How AI Is Being Used to Attack UK Businesses
- July 8, 2026
- Posted by: Gradeon
- Categories: Compliance, Cyber Security

AI is now being actively used by cyber attackers to scale attacks, personalise phishing, adapt ransomware in real time, and lower the cost of sophisticated cyber crime to around £65 per attack attempt. The UK’s National Cyber Security Centre confirmed in March 2026 that the best AI models completed nearly six times more steps in a simulated enterprise attack than 18 months earlier. For UK businesses, this is not a future threat. It is happening now.
What Has Actually Changed Since 2025?
The NCSC’s assessment is direct: AI has moved from theoretical concern to operational reality faster than almost anyone predicted.
Two specific trends define the shift.
First, capability is accelerating. Each new generation of AI model is better at working through complex attack sequences than the last. The best model in early 2026 completed nearly six times more attack steps than the best model 18 months earlier.
Second, cost is collapsing. At current pricing, a full attempt at a simulated enterprise attack costs around £65. This means the limiting factor for attackers is increasingly funding, not expertise.
The result is a threat environment that is categorically more dangerous than 2024, not incrementally so.
How Are Attackers Using AI Against UK Businesses Right Now?
AI-Generated Phishing at Industrial Scale
Hyper-personalised phishing is now the top AI-enabled threat concern, cited by 50% of security professionals in the State of AI Cybersecurity 2026 report.
Traditional phishing was relatively easy to spot: generic language, formatting errors, implausible pretexts. AI-generated phishing in 2026 is different.
Attackers feed publicly available information about a specific individual — their role, recent activity, known contacts, writing style — into AI models that generate messages indistinguishable from legitimate correspondence. That work, which once required a skilled social engineer, now takes seconds and can be personalised to thousands of targets simultaneously.
The attack arrives across email, SMS, voice calls, and messaging platforms in coordinated sequences, not as a single suspicious email that a trained eye might catch.
Deepfake Voice and Video Fraud
In February 2026, a Birmingham engineering firm lost £340,000 after a call that perfectly replicated their managing director’s voice and speech patterns.
Deepfake audio fraud targeting UK businesses has moved from proof-of-concept to operational attack. Attackers clone the voice of a CEO, CFO, or senior partner using as little as 30 seconds of audio from a public video, earnings call, or podcast appearance, then call the finance team authorising an urgent payment transfer.
Approximately £100 million was lost to investment scams driven by deepfake videos in the first half of 2025. The same technology is now targeting B2B payment authorisation directly.
AI-Adaptive Ransomware
Unlike traditional ransomware following predetermined paths, AI-enhanced variants analyse infiltrated networks, identify the most valuable data, prioritise high-impact targets, and modify their approach to evade detection systems in real time.
These strains detect sandbox analysis and alter their behaviour accordingly. They disable backup systems before encrypting files. Some even assess the target’s perceived financial capacity using publicly available data before setting the ransom demand.
The NCSC has consistently confirmed that ransomware remains the most acute cyber threat facing UK organisations, with AI accelerating both the reach and impact of campaigns.
Automated Vulnerability Exploitation
AI will almost certainly further reduce the time between vulnerabilities being disclosed and being exploited by malicious actors. The window between a patch being released and attackers exploiting the underlying vulnerability has already shrunk to days. AI narrows it further.
IBM X-Force observed a 44% year-over-year increase in the exploitation of public-facing applications — meaning attackers are finding and exploiting externally accessible vulnerabilities at a pace that most organisations’ patching cycles cannot match.
AI-Powered Reconnaissance
Before launching any attack, threat actors now use AI to conduct reconnaissance at scale. AI tools scrape LinkedIn, Companies House, social media, job listings, and press releases to build detailed profiles of target organisations — identifying key personnel, technology vendors, payment processes, and supply chain relationships.
This reconnaissance, which previously took skilled analysts days or weeks, now takes minutes. The result is more precisely targeted attacks with higher success rates against both technical and human vulnerabilities.
Who Is Being Targeted?
The assumption that AI-driven attacks target only large enterprises is demonstrably wrong.
AI enables attackers to scan and target thousands of businesses automatically, often focusing on organisations that lack robust cyber security protections. SMEs are disproportionately attractive because they frequently lack dedicated security teams, run legacy systems, and serve as entry points into larger supply chains.
