Artificial intelligence is accelerating cyberattacks and changing their nature — the time needed to prepare malicious code may shrink to just a few minutes, while phishing already accounts for more than 47% of all incidents, according to a report by CERT Orange Polska. The largest share of scams consists of fake investment schemes, which make up nearly 70% of cases.
“The key cybersecurity trends in 2026 and the coming years are definitely related to artificial intelligence. We can see its impact in a great many attacks, but also in defense systems. Those defenses and the techniques we use must match what our adversaries are doing — time, speed of action, streamlining those attacks, and responding to them, often with the support of artificial intelligence, are what matter most,” Robert Grabowski, Head of CERT Orange Polska, said in an interview with Newseria.
In 2025, Orange’s CyberShield blocked 345,000 phishing domains and protected almost 5.5 million people from losing data or money. At the same time, phishing remains the main attack vector, accounting for more than 47% of all incidents, clearly ahead of DDoS attacks at nearly 16% and malware at more than 13%.
The scale of threats is growing, although their structure has remained broadly similar for several years. What is changing is the way attacks are carried out — they are becoming increasingly automated, scalable, and based on ready-made tools. It is estimated that as many as 90% of phishing campaigns rely on the same schemes and pre-prepared templates, which are replicated and modified on a massive scale. Domains used in attacks are generated automatically and deployed widely, often only for a short period of time, making them harder to detect and block quickly. Special applications for sending phishing text messages are also being used more frequently, further increasing the speed and reach of campaigns.
Phishing is no longer simply about persuading a user to click on a link. More and more often, it has become a complex ecosystem involving fake websites, advertisements, communications, and technical infrastructure, all designed to imitate trustworthy services as closely as possible and maximize the effectiveness of the attack.
“We are seeing a very significant impact of artificial intelligence on what is known as the weaponization of vulnerabilities — in other words, preparing malicious code that can exploit them. Right now, these exploits are created within 24 hours, but we expect that in the coming years this timeframe could shrink to just a few minutes,” Robert Grabowski said.
Automation is also changing the structure of fraud itself. Fake investments now make up the largest category of phishing, accounting for nearly 70% of all cases, compared with just 28% two years earlier. This category is dominated by fake trading platforms and services promising quick profits without risk, distributed mainly through social media and the largest advertising networks.
According to the report, more than 72% of users who landed on phishing websites were lured in through investment-related scenarios. In practice, this means that the scale of these scams is driven primarily by the mass distribution of content on social platforms and by the use of unsuspecting users as channels for further dissemination.
“The market for fake ads and the distribution of malicious content through them in social media and major advertising networks remains strong. At the same time, advanced APT groups and their sophisticated techniques influence the methods used by widely distributed malware. APT refers to the most advanced attacks carried out by groups, often state-sponsored, targeting the most critical sectors and companies. They often exploit so-called zero-day vulnerabilities,” the Head of CERT Orange Polska explained.
Changes are also visible in the nature of DDoS attacks. Although short incidents lasting less than 10 minutes and of relatively low intensity still dominate, their operational importance is growing. More and more often, they form part of broader campaigns — supporting disinformation efforts, extortion attempts, or serving as a distraction from parallel operations. In 2025, Orange’s network recorded attacks of record-breaking strength, reaching as much as 1.5 Tb/s.
The year 2025 also saw the rise of multi-million-node botnets, enabling attacks on a scale not seen before. One example is bot networks such as Aisuru, which are used to carry out very large, coordinated DDoS attacks.
DDoS attacks are no longer isolated one-off incidents; they are becoming tools used in complex operational scenarios. The platformization of these services means they are easily accessible and can be planned with precision, fundamentally changing their role in the threat ecosystem.
“Technology helps both defenders and attackers, who use it without any ethical or moral constraints, particularly artificial intelligence, whereas we operate within imposed ethical boundaries. It is a double-edged sword. We need to study how attacks using artificial intelligence have changed, what impact it has on malware and on generated code. At the same time, we must keep updating our detection systems,” Robert Grabowski argued.
The growing scale of threats is driving the development of protective tools operating at the network level. A key solution remains Orange CyberShield, which blocks traffic to malicious domains before it reaches the user, limiting the effects of attacks regardless of the user’s reaction.
“When users try to visit malicious sites or phishing pages, or when malware attempts to contact the botmaster or the C2 server controlling it or the botnet, that traffic is stopped within the Orange Polska network. Either the traffic never gets through, or the user is informed that they have just attempted to visit a malicious site, which also has an added educational value,” the Head of CERT Orange Polska pointed out.
Cybercriminals are increasingly using tools that make it possible to create credible messages and fake websites on a massive scale, which means that the user and their awareness of threats remain a crucial part of the security system. Continuous threat monitoring and hunting, as well as preparing incident response scenarios, are no longer precautionary measures taken “just in case” — they are becoming a necessity.
CERT Orange Polska is also developing tools that allow users to monitor data leaks and gain greater control over their digital identity. More than 40,000 users are already using the Password Alert solution. The tool analyzes leak databases containing billions of records and enables users to quickly check whether their login credentials have been exposed.
“This year we also launched a new form on the cert.orange.pl website where users can verify whether a domain is malicious. So before someone visits it, they can enter the address and receive information on whether the site is blocked. We will certainly continue to expand this mechanism with new forms of detection,” Robert Grabowski announced.





