Privacy & Security

Cyber-crooks now deploy AI, making data protection more difficult
June 30, 2026
HAMILTON, ONT. – If your worries about hackers and cyber-criminals were already bad enough, they’re about to get even worse. And we can thank AI for that.
“AI has been weaponized,” said Kashif Parvaiz, speaking at the Medical Imaging Informatics & Teleradiology (MIIT) conference in April, which was held in Hamilton and was supported by McMaster University.
Kashif Parvaiz is a VP and chief information security officer at Arancia, where he leads the governance, risk, compliance and consulting portfolio and provides advisory services to healthcare and public sector organizations.
He was previously CISO at University Health Network, in Toronto, where he led the provincial initiative to strengthen cyber capabilities across more than 15 Ontario hospitals.
Cyber-criminals are now revving up their efforts, using AI-assisted techniques such as deep-fakes where they can emulate voices to trick unwary staff into opening files that contain viruses.
He noted there have been instances of cyber-crooks calling help desks and impersonating doctors, saying they’ve damaged their phones and can’t get back into the network. They ask for help setting up a new login, which the help desk facilitates.
“They’ve done all their research and know what the person’s name is, who they report to, etc. The initial verification usually passes.”
As a result, the thieves get into the network.
They can also use AI to seek out vulnerabilities in computer networks, using them as launch pads for viruses or ransomware.
The IOMT (Internet of Medical Things) is a special target, such as medical dispensing machines and remote personal monitors for imaging. They’re all from third party suppliers, who may not be vigilant about security, Parvaiz said.
What’s more, a great deal of medical equipment is old and doesn’t have the latest software, making it susceptible to hackers when linked to a network.
Once into the network, hackers can launch a viral attack, shutting down the system and simultaneously acquiring reams of patient and staff data.
Cyber-thieves can and have demanded ransoms to restore the data, a nightmare for hospitals and health regions.
Parvaiz noted that Anthropic, a leader in the creation of AI models, recently produced a new system so powerful that the company was closely controlling its dissemination. In the wrong hands, they worried, it could be used to wreak havoc by discovering weak points in computer networks.
According to Parvaiz, what’s driving the latest generation of cyber-criminals? As he puts it, it’s all about the money.
“We have a lot of information that they can leverage from people’s accounts, including names, addresses and healthcare numbers. They can then impersonate people.
Armed with that data, they can mimic the identities of real people, spending on their accounts.
The problem for healthcare systems is that most are underfunded and unprepared. They’re unable to properly fund their staffing needs and technology, let alone IT security.
But today, every hospital and medical facility must realize that cyber-crime is a growing threat. Moreover, said Parvaiz, organizations are evolving from thinking they can protect themselves to a strategy of resilience. “You know that some stuff is going to get through,” he said.
Not only do you need as strong a defence as possible, but you also need credible backup. In fact, said Parvaiz, you shouldn’t have just one backup, you should have two. “You really should have three copies of the data – two on 90-day standby, and one offsite,” he commented.
Parvaiz urged healthcare managers to assess their current states of cyber-security. “If you’re at two [out of a scale] of five, you’ve got a lot of work to do,” he said.
As first steps, he said organizations must build up their resilience, deploying multi-factor authentication (MFA), as well as 24/7 monitoring of networks and a containment response strategy.
“Make sure you have incident response partners in place for all emergencies. If a person you need is in Bermuda, it doesn’t help.”
And importantly, keep testing the network for vulnerabilities. As systems change over time, with updates and additions, new weak spots emerge. These must be identified and shored up.
Parvaiz noted that on the plus-side, AI can also be used to fight AI. Fortunately, some of the work can be done by AI systems that seek out and find problem areas and suspicious behaviours.
“For example, artificial intelligence can identify a log-in from a foreign country and challenge it with a second login,” he said.
And AI systems work around the clock.
As a defensive measure, organizations have been segmenting their networks, splitting them up into self-contained units so that if a virus penetrates one, it can’t easily get through to the others.
Parvaiz emphasized the role of continuous testing – something that still benefits from human participation. He termed it red team versus purple team, where a group of staff members are assigned to mimic hackers and try to break through the network.
This could be done by phishing, for example, where red team-members trick regular staff into opening files containing viruses, or by impersonating others to gain access to the network.
Another group, team purple, is assigned to defend – to find weak points in the network or suspicious activities.
Through this technique, the network is constantly being assessed and upgraded.
Parvaiz mentioned that hospital executives should also be trained to respond to real-world pressures that occur when a network is breached. “TV reporters and cameras will show up asking for comment,” he asserted. Executives must respond appropriately under this stress, so the public doesn’t lose confidence in the healthcare system.
“Unfortunately, the break-ins tend to happen at 10 pm on a long weekend,” he observed, just when people are expecting to relax.
Because you never know when hackers may strike – and viruses can lay dormant in a system for months – it’s important to conduct defensive exercises, commented Parvaiz.
“Cyber-crime is accelerating at a pace we’ve never seen before,” he said. “AI is now a weapon.”