Even the Best IT Expert Will Click the Wrong Link Eventually Jana Juzová 16. 7. 2026

Even the Best IT Expert Will Click the Wrong Link Eventually

orez security brunch

Today’s cyberattack techniques are so sophisticated that successfully protecting an organization no longer rests solely on a strong firewall or the technical components of critical infrastructure. Cybersecurity also relies on informed colleagues who are not afraid to speak openly, share risks, and flag mistakes in time.

This was one of the takeaways from our latest Monet+ Security Brunch, organized in cooperation with Gen on the topic of Cybersecurity in the Financial Sector.

_DSF9870
How Generative AI Is Changing the Rules of the Game in Cybercrime

Michael Salát, Threat Intelligence Director at Gen, accepted our invitation to the Security Brunch. In his talk, based on the current “Consumer Threat Landscape” analysis, he demonstrated in detail how attackers are dramatically increasing the sophistication, speed, and success rate of their methods through the massive use of artificial intelligence.

The most significant phenomena of today include:

  • The rise of AI in phishing (Vibe Scams and Promptmorphism)
    While building convincing fraudulent websites once required experienced developers, today a single text instruction (prompt) for AI is enough to create a perfect replica of a banking interface. AI also generates polymorphic malware ( promptmorphism) that changes its own code faster than traditional signature-based detection can identify it.

  • Ad fraud (The Scam Ad Machine)
    Fraudulent ads are massively flooding social networks. Analyses show that on selected platforms, up to 1 in 3 ads is fraudulent (31% of 14.57 million analyzed samples). These campaigns abuse the logos of real brands and deliver up to 41% of all cyberattacks through malvertising.

  • Deepfakes and synthetic identities
    Attackers generate indistinguishable voice and face forgeries for targeted vishing and investment scams. In the area of KYC (Know Your Customer), fraudsters also use AI to generate complete fake identity documents and selfie photos of people who never existed (so-called synthetic identities), which standard verification processes often fail to detect.

  • Fake Captcha verification (ClickFix) and AI Agent Hijacking
    New techniques manipulate users into unknowingly executing malicious code from the clipboard under the pretext of identity verification. Moreover, if users rely on AI assistants connected to banking APIs, attackers can embed hidden instructions in web content that the assistant then executes without the user’s knowledge – for example, transferring funds.

  • Sophisticated abuse of legitimate platforms
    From WhatsApp Ghost Pairing attacks (silently linking an attacker’s device via a QR code) to Reservation Hijack Scams (e.g., on Booking.com), where attackers take over hotel staff accounts and message guests directly from a legitimate internal system, making the fraudulent payment link appear completely trustworthy.From WhatsApp Ghost Pairing attacks (silently linking an attacker’s device via a QR code) to Reservation Hijack Scams (e.g., on Booking.com), where attackers take over hotel staff accounts and message guests directly from a legitimate internal system, making the fraudulent payment link appear completely trustworthy.


_DSF0279
A Fourfold Increase in Attacks

That technical security alone is not enough was confirmed by representatives of the insurance company Kooperativa – Zdeněk Adamec (Chief Security Officer) and Petr Hejda (Chief Information Security Officer). Data from their Security Operations Center (SOC) show that the volume of automated and AI-driven attacks is growing radically.

Indicator2025 statistics
Total number of incidents23,406 /more than a fourfold increase compared to 2024
Average monthly volume1,950 investigated events
Monthly e-mail throughput3.4 million of which 232,800 spam and 5,700 malware
_DSF0103

An interesting finding is that the employee error rate (click rate in controlled phishing tests) remains stable at relatively high levels. However, this increase or stagnation is not caused by a deteriorating security culture, but by the credibility of the attacks.

Generative tools create such precise personalized communication and voice imitations that spotting phishing with the naked eye is nearly impossible today. Attackers also deliberately abuse well-known brands (e.g., spearphishing campaigns disguised as legitimate Czech companies or fake insurance premium payment notices distributed from external servers).

Sooner or later, almost everyone will respond to a manipulative message or a sophisticated scam – regardless of their level of IT education.

If a culture of fear of punishment prevails in a company, employees will conceal their mistakes (e.g., clicking a suspicious link). This gives the attacker precious time (often hours or even days) to move unnoticed through the network, escalate privileges, and exfiltrate data. If, on the other hand, the culture is open and the employee reports the incident immediately, internal security teams can instantly isolate the affected device, revoke tokens, and stop the attack in its infancy.

_DSF9939
Mobile Security and Collective Defence: Talsec

As part of the Security Brunch, Talsec presented an innovative approach to comprehensive mobile security. Their solution combines active application protection (RASP SDK), real-time device risk assessment (Device Risk Intelligence), and advanced cryptographic verification of application integrity against the backend (AppiCrypt®).

The key idea is the concept of Collective Defence – the rapid sharing of information about new threats and malware (e.g., SMS stealers or banking trojans) among participating financial institutions and eGov entities within local Threat Intelligence Hubs.

_DSF9781
Scroll to Top