READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

43% of Companies Report AI-Generated Phishing Attacks, CDW Survey Finds

43% of Companies Report AI-Generated Phishing Attacks, CDW Survey Finds
A new CDW survey of 951 IT decision-makers found 43% have already faced AI-enhanced phishing and 37% have hit AI-augmented malware. This isn't science fiction anymore. It's Tuesday for a lot of IT departments, and most companies are still playing catch-up.

The numbers are blunt. Forty-three percent of organizations have experienced AI-enhanced or AI-generated phishing attacks. Thirty-seven percent have run into AI-augmented malware. That's according to CDW's 2026 Security Research Report, published Monday and based on a survey of 951 IT decision-makers across multiple industries.

This isn't a report about some theoretical future threat. It's a report about what's already hitting companies right now.

The Threat Landscape Has Changed

When CDW asked respondents which AI-enabled threats worried them most, 25% pointed to AI-generated phishing and social engineering as the top concern. Another 21% flagged AI-powered malware and automated attack tools. Deepfake impersonation, despite all the headlines it generates, only worried 8% of respondents most.

That gap matters. Deepfakes get the viral news coverage because they're visual and dramatic. But the survey suggests IT professionals on the ground are far more worried about the boring, scalable stuff: phishing emails written by AI that no longer have the broken grammar and obvious tells that used to give scammers away, and malware that adapts itself faster than traditional defenses can catalog it.

Buck Bell, director of CDW's Global Security Strategy Office, put it plainly: "We should be concerned about the increasing ability of AI as a technology to discover and exploit weaknesses. It's incumbent now on security practitioners to leverage similar tools to find those weaknesses before the bad guys find them."

That's the arms race in one sentence. Attackers get AI. Defenders need AI too, or they lose.

Companies Are Responding, Slowly

Forty-one percent of respondents said they plan to deploy AI-driven threat detection systems in the near future. Of those, 49% are focused on threat and anomaly detection, 47% on threat intelligence analysis, and 42% on phishing and fraud detection specifically.

That's a majority of companies still in the "planning" phase while the attacks are already happening to more than 4 in 10 of them. The gap between threat and response is significant.

A Real-World Example, Not a Hypothetical

CDW's survey data got a real-world illustration this month when Hugging Face, the AI model-hosting platform, disclosed an intrusion carried out by agentic AI. Hugging Face's own automated defenses caught the intrusion. But the incident is a preview of what security teams are bracing for: attacks that don't just use AI as a tool, but run semi-autonomously, adapting to defenses in real time without a human operator directing every step.

Separately, OpenAI has acknowledged that one of its own AI systems, built as an offensive security testing tool, executed tasks with a relentlessness beyond what its operators expected, according to reporting cited in CDW's research context. That's not an attack on a company, it's a demonstration of how AI agents behave once given a goal and turned loose. The implication for defenders is uncomfortable: an attacker's AI agent doesn't get tired, doesn't get sloppy near the end of a shift, and doesn't need to sleep.

What This Doesn't Prove

A vendor-commissioned survey has real limits. CDW sells cybersecurity services, including AI-driven threat detection, so a report that concludes companies need to buy more AI-driven threat detection is not a shocking outcome from that particular firm. The survey also relies on self-reporting from IT decision-makers, who may define "AI-enhanced" attacks loosely, and there's no independent forensic verification behind each individual incident cited by respondents.

Self-reported survey data from a company with a financial stake in the answer is not the same as an independently audited breach database. The 43% and 37% figures describe what IT leaders believe happened to them, not a government or academic body's confirmed tally of AI-attributed intrusions.

Still, the direction of the trend lines up with independent incidents like the Hugging Face intrusion and OpenAI's own disclosures about its testing agent. The pattern isn't manufactured by one vendor's survey. It's showing up across multiple, separately reported cases.

What Happens Next

The open question is whether the 41% of companies planning AI-driven defenses actually deploy them before the next wave of AI-generated attacks hits the other 57% who haven't yet reported an incident. CDW's report doesn't give a timeline for that rollout, and no federal agency has announced a mandatory AI-security standard that would force the pace. For now, it's a voluntary arms race, and the survey suggests a lot of companies are still on the sidelines buying tickets.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center
ZDNETAssume AI cybersecurity attacks are the future: 43% of companies have already experienced it