
Artificial intelligence changes cybersecurity in two directions at once. It is improving defenders’ ability to analyze large volumes of security data, automate investigations and accelerate response, while also giving attackers faster and more scalable methods for reconnaissance, social engineering, identity abuse, content generation and campaign coordination. The result is a cyber environment in which the speed of attack development increasingly challenges security programs built around periodic assessments and reactive controls.
For organizations operating in Thailand, this shift is particularly relevant because digital banking, e-commerce, cloud adoption, mobile services, connected supply chains and increasingly digital public and private-sector operations expand the number of externally exposed assets and identities that attackers can target. AI does not necessarily create entirely new attack categories; rather, it reduces the cost and time required to execute existing attacks and makes them easier to personalize and scale.
This report sets out CYFIRMA’s assessment of that landscape, showing how AI is changing attacker behavior and the economics behind it. Reconnaissance, lure-crafting, exploit chaining, and infrastructure setup tasks that once required time, skill, and manual coordination can now be generated, tested, and deployed by machines with limited human involvement.

The report focuses on the implications of AI-enabled cyber threats for organizations in Thailand, including financial services, government, telecommunications, technology, manufacturing, retail, healthcare, logistics, and critical infrastructure. It does not attempt to provide a statistical ranking of Thai cyber incidents. Instead, it uses a strategic threat-landscape approach to explain how AI changes attacker capability and what organizations can do to reduce exposure.
The CYFIRMA solution discussion is derived from the supplied reference content describing External Threat Landscape Management (ETLM), its nine intelligence pillars, continuous outside-in visibility, AI-driven predictive intelligence, closed-loop automated response, and the stated illustrative outcome. Additional report content has been written originally for this Thailand-focused report.
Thailand’s digital economy creates a broad and increasingly interconnected cyber environment. Organizations depend on online customer channels, digital payments, cloud infrastructure, mobile applications, third-party technology providers and cross-border business ecosystems. These dependencies create value for legitimate users, but they also increase the number of assets, identities and relationships that can be exploited.
In the AI era, the risk equation changes because attackers can use automation to conduct research, generate convincing messages, adapt language to the target, test multiple attack approaches and scale campaigns. In Thailand, this may include campaigns designed around local language and cultural context, impersonation of executives or trusted brands, fraud targeting digital financial services, and attacks against employees or suppliers who have access to corporate systems.
The strategic challenge is therefore not simply to protect the corporate network. Organizations must understand what is visible from the outside, which assets and identities are exposed, what adversaries are discussing or preparing, which third parties introduce risk, and which emerging signals indicate that an attack may be moving toward execution.
| Threat area | How AI changes the threat | Potential organizational impact |
| AI-enhanced phishing and social engineering | Messages can be generated rapidly, personalized to roles and written with fewer obvious language errors. | Credential theft, malware delivery, payment fraud and account compromise. |
| Deepfakes and synthetic identity | AI-generated voice, video and images can make impersonation more convincing. | Executive fraud, financial loss, fraudulent approvals and reputational damage. |
| Credential attacks | Automation supports large-scale testing of leaked credentials and more targeted identity abuse. | Account takeover, privileged access and unauthorized transactions. |
| AI-assisted vulnerability exploitation | Attackers can accelerate reconnaissance and research around exposed technologies and known weaknesses. | Faster exploitation of internet-facing systems and reduced response windows. |
| Malware development and adaptation | AI can assist parts of the coding, debugging and adaptation process. | More varied campaigns and potentially faster modification of malicious tooling. |
| Brand and domain impersonation | AI makes it easier to create convincing websites, content and fake customer communications. | Fraud, customer compromise and loss of trust. |
| Shadow AI exposure | Employees may adopt external AI tools without central governance or security review. | Data leakage, uncontrolled processing of sensitive information and new attack paths. |
| Third-party and supply-chain compromise | Attackers can use automation to identify weak links across interconnected ecosystems. | Indirect compromise through suppliers, partners and service providers. |
TOP 10 ACTIVE RANSOMWARE IN THAILAND

Based on CYFIRMA’s own tracking of ransomware activity relating to Thailand over the period reviewed, and reflecting the intelligence available at the time of writing, Thailand’s ransomware threat landscape in 2026 was led by The Gentlemen (57 incidents), Qilin (37), LockBit 5 (18), Payload (16), Nova (15), Lamashtu (12), Krybit (9), IncRansom (9), APT73/Bashe (9), and DragonForce (6). The Gentlemen and Qilin together represent more than half of the incidents in the dataset, highlighting the growing importance of large ransomware ecosystems and Ransomware-as-a-Service (RaaS) operations. The current trend suggests that attackers are increasingly focusing on organizations with valuable data, exposed remote-access infrastructure, weak credentials, and critical business operations. Ransomware groups are also adopting double-extortion strategies, combining data theft with encryption to increase pressure on victims.
