Proofpoint study: AI is making ransomware more effective for 62% of Indian organisations
Artificial intelligence (AI) is increasing the effectiveness of ransomware attacks in India by making phishing, impersonation and credential theft campaigns more convincing, according to Proofpoint’s 2026 AI-Era Ransomware Report.
The global study found that 62% of Indian organisations that experienced ransomware incidents said AI made the attacks more effective, highlighting how cybercriminals are increasingly exploiting people rather than technical vulnerabilities. The findings are based on a survey of 953 cybersecurity professionals across 12 countries, conducted between March and April 2026.
Phishing and human error drive most attacks
The report found that ransomware campaigns continue to rely heavily on social engineering.
Among Indian respondents:
- 42% said ransomware attacks began through phishing emails or other email-based social engineering
- 71% identified malicious links as the most common initial threat
- 53% cited malicious attachments
- 47% pointed to Business Email Compromise (BEC)
The study also found that 49% of organisations attributed successful attacks to employees interacting with malicious content, while 42% said employees trusted attacks because they appeared authentic. According to Proofpoint, AI-generated content is making fraudulent communications increasingly difficult for users to distinguish from legitimate business messages.
“AI hasn’t fundamentally changed ransomware, but it has materially improved the attacks that lead to ransomware,” said Ryan Kalember, Chief Strategy Officer, Proofpoint.
“Today’s attackers are using AI to create highly convincing phishing emails, malware components like scripts, and credential theft campaigns that exploit human trust at scale. Organisations that continue treating ransomware and data extortion as endpoint or recovery problems are missing what these attacks most frequently begin with: people, identities and trusted communications.”
Data theft and repeat extortion become more common
The report suggests ransomware has evolved beyond encrypting systems to include data theft and repeated extortion.
Among Indian organisations affected by ransomware:
- 71% reported that data was stolen during the attack
- 64% paid a ransom
- Of those that paid, 48% received additional ransom demands
Proofpoint says this reflects a broader shift towards attacks that combine encryption with data exfiltration, allowing threat actors to apply continued pressure through the threat of public disclosure or additional attacks.
India also recorded one of the highest rates globally of users interacting with malicious content, alongside Japan and Singapore.
“India recording the highest user-interaction bypass rate in this ransomware study is sending a clear message to the industry,” said Bikramdeep Singh, India Country Manager, Proofpoint.
“When employees are the reason an attack gets through more often than anywhere else, it confirms that ransomware succeeds by exploiting people’s trust, not just systems. As AI makes these interactions harder to distinguish from legitimate business communication, human-centric cybersecurity is critical. It’s the only proactive defence that actually addresses where these attacks begin.”
The report concludes that organisations need to complement endpoint protection and recovery strategies with stronger identity protection, phishing defence and employee awareness, as AI-enabled social engineering continues to reshape the ransomware landscape.