The widespread adoption of artificial intelligence (AI) in the workplace is apparently being exploited by irresponsible parties to launch cybercrime activities. According to the latest report from Kaspersky, there were more than 33,300 attack attempts disguised as popular AI software during the first four months of 2026. This figure reflects a sharp surge of up to five times compared to the same period in the previous year.
In Southeast Asia, this threat is felt more intensely, with more than 1,800 recorded attacks, representing an increase of nearly sevenfold compared to 2025. Hackers leverage the popularity of AI services such as ChatGPT, DeepSeek, and Claude as bait to trick users into downloading malicious files embedded with Trojans.
The methods used by the perpetrators are quite systematic; they create installation files that appear legitimate and harmless. However, once the software is installed, the malware works silently to steal, damage, or hold corporate critical data hostage. In addition to AI services, hackers also actively impersonate popular office applications such as Telegram, WhatsApp, Zoom, and Microsoft Teams.
Adrian Hia, Managing Director of Kaspersky for Asia Pacific, emphasized that the SME sector is the primary target because it comprises over 90 percent of businesses in this region. Limited IT resources often make SMEs easy targets, highlighting the need for stricter preventive measures in facing the continuously evolving digital threats.
Experts advise business operators not to download pirated software, to always verify website addresses, and to avoid clicking links from unknown sources. Additionally, regular cybersecurity training for employees and periodic data backups are key to minimizing the risk of data loss due to cyberattacks that are becoming increasingly difficult to detect.