Posted on Leave a comment

AI phishing is turning trust into APAC cybersecurity’s weakest link

For years, cybersecurity teams have told employees to look for the usual clues: awkward grammar, strange email addresses, urgent requests, and links that do not quite look right. Generative AI is making that advice less reliable.

A new Mimecast study suggests that many organisations in Asia Pacific now expect attackers to use AI against them, yet a large number still have not adjusted their defences to match the threat.

According to the company’s “State of Human Risk 2026” study, 65 per cent of surveyed IT and security decision-makers believe an AI-enabled attack against their organisation is inevitable within the next 12 months.

Also Read: GoSerpent exposes the quiet cyber war against Southeast Asian governments

The APAC findings are based on responses from 500 IT security and IT decision-makers in Singapore and Australia, drawn from a broader global survey of 2,500 respondents across nine markets. All organisations surveyed had more than 250 employees and more than 250 email users, spanning sectors including financial services, healthcare, technology, manufacturing, retail, energy, public services, construction and media.

The headline number is striking, but the more important finding may be this: 60 per cent of APAC respondents said their organisation was not fully prepared to deal with AI-driven threats that exploit human vulnerabilities. In other words, many companies can see the risk coming, but their playbooks are still catching up.

The new face of social engineering

Social engineering attacks are not new. Fraudsters have long pretended to be bosses, suppliers, banks, government agencies or colleagues to trick employees into revealing credentials, approving payments or sharing sensitive data.

What AI changes is the quality and scale of deception.

Attackers can now use generative AI tools to write polished emails, imitate a company’s tone, translate messages into local languages, personalise scams using scraped public information, and produce convincing voice or video impersonations. For businesses in Southeast Asia, where cross-border teams often work across English, Mandarin, Bahasa Indonesia, Vietnamese, Thai and other languages, this matters. Poor language used to be one of the easiest warning signs of a scam. That signal is becoming weaker.

“AI is changing the way cybercriminals manipulate trust,” said Nicky Choo, Vice President and General Manager, APAC, Mimecast. “Attackers can now use it to create convincing, tailored messages that appear to come from a colleague, a partner or a senior leader.”

Also Read: Southeast Asian SMEs remain soft targets as ransomware groups refine extortion tactics

That is particularly relevant in regional markets where startups, SMEs and large enterprises alike rely heavily on fast-moving digital communication. A procurement request may arrive by email, be clarified on a messaging app, approved through a cloud workflow, and paid through a banking portal. Each handoff creates a moment where an employee has to decide whether the person on the other side is genuine.

Mimecast’s study found that 79 per cent of respondents were concerned about AI being used as an attack vector against their organisation. Two-thirds, or 66 per cent, agreed that an employee in their organisation was very likely to be fooled by a cybercriminal using AI as part of a social engineering attack.

That finding points to a difficult reality for security leaders: the weak point is not simply technology. It is judgement under pressure.

Training has not caught up

The study found that AI-specific employee preparation remains limited. Only 40 per cent of surveyed APAC organisations provide training on how to use AI while avoiding exploitation, while 42 per cent conduct simulated AI-driven phishing attacks.

This does not mean employees are receiving no cybersecurity training at all. Many companies already run phishing awareness programmes, password hygiene sessions or compliance modules. The gap is that traditional training may not prepare workers for scams that sound natural, reference real business context, and arrive through channels they use every day.

“Employees should not be expected to identify increasingly sophisticated deception on instinct alone,” Choo said. “Fewer than half are training staff on how to avoid AI-driven exploitation or running simulated AI phishing exercises.”

For Southeast Asian companies, this gap could widen as AI adoption accelerates inside the workplace. Employees are experimenting with AI assistants for writing, coding, customer support, research and translation. At the same time, attackers are using similar tools to improve fraud. That creates a messy middle ground where legitimate AI use and malicious AI use can look increasingly similar.

Also Read: Thailand is suddenly on the frontline of a new ransomware wave

A finance employee may receive a payment request written in the exact style of a senior executive. A customer support agent may be sent a forged document that looks credible. A founder may hear what sounds like an investor or board member on a voice call. The problem is not that workers are careless. It is that the cost of verifying trust has gone up.

Why APAC firms face a sharper test

APAC’s exposure is not uniform, but several regional factors make the issue more pressing. Singapore and Australia, the two markets covered in the APAC sample, are both highly digitised economies with mature financial and enterprise technology sectors. They are also hubs for regional business activity, meaning employees frequently deal with overseas vendors, remote teams and cross-border customers.

In Southeast Asia, the challenge is compounded by uneven cyber maturity. Large banks, telcos and technology firms may have advanced controls, while smaller companies in their supply chains often operate with lean security teams. Startups can be especially vulnerable because they prize speed, informality and rapid decision-making, the same conditions that social engineers exploit.

A young company may not have layered approval systems for payments or data access. A fast-scaling regional business may onboard new staff and vendors faster than it updates security processes. In such environments, a convincing AI-generated message does not need to defeat sophisticated infrastructure; it only needs to land at the right moment.

The growing use of collaboration tools also expands the attack surface. Email remains central, but work now happens across Slack, Teams, WhatsApp, Telegram, shared documents and customer platforms. If security awareness is still built mainly around spotting suspicious emails, organisations may miss deception that begins elsewhere.

From blocking threats to building judgement

Mimecast argues that organisations need to treat human judgement as a core part of cyber defence, not merely as the last line of protection when technical filters fail. That means pairing security tools with practical training, realistic simulations and clearer verification processes.

For example, companies can require out-of-band confirmation for payment changes, create simple escalation paths for suspicious requests, and train staff on AI-specific red flags such as synthetic voice calls, overly personalised messages or unusual urgency framed in familiar language. Security teams can also run simulations that reflect how employees actually work, rather than relying only on generic phishing tests.

The broader lesson is that AI-enabled cyber risk is not just a technical problem to be solved by buying another tool. It is an organisational problem involving culture, process and incentives. Employees need permission to slow down, question authority and verify unusual requests without fearing that they are blocking business.

Also Read: From fraud fighters to zero-trust builders: SEA’s cyber stars

The Mimecast study is a warning, but not an unexpected one. As AI lowers the cost of producing convincing deception, the old assumption that scams are easy to spot will become increasingly dangerous. For APAC organisations, the next phase of cybersecurity may depend less on whether employees can catch every fake, and more on whether companies design systems that do not leave them to make those calls alone.

The post AI phishing is turning trust into APAC cybersecurity’s weakest link appeared first on e27.

Leave a Reply

Your email address will not be published. Required fields are marked *