{"id":918,"date":"2026-03-27T15:18:19","date_gmt":"2026-03-27T20:18:19","guid":{"rendered":"https:\/\/www.paymentconsulting.net\/Blog\/wordpress\/?p=918"},"modified":"2026-03-27T15:18:19","modified_gmt":"2026-03-27T20:18:19","slug":"ransomware-and-phishing-still-drive-data-security-incidents-but-ais-shadow-looms","status":"publish","type":"post","link":"https:\/\/www.paymentconsulting.net\/Blog\/wordpress\/?p=918","title":{"rendered":"Ransomware and Phishing Still Drive Data-Security Incidents, But AI\u2019s Shadow Looms"},"content":{"rendered":"<h1 class=\"name post-title entry-title\">Ransomware and Phishing Still Drive Data-Security Incidents, But AI\u2019s Shadow Looms<\/h1>\n<p class=\"post-meta\"><span class=\"post-meta-author\"><i class=\"fa fa-user\"><\/i><a title=\"\" href=\"https:\/\/www.digitaltransactions.net\/author\/jim-daly\/\">Jim Daly<\/a><\/span>\u00a0<span class=\"tie-date\"><i class=\"fa fa-clock-o\"><\/i>March 27, 2026<\/span>\u00a0<span class=\"post-cats\"><i class=\"fa fa-folder\"><\/i><a href=\"https:\/\/www.digitaltransactions.net\/category\/news\/e-commerce\/\" rel=\"category tag\">E-Commerce<\/a>,\u00a0<a href=\"https:\/\/www.digitaltransactions.net\/category\/news\/fraud-security\/\" rel=\"category tag\">Fraud &amp; Security<\/a>,\u00a0<a href=\"https:\/\/www.digitaltransactions.net\/category\/news\/law-and-regulation\/\" rel=\"category tag\">Law and Regulation<\/a>,\u00a0<a href=\"https:\/\/www.digitaltransactions.net\/category\/news\/mobile-commerce\/\" rel=\"category tag\">Mobile Commerce<\/a>,\u00a0<a href=\"https:\/\/www.digitaltransactions.net\/category\/news\/transaction-processing\/\" rel=\"category tag\">Transaction Processing<\/a><\/span><\/p>\n<div class=\"clear\"><\/div>\n<div class=\"entry\">\n<p>The average ransomware demand soared 70% to $4.24 million last year, while the average payment was up 36% to $682,702. Meanwhile, phishing remains the leading root cause of data-security incidents, accounting for 30%, according to the 12th annual \u201cData Security Incident Response Report\u201d released late Thursday by the law firm BakerHostetler.<\/p>\n<p>The report, entitled \u201cThe Risk Remains (Mostly) the Same,\u201d draws on information and insights gained in guiding the national law firm\u2019s clients through more than 1,250 data breaches and related security compromises. Health care was the biggest affected industry at 27% of incidents, followed by finance and insurance at 18%, business and professional services at 15%, and the retail, restaurant, and hospitality sectors at 11%.<\/p>\n<div class=\"g g-4\">\n<div class=\"g-dyn a-679 c-1\">\n<div><\/div>\n<\/div>\n<\/div>\n<p>The largest ransom demand in 2025, as cited by\u00a0<strong><a href=\"https:\/\/www.digitaltransactions.net\/better-defenses-make-it-harder-to-perpetrate-fraud-a-report-finds\/\">BakerHostetler<\/a><\/strong>\u00a0was $98 million, while the largest paid ransom was $5.65 million, well under a $20-plus million payment in 2024. But the average paid ransom rose by more than a third from 2024\u2019s average of $501,338.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"alignright size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1332840\" src=\"https:\/\/v6r2p5t5.delivery.rocketcdn.me\/wp-content\/uploads\/2026\/03\/fraud-1024x1024.jpg.webp\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" srcset=\"https:\/\/v6r2p5t5.delivery.rocketcdn.me\/wp-content\/uploads\/2026\/03\/fraud-1024x1024.jpg.webp 1024w,https:\/\/v6r2p5t5.delivery.rocketcdn.me\/wp-content\/uploads\/2026\/03\/fraud-300x300.jpg.webp 300w,https:\/\/v6r2p5t5.delivery.rocketcdn.me\/wp-content\/uploads\/2026\/03\/fraud-768x768.jpg.webp 768w,https:\/\/v6r2p5t5.delivery.rocketcdn.me\/wp-content\/uploads\/2026\/03\/fraud-150x150.jpg.webp 150w,https:\/\/v6r2p5t5.delivery.rocketcdn.me\/wp-content\/uploads\/2026\/03\/fraud-70x70.jpg.webp 70w,https:\/\/v6r2p5t5.delivery.rocketcdn.me\/wp-content\/uploads\/2026\/03\/fraud-500x500.jpg.webp 500w,https:\/\/v6r2p5t5.delivery.rocketcdn.me\/wp-content\/uploads\/2026\/03\/fraud.jpg.webp 1500w\" alt=\"\" width=\"1024\" height=\"1024\" \/><\/figure>\n<\/div>\n<p>The leading types of compromises cited in BakerHostetler\u2019s client incidents were network intrusions at 47% and business email compromises, 32%. Five other types of compromises all accounted for under 10% each.<\/p>\n<p>While phishing was the root cause of nearly one-third of incidents, the cause of some 19% was unknown. Unpatched vulnerabilities accounted for 10%. At 8% each were social engineering and human error\/unintended recipients.<\/p>\n<p>Meanwhile, it\u2019s no surprise that the rapidly growing adoption of\u00a0<strong><a href=\"https:\/\/www.digitaltransactions.net\/visa-uses-ai-to-thwart-cyber-monday-fraudsters-card-com-adds-visa-direct-cross-border-payments\/\">artificial intelligence<\/a><\/strong>\u00a0is showing up in data-security incidents. At first, AI seemed mainly to be enhancing the effectiveness of phishing, but now it\u2019s more than that, according to the report\u2019s authors.