Five Eyes Warn AI Could Supercharge Cyberattacks: What Bermuda Businesses Should Do
Artificial intelligence is helping businesses work faster, automate routine tasks, and improve customer service. Unfortunately, it is also helping cybercriminals.
TL;DR
- The Five Eyes intelligence alliance (US, UK, Canada, Australia, New Zealand) says AI-powered cyberattacks could become significantly more capable within months, not years.
- Attackers are already using AI to improve phishing campaigns, automate vulnerability discovery, and increase the speed of cyber operations.
- Some cybersecurity practitioners argue the threat isn’t months away — they say AI-assisted attacks are already happening today using existing tools and automation.
- Either way, the message for Bermuda businesses is the same: cyber risk is a leadership issue, not just an IT department responsibility.
What Happened
A joint statement from the heads of six major cyber and intelligence agencies — the Australian Cyber Security Centre, Canadian Centre for Cyber Security, New Zealand’s NCSC, the UK’s NCSC, the US NSA, and CISA — warned that frontier AI models are expected to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities. The warning suggests attackers are already using AI to improve phishing campaigns, automate vulnerability discovery, create more convincing social engineering attacks, and increase the speed of cyber operations.
Not everyone agrees on the timeline. Some cybersecurity professionals have pushed back on the “months not years” framing, pointing out that AI-assisted attacks using existing tooling and automation are already a well-documented part of the threat landscape today, not a future risk. Whether the shift is already here or arriving soon, the practical guidance is the same: organizations that wait to prepare will be at a disadvantage.
Why It Matters for Bermuda
Many Bermuda businesses operate in industries built on trust, including insurance and reinsurance, banking and financial services, law firms, healthcare providers, government agencies, hospitality, and small and medium-sized businesses.
These organizations increasingly depend on cloud services, Microsoft 365, mobile devices, remote access, and AI-powered productivity tools. While these technologies improve efficiency, they also expand the number of potential attack points. Unlike traditional cyberattacks that often relied on poor spelling or obvious warning signs, AI can now generate highly convincing emails, fake invoices, cloned voices, and realistic messages that are much harder for employees to detect.
The Bermuda Monetary Authority has been working through its own AI governance process for the financial sector. Its discussion paper on the responsible use of AI, first published in mid-2025, closed its consultation period and has since moved into the next stage of engagement with industry stakeholders. The direction is clear: AI governance, cyber-risk, and operational resilience are increasingly treated as connected issues by regulators, not separate checkboxes.
What AI Changes
- Write convincing phishing emails in seconds.
- Translate attacks into multiple languages.
- Research organizations automatically.
- Personalize scams using publicly available information.
- Generate malware more quickly.
- Identify vulnerable systems at scale.
The result is that cybercriminals can launch more attacks with fewer people and at much lower cost. For businesses, that means even smaller organizations are becoming worthwhile targets.
What You Should Do
1. Strengthen Multi-Factor Authentication
Every Microsoft 365 administrator should review authentication methods and eliminate legacy authentication where possible.
2. Train Employees Regularly
Annual awareness training is no longer enough. Employees should regularly practice identifying phishing emails, fake support requests, and AI-generated scams.
3. Review Backup Strategies
Backups should be tested regularly, stored securely, protected against ransomware, and kept offline or immutable where appropriate. A backup that has never been tested is only a theory.
4. Review Third-Party Risk
Many businesses depend on cloud providers, IT support companies, payroll vendors, accounting platforms, and CRM providers. Each supplier becomes part of the organization’s security posture. Ask vendors about MFA, incident response, backup practices, security certifications, and breach notification procedures.
5. Develop an AI Policy
Employees are already experimenting with AI. Organizations should provide guidance on what information may be entered into AI systems, which AI tools are approved, data privacy expectations, human review requirements, and acceptable business uses. Waiting until after an incident is too late.
IT Perspective
Cybersecurity is changing rapidly because artificial intelligence is changing the economics of cybercrime. Businesses can no longer assume that only large multinational organizations are attractive targets — automation makes it economical for criminals to target organizations of every size. For Bermuda companies, cybersecurity should now be viewed the same way as financial controls, insurance, and business continuity planning: an essential part of managing organizational risk.
Tools That Can Help
Identity & Access: Microsoft Entra ID Multi-Factor Authentication, password managers
Endpoint & Email Security: Microsoft Defender for Business, Microsoft 365 Business Premium, Endpoint Detection and Response (EDR) solutions
Backup: Immutable backup solutions
Awareness: Security awareness training platforms
Sources
- UK National Cyber Security Centre
- CISA — AI Security Resources
- CBS News — Five Eyes AI cybersecurity warning
- New York Post — Five Eyes AI cyberattack warning
- Bermuda Monetary Authority — Discussion Paper: The Responsible Use of Artificial Intelligence in Bermuda’s Financial Services Sector
- Office of the Privacy Commissioner for Bermuda — Guide to PIPA