Looking ahead, AI is likely to make ransomware attacks more scalable, personalized, and difficult to detect. Attackers could use AI to create highly convincing phishing emails in local languages, automate reconnaissance, profile employees and organizations, analyze stolen data, and improve social-engineering campaigns. AI-assisted tools may also lower the technical barrier for less-skilled criminals, allowing them to conduct more sophisticated attacks using existing ransomware platforms. However, AI is more likely to act as a force multiplier for existing ransomware operations rather than completely replacing human attackers.
For Thailand, the most likely future scenario is an increase in AI-enhanced ransomware campaigns targeting critical infrastructure, healthcare, financial institutions, manufacturing, and government-related organizations. Organizations should therefore move beyond traditional antivirus-based defenses and strengthen identity security, multifactor authentication, offline backups, endpoint detection and response, vulnerability management, and employee awareness. Continuous monitoring for suspicious authentication activity and unusual data transfers will become increasingly important as ransomware groups combine established attack techniques with AI-driven automation.
INDUSTRY-WISE VICTIMS

Based on the same dataset, the industry distribution shows that ransomware activity in Thailand in 2026 was spread across a broad range of sectors, with Professional Goods & Services (32 incidents), Consumer Goods & Services (29), and Manufacturing (29) being the most targeted. These are followed by Information Technology (24), Materials (23), Transportation & Logistics (21), and Real Estate & Construction (20). The concentration in these sectors suggests that attackers are increasingly targeting organizations that combine valuable data, large digital footprints, interconnected supply chains, and high operational dependence on IT systems. Manufacturing and materials organizations are particularly attractive because a successful ransomware attack can disrupt physical production and supply chains, creating strong pressure to restore operations quickly. Similarly, professional services and consumer-facing organizations often hold large volumes of customer, financial, and business data that can be used for extortion.
The Finance (18), Government & Civic (15), Education (12), Healthcare (11), and Energy & Utilities (9) sectors represent another important risk category. Although their incident counts are lower, the potential impact of attacks against these sectors is significantly higher because they provide essential services and manage sensitive information. Healthcare organizations, for example, may face pressure to restore systems rapidly because disruptions can affect patient care, while government and energy organizations may be targeted for both financial and strategic reasons. Telecommunications & Media (4) has the lowest reported number among the named sectors, but this should not necessarily be interpreted as low risk because telecom infrastructure can provide attackers with valuable access to large networks and interconnected systems.
The broader trend indicates that ransomware is moving toward high-impact, sector-specific targeting rather than indiscriminate attacks. Attackers are likely to increasingly prioritize organizations where downtime has immediate financial or operational consequences. Over the next 12–24 months, AI could amplify this trend by helping attackers automate reconnaissance, identify high-value employees, create convincing phishing campaigns in Thai and English, and personalize social-engineering attacks. AI could also help criminals analyze stolen data to determine which information would create the greatest pressure during extortion.
As a result, the key future concern is not simply an increase in ransomware attacks, but the emergence of more targeted, faster, and highly personalized campaigns against Thailand’s manufacturing, professional services, technology, logistics, finance, healthcare, and critical infrastructure sectors.

Based on CYFIRMA’s monitoring of open-source and underground chatter over the period, the threat landscape shows a clear escalation in DDoS activity, credit-card-related chatter, and claimed hacks during the later months of the period. DDoS chatter increased sharply from 8 mentions in May to 83 in June and 99 in July, making it the most significant emerging trend. Credit-card chatter also rose substantially, reaching 66 in May, 55 in June, and 73 in July, suggesting increased attention around payment data, financial fraud, and potentially stolen card information. At the same time, claimed hacks increased from 1 in May to 32 in June before declining slightly to 19 in July. This could indicate a broader shift from traditional ransomware-focused activity toward disruptive attacks, data theft, and public claims of compromise. Ransomware chatter itself remained relatively stable, peaking at 19 in April and declining to 8 in June and 9 in July, suggesting that ransomware continues to be an important threat but is increasingly becoming part of a wider ecosystem of cyber extortion and disruption.
