Cybersecurity Insights & Research

Threat reports, research papers, webinars and whitepapers from the Mercurius security team — staying ahead of the adversary.

Marcos Reis CEO Mercurius - Shadow AI e fraudes

Marcos Reis warns about Shadow AI and more convincing Cybersecurity Fraud

The CEO of Mercurius Cybersecurity examines the dual challenge created by AI adoption within organizations, with incidents stemming from unsupervised use and increasingly sophisticated attacks such as personalized phishing and voice cloning, in a landscape where Gartner estimates that 34% of companies using generative AI have already experienced unintended data exposure.

The rapid adoption of artificial intelligence (AI) tools by businesses has created a new cybersecurity risk landscape for organizations. This phenomenon combines two simultaneous dynamics: the unsupervised use of AI applications by employees—known as Shadow AI—and the use of the same technology by cybercriminals to design increasingly sophisticated attacks.

In this context, Marcos Reis, CEO of Mercurius Cybersecurity, argues that organizations face an operational crossroads: controlling how AI is used within the company while simultaneously preparing for AI-driven threats. The issue extends beyond the use of public chatbots and includes virtual assistants, browser extensions, and other unauthorized tools that can become part of everyday workflows without the involvement of IT departments.

Unintentional information exposure has emerged as one of the primary concerns. According to Gartner, 34% of organizations using generative AI tools have already experienced security incidents or data breaches associated with their use. Meanwhile, research by the Ponemon Institute indicates that more than 40% of the information compromised in these incidents consists of intellectual property and trade secrets—a particularly sensitive category due to its potential impact on competitive advantage and business continuity.

At the same time, AI has become a powerful resource for attackers. It is being used to craft phishing emails that are virtually indistinguishable from legitimate ones, clone executives’ voices, and generate highly personalized messages. It can also facilitate fraud through corporate communication channels such as WhatsApp and Telegram, increasing both the speed of propagation and the complexity of detection.

According to Reis, this shift weakens a traditional security barrier based on people’s ability to recognize obvious warning signs. “For years, we taught people to be suspicious of emails containing spelling mistakes,” said Marcos Reis, CEO of Mercurius Cybersecurity. In his view, today’s level of sophistication requires organizations to rethink their approach: it is no longer enough to identify which applications employees use or to rely solely on traditional awareness training.

In this scenario, the response should evolve from a static model to one focused on data visibility and continuous response. This includes automating the monitoring of sensitive data before it leaves the corporate network and operating with real-time detection capabilities. “The difference will lie in who can detect and respond first,” said Marcos Reis, CEO of Mercurius Cybersecurity.

Industry media

Did you enjoy the content? Share it with your network!

Categories

Last contents