<\/p>\n<p>\u201cWhen we began analyzing matter data in December 2025, AI\u2019s role in incidents appeared limited,\u201d the report says. \u201cHowever, as we approached our March 2026 publication date, we clearly passed a tipping point. AI is moving beyond serving as just an \u2018enhancer\u2019 for phishing: it is moving toward more sophisticated social engineering support and automation, and we are now seeing the rise of \u2018vibe hacking\u2019 and autonomous coordination between agentic AIs.\u201d<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"alignleft size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1332830 entered lazyloaded\" src=\"https:\/\/v6r2p5t5.delivery.rocketcdn.me\/wp-content\/uploads\/2026\/03\/BH11003-logo_CMYK_FINAL.jpg.webp\" sizes=\"auto, (max-width: 480px) 100vw, 480px\" srcset=\"https:\/\/v6r2p5t5.delivery.rocketcdn.me\/wp-content\/uploads\/2026\/03\/BH11003-logo_CMYK_FINAL.jpg.webp 480w,https:\/\/v6r2p5t5.delivery.rocketcdn.me\/wp-content\/uploads\/2026\/03\/BH11003-logo_CMYK_FINAL-300x86.jpg.webp 300w,https:\/\/v6r2p5t5.delivery.rocketcdn.me\/wp-content\/uploads\/2026\/03\/BH11003-logo_CMYK_FINAL-150x43.jpg.webp 150w\" alt=\"\" width=\"480\" height=\"137\" data-lazy-srcset=\"https:\/\/v6r2p5t5.delivery.rocketcdn.me\/wp-content\/uploads\/2026\/03\/BH11003-logo_CMYK_FINAL.jpg.webp 480w,https:\/\/v6r2p5t5.delivery.rocketcdn.me\/wp-content\/uploads\/2026\/03\/BH11003-logo_CMYK_FINAL-300x86.jpg.webp 300w,https:\/\/v6r2p5t5.delivery.rocketcdn.me\/wp-content\/uploads\/2026\/03\/BH11003-logo_CMYK_FINAL-150x43.jpg.webp 150w\" data-lazy-sizes=\"(max-width: 480px) 100vw, 480px\" data-lazy-src=\"https:\/\/v6r2p5t5.delivery.rocketcdn.me\/wp-content\/uploads\/2026\/03\/BH11003-logo_CMYK_FINAL.jpg.webp\" data-ll-status=\"loaded\" \/><\/figure>\n<\/div>\n<p>BakerHostetler cites a report from AI developer Anthropic, creator of Claude AI, in which the company disrupted fraudsters using Claude Code to automate reconnaissance, credential harvesting, and network penetration in one month\u2019s time against approximately 17 organizations in multiple industries<\/p>\n<p>Of the 1,250-plus data incidents BakerHostetler handled for clients in 2025, some 68 resulted in one or more lawsuits. Seven incidents involved payment card data, while 59 involved Social Security numbers. Many others involved medical information or health-care organizations<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Ransomware and Phishing Still Drive Data-Security Incidents, But AI\u2019s Shadow Looms Jim Daly\u00a0March 27, 2026\u00a0E-Commerce,\u00a0Fraud &amp; Security,\u00a0Law and Regulation,\u00a0Mobile Commerce,\u00a0Transaction Processing The average ransomware demand soared 70% to $4.24 million last year, while the average payment was up 36% to $682,702. Meanwhile, phishing remains the leading root cause of data-security incidents, accounting for 30%, according &hellip; <a href=\"https:\/\/www.paymentconsulting.net\/Blog\/wordpress\/?p=918\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Ransomware and Phishing Still Drive Data-Security Incidents, But AI\u2019s Shadow Looms<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-918","post","type-post","status-publish","format-standard","hentry","category-news-update"],"_links":{"self":[{"href":"https:\/\/www.paymentconsulting.net\/Blog\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/918","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.paymentconsulting.net\/Blog\/wordpress\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.paymentconsulting.net\/Blog\/wordpress\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.paymentconsulting.net\/Blog\/wordpress\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.paymentconsulting.net\/Blog\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=918"}],"version-history":[{"count":1,"href":"https:\/\/www.paymentconsulting.net\/Blog\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/918\/revisions"}],"predecessor-version":[{"id":919,"href":"https:\/\/www.paymentconsulting.net\/Blog\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/918\/revisions\/919"}],"wp:attachment":[{"href":"https:\/\/www.paymentconsulting.net\/Blog\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=918"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.paymentconsulting.net\/Blog\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=918"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.paymentconsulting.net\/Blog\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=918"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}