Peter Barrett speaks on navigating communication risks and response to AI-driven cybercrime for LIDW26

Our partner Peter Barrett spoke at the LIDW26 member-hosted event, “AI-driven cybercrime: navigating risks, resilience and response”, alongside Shireen Peermohamed and Amy Bradbury of Harbottle & Lewis, and Jacob Coles of leading cybersecurity provider Zensec.

Peter Barrett speaking on AI-driven cybercrime for LIDW26

The session examined how the rapid evolution of cybercrime, driven by threats such as deepfakes, malicious GPTs and AI-enhanced ransomware, is reshaping legal, reputational and cybersecurity risk. Using a fictional case study involving disinformation, synthetic media, ransomware and multi-layered extortion, Peter addressed the crisis communications and reputational response, including stakeholder engagement and narrative control. Amy examined the legal options and challenges arising from takedowns, individual rights, data and regulatory issues, while Jacob explored technical and forensic response techniques, including attribution, deepfake analysis and the anatomy of breach recovery.

The event was well-timed and a salutary lesson for attendees, as there are very few risks facing corporate and private clients that are more acute, or evolving more quickly, than AI-enabled cybercrime.

A new phase of cyber risk

Peter highlighted that AI is not merely another cyber risk. It adds scale, speed and sophistication to conventional attacks, particularly ransomware, and lowers the barrier to entry for malicious actors. He noted that it also operates within a hostile information environment in which data and content are easier to manipulate and harder to verify. The result is a catalyst for broader reputational attack. Hard-earned trust, goodwill and stakeholder confidence have rarely been more exposed.

Drawing on the fictional scenario discussed during the session, Peter noted that the core pillars of cyber risk remain familiar: ransomware, data exfiltration and extortion, denial-of-service attacks, fraudulent payments and business interruption. Their consequences can include financial loss, regulatory scrutiny, operational disruption and reputational harm. What has changed is the choreography of attacks. Threat actors are increasingly using agentic AI to identify victims, map exposed systems, detect vulnerabilities, harvest credentials, navigate internal environments and prepare information for exfiltration.

The panel explored how authorised enterprise AI applications can themselves create vulnerabilities through hostile prompts or hidden instructions, while deceptive AI-related services may appear legitimate but exist to capture confidential information. He also highlighted how new software releases and platform updates can create additional risks in this regard.

Also discussed was the growing threat posed by AI-enabled disinformation. Peter highlighted that generative AI can now produce convincing documents, images, voice clones, synthetic video, local-language translations and mimicked writing styles quickly and cheaply. The 2024 Arup Hong Kong incident, in which a finance employee transferred US$25 million after joining what appeared to be a video call with senior colleagues, remains the best-known example. Similar risks have been seen in near misses involving Ferrari and WPP.

Reputational pressure: growing multi-layer extortion

Peter discussed how cyber extortion is increasingly moving beyond the familiar “double extortion” model, in which data is encrypted and stolen. Threat actors now deploy triple, quadruple or multi-layered extortion: threatening to publish authentic stolen data alongside AI-generated false material designed to cause reputational damage. Fabricated content might appear to reveal executive misconduct, internal decision-making at odds with stated values, or misleading claims about the scale of a breach and the sensitivity of affected data. These tactics increase pressure on victims and destabilise stakeholders during ransom negotiations.

Peter also examined the practical challenges this creates for organisations responding to an incident. Often, the most damaging material is not wholly false. Effective smear campaigns routinely combine genuine facts with insinuation, omission and distortion, creating allegations that are difficult to disprove quickly. The attacker’s aim is to create credible fear, uncertainty and doubt, particularly in the early stages of an incident when the organisation is still investigating.

The panel noted that the motivations behind such attacks vary considerably. Criminal groups typically seek leverage in extortion talks. Nation-state actors aim to weaken institutions, disrupt infrastructure, influence political debate or damage economically important companies. Competitors, former employees, activists, litigants or private individuals may use similar techniques for commercial, ideological or personal reasons.

However, it is not only corporates and major institutions that are under threat; individuals are also vulnerable. Peter highlighted the case of West Midlands teacher Cheryl Bennett, who was targeted when doorbell footage was manipulated to make it appear that she had used a racial slur while canvassing for a local political candidate. She later secured the UK’s first legal settlement concerning a political deepfake, though not before the video had spread online, prompting abuse and threats.

Concluding the discussion, Peter emphasised that organisations and individuals need more than technical cyber controls. Effective governance, training, incident-response planning, pre-bunking strategies, stakeholder preparation and coordination between forensic, legal and communications advisers are essential. False content must be disproved clearly and quickly where appropriate. Information veracity and narrative control are now strategic disciplines. Boards, advisers and senior leaders must treat AI-powered cybercrime and disinformation as interlocking threats to legal, commercial and reputational resilience.