The impact of AI on the risks of cyberattacks; key takeaways from the AP’s Report Data Breaches 2025
-
Insight Article 24 July 2026 24 July 2026
-
UK & Europe
-
Cyber Risk
The Dutch data protection authority (Autoriteit Persoonsgegevens, hereafter: “AP”) recently published its Report Data Breach 2025, highlighting a significant increase in data breaches and warning that the growing use of artificial intelligence (AI) by cybercriminals is making phishing attacks more effective, scalable and difficult to detect.
Key findings
The AP received 39,407 data breach notifications in the Netherlands in 2025, up from 37,839 in 2024. Particularly notable was the increase in cyber-related incidents, with 2,428 data breaches resulting from cyberattacks, compared with 1,537 in 2024.
The regulator identified a sharp rise in account takeover attacks, where threat actors gain access to user accounts, typically through phishing campaigns. The number of successful account takeover attacks increased from 607 in 2024 to 1,742 in 2025, making phishing one of the most significant cybersecurity risks facing organisations today.
Importantly, the AP notes that phishing is increasingly not only a consequence of data breaches, but also a cause of them. Successful phishing attacks frequently result in account takeovers, which may provide threat actors with access to corporate networks and are increasingly used as a stepping stone for larger cyberattacks. This trend is reflected in the sharp increase in account takeover attacks reported in 2025.
The report also notes a modest increase in ransomware incidents, from 127 attacks in 2024 to 136 in 2025. The AP notes that modern ransomware attacks increasingly involve the theft of personal data, and not solely the encryption of systems.
While cyberattacks dominate headlines, the AP notes that many breaches continue to result from preventable organisational mistakes. In 2025, the AP recorded hundreds of incidents involving personal data accidentally published online, improper redaction of documents, and lost devices, documents and USB drives containing sensitive information.
Why AI changes the threat landscape
According to the AP, AI is accelerating several stages of the phishing lifecycle. AI tools enable attackers to:
- collect and analyse publicly available information about targets more efficiently;
- produce highly convincing and personalised phishing messages;
- mimic writing styles and trusted brands;
- generate multilingual content at scale; and
- analyse which phishing messages are most effective and automatically adapt campaigns accordingly.
The AP emphasises that personal data obtained through breaches may increasingly be used to facilitate AI-enhanced phishing attacks. Personal data may subsequently be used in highly personalised phishing, fraud and social-engineering campaigns, significantly increasing the risks faced by affected individuals. The report also highlights how existing phishing kits and phishing-as-a-service offerings are becoming increasingly sophisticated through the use of AI, lowering the technical barriers for would-be attackers and increasing the volume of malicious campaigns.
Adequate security measures against phishing
Organisations must assume that human error will occur and design their security frameworks accordingly.
- The AP emphasises the importance of:
- multi-factor authentication (MFA);
- a general policy for effectively filtering email and network traffic;
- network segmentation;
- clear internal reporting mechanisms for suspected phishing attempts.
What this means for organisations
As AI continues to reshape the cyber threat landscape, organisations should assume that phishing attacks will become more convincing, more personalised and more difficult to detect. In its accompanying announcement of the report, the AP emphasised that digital security is a top management matter. Effective governance, board-level engagement, employee awareness and robust incident response capabilities will increasingly determine how successfully organisations can prevent, withstand and recover from incidents. As phishing attacks become more sophisticated and scalable through AI, organisations should treat phishing resilience as a core component of their broader cyber risk and incident response strategy.
End

