Check Point Research Reveals Gen AI Adoption Leaks Sensitive Information
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
Check Point Research’s December 2025 Global Cyber Attack Statistics report reveals alarming trends regarding the security risks associated with Generative AI adoption. Organizations worldwide experienced an unprecedented volume of cyber threats, averaging 2,027 attacks weekly, which is a 9% increase from 2024. The United States and the United Kingdom were particularly affected, with over 1,440 organizations attacked weekly, marking a significant 39% rise in incidents compared to the previous year.
The report emphasizes that while ransomware remains a dominant threat, the integration of Generative AI tools has introduced new vulnerabilities. Sensitive corporate data is often input into AI systems without proper security controls, increasing the risk of leaks and exploitation by cybercriminals. This lack of governance and oversight is particularly concerning for sectors like government, education, and non-profits, which are already struggling with outdated infrastructure and insufficient cybersecurity expertise.
Among the most active ransomware groups identified in 2025, the Qilin ransomware gang, believed to be operating from Russia, was the most aggressive, followed by LockBit5 and Akira. These groups primarily targeted Windows-based systems and increasingly Linux infrastructures, showcasing the evolving capabilities of attackers.
The findings underscore the urgent need for organizations to implement stronger AI governance frameworks, modernize legacy systems, and invest in cybersecurity talent. As the threat landscape continues to evolve with the adoption of AI technologies, businesses must prioritize the protection of sensitive information to mitigate risks.
Implications for Organizations
Organizations must recognize that the rapid adoption of AI tools can inadvertently expose them to significant risks. The increase in cyber attacks indicates a growing attack surface, driven by digital transformation and cloud adoption. Companies should evaluate their data handling practices, especially regarding how sensitive information is utilized in AI systems.
Furthermore, the identification of specific ransomware groups highlights the need for organizations to enhance their defenses against such threats. Regularly updating security protocols and investing in cybersecurity training for employees can help mitigate the risks associated with these evolving threats.
Ultimately, the report serves as a wake-up call for enterprises to reassess their cybersecurity strategies in light of the growing reliance on AI technologies. By adopting comprehensive security measures and fostering a culture of cybersecurity awareness, organizations can better protect themselves against the increasing tide of cyber threats.
Key Takeaways
- Review and update data handling practices to ensure sensitive information is not exposed when using AI tools.
- Implement stronger governance frameworks around AI adoption to mitigate risks associated with data leaks.
- Invest in modernizing legacy systems to enhance overall cybersecurity posture.
- Provide cybersecurity training for employees to raise awareness of potential threats and safe practices.
- Regularly monitor and update security protocols to defend against evolving ransomware threats.
Key Terms & Concepts
- Generative AI: In this article, Generative AI refers to tools that create content or data based on input, which can inadvertently expose sensitive information.
- Ransomware: Ransomware is a type of malicious software that encrypts a victim’s data, demanding payment for its release.
- Qilin ransomware gang: The Qilin ransomware gang is identified as the most aggressive group in 2025, believed to operate from Russia.
- LockBit5: LockBit5 is ranked as the second most active ransomware group targeting organizations in 2025.
- Akira: Akira is recognized as the third most active ransomware group in 2025, focusing on various systems.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.