Industry Trends

From an industry perspective, Professional Goods & Services consistently generated some of the highest levels of cyber-threat chatter, rising sharply to 47 in July. Government & Civic organizations also experienced sustained attention, reaching 47 in June and 41 in July, making the government sector one of the most consistently targeted areas. A notable development is the surge in Telecommunications & Media, which increased from only 7 in May to 42 in June, followed by 21 in July. This coincides with the major increase in DDoS activity and may indicate that telecom and media organizations are becoming more exposed to disruption-oriented campaigns. Information Technology also experienced a significant increase, reaching 27 in July, while healthcare and education remained consistently active targets throughout the period.
Overall, the data suggests a changing threat environment in Thailand, with the second quarter and early third quarter showing a move toward large-scale disruption, DDoS campaigns, financial targeting, and publicized claims of compromise. The strongest emerging pattern is the convergence of different attack motivations: attackers may combine DDoS for disruption, data breaches and leaks for extortion, and credit-card theft for direct financial gain. The increase in activity against government, telecommunications, IT, healthcare, and professional services is particularly significant because these sectors are highly interconnected and can provide attackers with greater downstream impact.
Looking ahead, AI could accelerate these trends by enabling more automated reconnaissance, highly personalized phishing and social engineering, rapid analysis of stolen data, and scalable attack operations. The likely result is a threat environment where cybercriminals can identify high-value targets faster and conduct more sophisticated campaigns with fewer resources, increasing the need for organizations to strengthen identity security, DDoS resilience, data-loss prevention, and continuous threat monitoring.
Phishing has historically relied on volume, deception and human error. AI strengthens all three dimensions. Attackers can generate large numbers of messages, tailor them to specific individuals and rapidly modify campaigns when recipients or security systems respond.
For Thai organizations, the risk extends beyond conventional email phishing. Attackers may combine email, messaging platforms, social networks, phone calls and synthetic voice to create multi-stage impersonation campaigns. A victim may first receive a credible message, then a follow-up call or voice message that appears to confirm the request. This creates a blended social-engineering threat in which individual security controls may each appear to function, while the overall campaign remains effective.
The appropriate response is therefore broader than user awareness training alone. Organizations need visibility into exposed identities, leaked credentials, impersonation infrastructure, malicious domains, and emerging adversary activity.
Synthetic media introduces a new layer of uncertainty into trust-based business processes. A realistic voice or video can be used to impersonate an executive, customer, supplier, or government representative. The primary risk is not that every deepfake will be technically perfect; it is that the attacker only needs enough credibility to persuade a victim to take an action.
Organizations should strengthen verification procedures for high-value transactions and sensitive requests. Independent confirmation, separation of duties, out-of-band verification, and transaction controls become increasingly important as visual and audio evidence becomes easier to fabricate.
AI can reduce the effort required to research targets, understand technical environments, and produce or adapt attack content. This does not mean that AI automatically creates sophisticated malware without human expertise. The more important shift is operational: AI lets attackers perform supporting tasks faster, allowing smaller groups to operate with greater scale.
For defenders, there is a shorter window between exposure and exploitation. Internet-facing assets and vulnerabilities therefore need continuous monitoring and contextual prioritization. A vulnerability that appears moderate in isolation may become urgent when combined with evidence that an adversary is actively targeting the affected technology or organization.
AI-era campaigns increasingly depend on infrastructure and information outside the organization’s traditional security boundary. This includes leaked credentials, underground discussions, newly registered domains, phishing infrastructure, malicious applications and other signals that may appear before a successful attack.
The strategic value of external intelligence lies in its ability to correlate weak signals into actionable intelligence. A leaked credential, a newly registered look-alike domain, and an emerging discussion about a target may each appear insignificant when viewed separately. Correlation can reveal a campaign developing before the attacker reaches the intended victim.
The rapid adoption of generative AI creates a new category of external exposure. Employees may use AI services, browser extensions, plug-ins, and third-party applications without security teams having complete visibility. Sensitive information may be submitted to external services, while unmanaged applications can introduce authentication, configuration, or supply-chain risk.
A modern attack-surface program should therefore include not only conventional internet-facing infrastructure but also cloud resources, SaaS applications, exposed identities, shadow IT and shadow AI usage where discoverable. The objective is to maintain an up-to-date outside-in view of what an attacker can observe and potentially exploit.
Thailand’s highly connected business environment means that an organization’s cyber risk can extend into suppliers, technology partners, logistics providers, managed services, and other external relationships. AI-assisted reconnaissance can make it easier for attackers to identify weak points across these interconnected ecosystems.
Third-party risk management should therefore move beyond annual questionnaires. Organizations need ongoing visibility into external exposure, security changes, leaked credentials, suspicious infrastructure, and emerging threats affecting critical partners.