Research from the Federation of Small Businesses reveals that 43% of UK SMEs experienced a cyber attack in the past year, yet only 14% feel confident handling an AI-powered threat.
The NCSC CEO confirmed in June 2026 that more than 200 cyber incidents affecting the UK’s critical national infrastructure and its supporting ecosystem were managed by the NCSC in the year to May 2026, with around 75% of those believed to be linked to state actors. State-level threats, previously reserved for critical infrastructure, increasingly cascade into commercial supply chains through less-protected SME suppliers.
What Makes AI-Powered Attacks Harder to Defend Against?
Three specific factors make the current threat environment harder to manage than previous generations of cyber attack.
Speed. AI attacks operate faster than human-led incident response. By the time an alert is reviewed, an AI-driven attack may have already moved laterally, identified high-value targets, and begun exfiltration.
Personalisation. Generic security awareness training teaches staff to spot generic phishing. AI-personalised attacks are specifically designed to defeat that training by mimicking real people, real scenarios, and real writing styles.
Cost asymmetry. Defending against AI-driven attacks requires continuous investment in monitoring, detection, and training. Launching them costs around £65. That asymmetry is not going to reverse.
What Should UK Businesses Do Now?
The UK government’s open letter to business leaders in April 2026 made the ask direct: treat cyber risk as a board agenda item and act on the NCSC’s published guidance.
Why the UK government is urging boards to treat AI-driven cyber risk as a standing leadership responsibility comes down to this: the decisions that determine whether a business is resilient to AI-powered attacks are leadership decisions about investment, governance, and culture — not IT configuration choices.
Practically, the NCSC recommends five immediate actions for UK businesses facing AI-powered threats:
- Enable multi-factor authentication on all accounts and cloud services
- Implement a rigorous patching programme, prioritising internet-facing systems
- Establish voice and payment verification procedures that cannot be bypassed by a phone call alone
- Deploy continuous monitoring rather than periodic scanning
- Train staff specifically on AI-generated phishing and deepfake fraud, not generic phishing awareness
The generative AI threats UK CISOs must already be planning defences against extend beyond technical controls. Governance, board reporting, and incident response capability are the differentiators between organisations that contain AI-driven attacks quickly and those that do not.
The practical steps UK businesses should be taking now against AI-driven threats are covered in our 2026 cyber threat landscape guide. which sets out a control-by-control review of where most UK businesses currently have gaps relative to the current threat environment.
Frequently Asked Questions
How is AI being used to attack UK businesses?
Attackers use AI for hyper-personalised phishing, deepfake voice fraud, adaptive ransomware, automated vulnerability exploitation, and large-scale reconnaissance. All are active threats against UK businesses in 2026.
How much does it cost attackers to use AI against a UK business?
The NCSC confirmed a full simulated enterprise attack attempt costs around £65 at current AI pricing, making sophisticated attacks accessible to low-skilled criminals.
Are UK SMEs being targeted by AI-powered cyber attacks?
Yes. AI enables attackers to target thousands of organisations simultaneously, and SMEs are frequently targeted as supply chain entry points into larger organisations.
What did the UK government say about AI cyber threats in 2026?
In April 2026, the government wrote directly to business leaders confirming AI-powered attacks had surged and urging boards to treat cyber risk as a standing agenda item.
Can traditional security tools defend against AI-powered attacks?
Not reliably. AI-generated phishing defeats signature-based filters. Deepfake calls bypass standard verification. Adaptive ransomware evades sandbox detection. Layered controls and continuous monitoring are required.
What is the NCSC’s guidance on AI cyber threats for UK businesses?
The NCSC recommends MFA on all accounts, rapid patching of internet-facing systems, continuous monitoring, staff training on AI-specific threats, and following the Cyber Assessment Framework.
Sources: NCSC, “Why Cyber Defenders Need to Be Ready for Frontier AI,” March 2026. NCSC CEO speech at RUSI Annual Security Lecture, June 2026. UK Government Open Letter to Business Leaders on AI Cyber Threats, April 2026. IBM X-Force Threat Intelligence Index 2026. Federation of Small Businesses UK Cyber Survey 2025/2026.