question is almost always the same: “Do you have cybersecurity insurance?” A surprising number of businesses don’t know the answer off the top of their head — which means the first two or three hours of an active incident get spent tracking down business leaders and executives just to find out who the insurer is and how to reach them.

Those are the most critical hours of the response. An incident response plan exists specifically so you’re not spending them on a phone tree. It documents who to call, in what order, and who needs to be looped in — so when something goes wrong, you’re executing a plan instead of building one from scratch under pressure.

Looking ahead, Nate expects AI-powered defense tools — many currently priced and built for large enterprises — to become more accessible for small and mid-sized businesses over the next year, alongside continued maturing of how organizations actually operationalize AI rather than just experimenting with it.

Enjoyed This Episode?

Subscribe to Tech for Business and get practical IT insights for SMB leaders every week. Or reach out — we’d love to hear what topics you want us to tackle next.