The rapid adoption of public generative AI services has introduced a new and increasingly difficult-to-monitor channel through which sensitive organizational data can leave the enterprise. Employees may routinely submit customer information, source code, contractual details, financial data, intellectual property, and internal strategy documents to external AI services to accelerate drafting, coding, analysis, translation, and other business activities.
Once sensitive information has been submitted, organizations may have limited visibility or control over how that data is processed, stored, retained, or subsequently accessed. Depending on the service and its configuration, submitted information may be logged, retained for a period, incorporated into service improvement processes, cached, or exposed through compromised accounts, insecure integrations, misconfigurations, or third-party security incidents. This creates a significant data protection challenge, as traditional security controls are often designed to monitor established corporate communication and data-transfer channels rather than open-ended interactions with external AI services.
The risk is particularly significant in environments where generative AI adoption has progressed faster than internal governance, policy, and security controls. As organizations increasingly incorporate AI into day-to-day workflows, they must address the possibility that sensitive information is being shared externally without appropriate authorization, oversight, or data classification.
The core challenge for security and risk teams is visibility. In many organizations, there is no reliable mechanism to determine which AI services employees are using, what types of information are being submitted, whether such usage complies with organizational policies, or where sensitive data may subsequently appear or be retained.
Addressing this emerging risk requires organizations to establish clear governance over generative AI usage, improve visibility into AI-related data flows, enforce appropriate data-handling policies, and implement controls that can identify and prevent the unauthorized disclosure of sensitive information through AI interactions. Without such measures, generative AI can become an unmanaged data-exfiltration pathway, creating material risks to confidentiality, regulatory compliance, intellectual property, and overall organizational security.
How CYFIRMA Helps
CYFIRMA’s ETLM platform addresses this exposure from the outside in, surfacing GenAI-related risk when it becomes externally visible, rather than inspecting what employees type in real time:
| Sector | Priority AI-era threats | Strategic focus |
| Banking and financial services | Credential attacks, deepfake fraud, phishing, brand impersonation | Identity protection, fraud controls, external threat intelligence, rapid takedown |
| Government and public services | Targeted phishing, impersonation, exposed infrastructure, influence operations | Continuous external visibility, threat monitoring and coordinated response |
| Telecommunications | Infrastructure targeting, credential compromise, supply-chain risk | Attack-surface intelligence, vulnerability prioritization and adversary tracking |
| Manufacturing | Third-party exposure, ransomware, exposed remote services | External asset discovery, supplier monitoring and vulnerability prioritization |
| Healthcare | Identity theft, ransomware, data exposure | Digital risk protection, credential monitoring and rapid incident response |
| Retail and e-commerce | Brand abuse, payment fraud, credential stuffing | Brand monitoring, identity protection and phishing takedown |
| Critical infrastructure | Targeted intrusion, supply-chain compromise, exposed operational assets | Continuous monitoring, predictive intelligence and high-confidence response |
The AI era increases the value of moving from a purely reactive security model toward predictive cyber resilience. Reactive controls remain necessary, but they operate after or during an event. Predictive security seeks to identify conditions that indicate an attack is becoming more likely.
CYFIRMA’s platform is positioned around External Threat Landscape Management (ETLM), a framework that brings multiple intelligence capabilities into a continuously updated view of an organization’s external risk. The objective is to connect external exposure and threat intelligence so that organizations can identify and act on emerging risks before they develop into successful attacks.
For AI-era threats, this approach is relevant because attackers themselves operate at increasing speed. The more rapidly attackers can discover assets, obtain credentials, create infrastructure, and launch campaigns, the less effective a security model becomes when it depends entirely on periodic review.
Three capabilities within the supplied CYFIRMA framework are particularly relevant to the AI-driven techniques discussed in this report.
Continuous, Outside-In Visibility
Dynamic discovery of internet-facing assets, cloud resources, shadow IT and shadow AI usage can help organizations maintain visibility as their external footprint changes. Continuous exposure scoring is intended to reduce the risk that newly created attack surfaces remain invisible between periodic assessments.
AI-Driven Predictive Intelligence
Correlation of dark-web, deep-web and adversary-infrastructure signals with intent modelling is designed to help forecast likely targets, techniques and campaign windows. This is particularly relevant when attackers use AI to accelerate reconnaissance and campaign planning.
Closed-Loop, Automated Response
Validated, high-confidence findings can support orchestrated actions such as credential rotation, MFA enforcement, WAF updates, takedown requests and identity isolation, subject to human-defined guardrails. The intended benefit is to reduce the time between intelligence and containment.
