In the final installment of our series of Festive Stories, Chief Consultant Lawrie Abercrombie takes us through a journey of cyber security discovery through the lens of Charles Dickens.
It was the best of times, it was the worst of times; it was the age of artificial intelligence, it was the epoch of digital peril; it was the season of innovation, it was the winter of vulnerability. In the bustling heart of the United Kingdom, where the gaslights of progress flickered against the encroaching fog, a new spectre haunted the land: the spectre of AI-driven threats.
In those days, the great houses of commerce, Marks & Spencer, Harrods and the venerable Co-op, stood as proud beacons of British industry. Yet, even as their windows gleamed with prosperity, unseen hands, guided by the cunning of artificial intelligence, wrought havoc within. Ransomware, as swift and silent as Fagin’s nimblest pickpocket, slipped through the cracks, halting the clatter of tills and the flow of goods. Contactless payments failed, logistics faltered and the private confidences of customers were laid bare. The cost? A king’s ransom, over one billion pounds vanished into the night.
Nor was the malice confined to the counting-houses. In the hallowed halls of healing, the Synnovis NHS Pathology fell prey to a most diabolical scheme. AI-enhanced ransomware, exploiting the trust placed in third-party laboratories, brought about not only the loss of service but, most grievously, harm to patients, two souls caught in the machinery’s cold embrace.
The cunning of these new villains was not limited to brute force. Like the Artful Dodger, they adapted and evolved, employing large language models to craft missives so convincing that even the sharpest-eyed clerk might be deceived. “AI is accelerating every stage of the attack chain, from phishing to payload delivery,” declared Elia Zaitsev, a modern-day sage of the cyber realm. “We know AI is transforming the cyber threat landscape, expanding attack surfaces, increasing the volume of threats and accelerating malicious capabilities,” echoed Paul Chichester of the NCSC.
In the grand manufactories of Jaguar Land Rover, the gears ground to a halt for five long weeks, the workmen idle, the economy poorer by £1.9 billion. Elsewhere, at Arup, a deepfake, so artfully rendered it might have fooled even Mr. Brownlow, enabled a fraud of £25 million, the very image and voice of trusted executives turned against their own.
Let us turn the pages of this chronicle further back: in 2019, the first whispers of AI voice synthesis were heard in the corridors of power, used in the infamous CEO fraud of a UK energy company where the voice clone’s German accent and vocal nuances were so convincing that it bypassed the company’s usual verification steps. In the same year, IBM’s DeepLocker revealed malware that could lie dormant, awaiting the perfect moment to strike. In 2020, the mighty GPT-3 penned phishing letters so plausible that even the most vigilant might fall.
No quarter was spared. In finance, deepfake scams and AI-powered fraud ran rampant. In healthcare, ransomware stalked patient data. The energy and transport sectors, with their intricate machinery, found themselves vulnerable to adaptive malware. Retailers, ever at the mercy of the market, now faced AI-driven phishing and supply chain disruption.
The numbers, like the ledgers of Scrooge, told a tale of woe:
68% of analysts confessed that AI-generated phishing was harder to detect than ever.
41% of ransomware families now bore the mark of AI.
£5.72 million, the average cost of a breach, enough to bankrupt many a small concern.
33% of AI-driven incidents targeted the keepers of the nation’s wealth.
62% rise in attacks by synthetic media, deepfakes, the new masks of villainy.
But there is sound advice from the Counsel of the Wise. “AI-generated phishing attacks are nearly indistinguishable from genuine emails,” warned the Harvard Business Review. “Organizations must rethink how they assess vulnerabilities and strengthen incident response strategies,” advised the Tech Advisors. Yet, amidst the gloom, there was hope: “AI is not a silver bullet, but it’s a critical part of a balanced defence,” proclaimed Helen Olsen Bedford of UKAuthority.com.
What, then, was to be done? Where is the Road to Redemption? The wise at the NCSC issued guidance on secure AI implementation. Parliament debated the Cyber Security and Resilience Bill, seeking to bind the new Prometheus with chains of governance. Across the land, the call went out for AI literacy, for vigilance, for the building of systems resilient to both the promise and peril of artificial intelligence.
Thus, as the lamps of London flickered against the gathering dusk, the lesson was clear: AI, like the city itself, was a thing of dual nature, capable of great good and great harm. The future of national resilience would depend not on fear, but on mastery; not on retreat, but on the courage to meet the shadows with wisdom, resolve and a touch of Dickensian fortitude.
For further reading, see the NCSC Annual Review 2025 and the Alan Turing Institute’s CNI defence initiatives.