Singapore's cyber landscape is transforming rapidly: my analysis of fresh data shows that 79% of local organizations have been attacked at least once using artificial intelligence over the past 12 months. This is not just statistics—it is a signal that AI has become the primary weapon of malicious actors.

The most common attack vector remains phishing with AI elements and impersonation—reported by 46% of companies. Slightly less noticeable, but no less dangerous, are attacks on AI tools themselves, including "prompt injections" (41%), as well as deepfakes and voice cloning (39%). The latter are especially concerning: they directly undermine trust and can bypass even multi-factor authentication.

AI Adoption Outpaces Protection

The paradox of the situation is that businesses are actively adopting AI—97% of respondents already use or are testing such technologies. However, only 49% control access to these tools and their outputs. This is a critical gap: companies are opening new attack surfaces without ensuring an adequate level of security.

The study is based on a survey of 400 cybersecurity decision-makers, making the sample representative of a mature market such as Singapore.

My expert assessment: this dynamic is characteristic not only of Singapore—it is a global trend. Companies that do not rethink their defense strategies in the context of AI risk facing not just isolated incidents, but systemic compromises where deepfakes and automated phishing campaigns become the norm. Managing access to AI systems is not an option, but basic cybersecurity hygiene for the new decade.