Skip to content

Why the removal of MIT's "jaw-droppingly bad" AI paper is a lesson for us all

Cybernews November 7, 2025

Few people call out cybersecurity hype as bluntly as WannaCry hero Marcus Hutchins.

This week, the hacker-turned-cybersecurity researcher took to social media to take aim at a widely derided working paper by the MIT Sloan School of Management and vendor Safe Security, which the research community has savaged for overstating AI’s role in ransomware attacks.

The community’s main point of contention with the paper, which has since been removed, is its headline assertion that 80% of ransomware attacks in 2024 involved AI techniques , without going into any detail how threat actors used AI.

First published as a PDF on MIT Sloan’s site in April this year, the paper claimed that it had examined 2,800 ransomware attacks and that 80% of them had been “powered by artificial intelligence.”

Hutchins , a former hacker who now works as a cybersecurity researcher, was one of many critics who have publicly scrutinised the methodology behind the claims, which the majority claim are either vague or false.

“The paper was so absurd I burst out laughing at the title. Then when I read their methodology I laughed even harder,” Hutchins said on .

He added: “Their definition of ‘AI-powered’ was already dubious. But what’s even more hilarious, they never even explained how they concluded that a threat actor was ‘using AI’.

“Many of the threat actors they cited as ‘using AI’ were ones I personally tracked as part of my day job and can testify did not use AI.”

Another vocal critic of the paper – which MIT Sloan claims “is being updated following recent reviews” – has been respected cybersecurity researcher Kevin Beaumont, who roasted the report in a blog post Cyberslop.

Beaumont was prompted to pick the report apart, he said, because CISOs kept forwarding the paper to him, telling the researcher that he was wrong AI not playing a major role in ransomware attacks.

Like Hutchins, he criticised the report for the way in which it was conducted: not naming sources, claiming that historic ransomware groups which have long since disbanded were using GenAI, and inaccurately describing malware like Emotet as being “AI-like.”

“It’s jaw-droppingly bad. It’s so bad it’s difficult to know where to start… The paper lumps almost every ransomware group into using AI, without a source.

“The paper talks things like Emotet as being AI-like (total nonsense; it’s also a historic threat), ransomware groups which disappeared before generative AI using GenAI… There’s just so much going on here that it’s unbelievable this was put into the public domain like this.”

And yet, in September of this year, the paper was very much in the public domain when it was highlighted in a blog post by MIT Sloan which was picked up by the cybersecurity press including TechRadar and Security Boulevard (Beaumont screen shots these reports in his blog).

Beaumont also pointed out how a Financial Times article dated 3 November 2025 had quoted stats from the paper in a story it published, although he adds that these have since been removed.

While the story is concerning, there are lessons to be learned.

What is particularly confusing and misleading the original paper’s headline is the leap it makes from well-documented areas where we already know threat actors are using AI – for things like phishing, polymorphic malware coding, and deepfake social engineering – to implying that AI is used to automate the execution of ransomware attacks.

Unlock more exclusive Cybernews content on YouTube.

Extracted Entities

Attack Types (2)

Malware (1)