AI deepfakes and poor security highlighted the OH Behave Report

AI deepfakes and poor security highlighted in the OH Behave Report

The OH Behave Online Security Report for 2025 provides a concerning summary of cybersecurity practices in an AI-driven world. While users demonstrate growing awareness of emerging threats, the gap between knowledge and action continues to widen, leaving individuals and organisations vulnerable to increasingly sophisticated attacks.

Artificial intelligence is changing how cybercriminals operate

65% of users believe AI will make it easier for criminals to convincingly impersonate individuals. Deepfake technology has already proven capable of creating realistic video and audio that can deceive even cautious observers, facilitating fraud and social engineering attacks at unprecedented scale.

58% of AI users report receiving no guidance on security or privacy risks associated with these tools. This training deficit is alarming as AI becomes embedded in daily workflows, where powerful technology meets uninformed usage.

Challenging assumptions

The report overturns conventional wisdom that suggest older generations are primary targets. Millennials (born 1981-96) top the list at 59% reporting financial losses from scams, with Gen Z (born 1997-2012) following closely at 56%. Familiarity with technology doesn't automatically translate to security awareness, and digital natives may be overconfident and trusting in their ability to spot threats.

Poor security implementation

Multi-factor authentication (MFA) is widely recognised as an essential defence against unauthorised access, yet only 41% of users enable it regularly. This vulnerability can lead to identity theft, financial fraud, and data breaches.

Data backup is equally inadequate, with just 57% of users regularly backing up important information. This should be a priority given the rise of ransomware attacks that can encrypt or destroy data within minutes.

What actions should you take?

The OH Behave report underscores an urgent need for businesses and organisations to provide comprehensive security training, particularly around AI tools and emerging threats. Individuals need greater awareness of implementing fundamental protections: enabling MFA across all accounts, maintaining regular backups, and staying informed about evolving threats in an AI-enhanced landscape.

If your business needs help setting out proven security procedures and training your colleagues to become more security aware, then please get in touch here.

Get the latest news from Strident

6 Steps for Sorted IT

ISO & Data Protection