The supplied CYFIRMA reference material describes a representative engagement in which the platform identified newly registered adversary infrastructure associated with a financially motivated threat group targeting a global financial services organization. Intent modelling indicated a likely credential-stuffing campaign against a retail-banking login surface, while validation identified a large set of previously leaked employee credentials, including some with administrative access. Automated playbooks were described as forcing credential rotation, enforcing MFA, and isolating high-risk sessions before the predicted campaign began.
This example is presented here as an illustrative outcome from the supplied reference material, not as an independently verified case study. Its strategic significance is the operating model: external intelligence identifies a developing threat, validation increases confidence, and automated controls are used to reduce the window available to the attacker.
For Thai organizations, the value of an ETLM approach can be viewed through the country’s increasingly digital and interconnected operating environment. Financial institutions can benefit from monitoring credential exposure, phishing infrastructure, and brand impersonation. Retail and e-commerce organizations can focus on fake domains, fraudulent applications, and customer-facing abuse. Government and critical-sector organizations can use continuous external visibility to identify exposed assets and emerging adversary activity. Enterprises with large supplier ecosystems can extend monitoring to third-party and supply-chain risk.
The central proposition is that cyber resilience should begin before an attacker reaches the organization’s internal security controls. By identifying exposed assets, compromised identities, malicious infrastructure, and adversary intent from an external perspective, organizations can potentially intervene earlier in the attack lifecycle.
The report concludes that AI is significantly changing the cybersecurity threat landscape in Thailand by enabling attackers to conduct reconnaissance, phishing, social engineering, identity attacks, vulnerability exploitation, and campaign coordination more quickly and at greater scale. AI does not necessarily create entirely new attack categories; instead, it acts as a force multiplier that makes existing attacks more targeted, personalized, automated, and difficult to detect. Thailand’s increasingly digital and interconnected economy, including financial services, government, telecommunications, manufacturing, healthcare, retail, and critical infrastructure, creates a broad external attack surface that can be exploited by threat actors.
The report highlights that organizations should move beyond reactive cybersecurity approaches and adopt a predictive cyber-resilience model. Continuous visibility of external assets, identities, brand exposure, third-party risks, adversary infrastructure, and emerging threat signals is increasingly important. By combining external threat intelligence, AI-driven analytics, continuous monitoring, and automated response with appropriate human oversight, organizations can identify developing threats earlier and reduce the time available to attackers.
Implement continuous external attack-surface monitoring
Organizations should continuously identify and monitor internet-facing assets, cloud resources, exposed identities, shadow IT, and shadow AI to prevent newly exposed risks from remaining undetected between periodic assessments.
Strengthen identity security and phishing protection
Organizations should enforce multifactor authentication, monitor leaked credentials, strengthen identity controls, and provide threat-adaptive security awareness training. Employees should also be prepared to recognize AI-generated phishing, impersonation, and social-engineering attacks.
Improve protection against deepfakes and impersonation
High-value financial transactions and sensitive requests should require independent verification, separation of duties, out-of-band confirmation, and appropriate transaction controls because AI-generated audio and video can make impersonation more convincing.
Prioritize vulnerabilities based on active threat intelligence
Vulnerability management should consider business impact and evidence of active exploitation rather than relying only on severity scores. Internet-facing systems should be continuously monitored because AI-assisted reconnaissance can reduce the time between vulnerability exposure and exploitation.
Strengthen ransomware resilience
Organizations should maintain offline backups, endpoint detection and response, vulnerability management, MFA, identity security, and continuous monitoring for suspicious authentication and unusual data transfers.
Manage third-party and supply-chain risk continuously
Organizations should monitor suppliers, partners, technology providers, and managed services for external exposure, leaked credentials, suspicious infrastructure, and emerging threats rather than relying solely on annual security questionnaires.
Establish governance for Shadow AI
Organizations should develop clear policies for the use of generative AI tools and monitor the use of external AI services, browser extensions, plug-ins, and third-party applications to reduce the risk of sensitive data leakage and unmanaged attack paths.
Adopt predictive and intelligence-led cybersecurity
Organizations should correlate external threat signals, leaked credentials, malicious domains, adversary infrastructure, and underground activity to identify potential attacks before they reach the internal environment. Automated response should be used for validated, high-confidence findings while maintaining human oversight for high-impact actions.
Overall recommendations: Thai organizations should transition from a predominantly reactive security model toward continuous, predictive, and intelligence-driven cyber resilience, combining strong identity protection, external attack-surface visibility, threat intelligence, third-party monitoring, employee awareness, and automated response. This approach is particularly important as AI enables threat actors to conduct faster and more personalized attacks across Thailand’s increasingly interconnected digital ecosystem.