Back to all articles

August 4, 2026

Cybercriminals Are Using AI And We Showed You How to Fight Back

Ironhack's First Class Free on cybersecurity in the AI era covered phishing attacks, AI-powered hacking, and what a real security career looks like in 2026. Here's what you missed.

Maya Tazi

Something shifted in the room on June 18th.

Sixty-plus people joined Ironhack's First Class Free on cybersecurity expecting a standard introductory session. What they got instead was something closer to a reality check: a front-row look at how artificial intelligence has changed both sides of the security equation and what that means for anyone considering a career in this field.

Simon Paloma, Cybersecurity Analyst and Consultant specializing in SecOps, Incident Response, and Ethical Hacking, spent 60 minutes walking a live audience through the tools, methods, and mindset that define modern cybersecurity work. No slides padded with theory. Just the job — explained by someone doing it.

If you missed it, you can watch the full recording here. And if you caught it live, here is the write-up worth sharing.

The Uncomfortable Truth About AI and Cybersecurity

Most conversations about AI and security focus on AI as a defense tool — smarter detection, faster alerting, automated response. What Simon opened with was more uncomfortable: the same AI tools helping you write emails and boost productivity are already being actively used by cybercriminals.

Phishing emails are harder to spot than they were two years ago. Not because attackers got more creative, but because AI-generated text has eliminated the typos, awkward phrasing, and off-brand language that used to tip people off. Scams are more convincing because they are better written. Attackers can now automate personalization at a scale that previously required human research — pulling from your public LinkedIn, your company's website, recent news about your organization and stitching those details into a message that reads like it came from someone who knows you.

The challenge for security teams is that the attack surface is expanding faster than most organizations can track. Ransomware. Supply-chain compromises. AI-enhanced voice cloning for vishing attacks. The volume is up, the sophistication is up, and the talent gap is real.

According to market projections cited in Ironhack's 2026 cybersecurity curriculum, the global cybersecurity market is expected to grow from approximately $245 billion in 2024 to over $500 billion by 2030. That growth is not speculative — it is driven by very concrete organizational need. Companies are prioritizing security not because it is a box to check but because the cost of failing to do so has become catastrophic.

What Attendees Actually Learned

The session covered the questions people most often have before they start seriously researching a cybersecurity career:

How do cybercriminals actually operate today? Simon walked through the attacker methodology — reconnaissance, weaponization, delivery, exploitation — and explained how AI tools accelerate each stage. Understanding attack patterns from the attacker's perspective is not just interesting; it is the foundation of every defensive role in the field.

What do security teams do all day? The session covered how SOC (Security Operations Center) analysts actually work: monitoring logs through SIEM platforms like Splunk, triaging alerts, distinguishing real incidents from false positives, and escalating the things that matter. The job requires pattern recognition, technical curiosity, and the ability to stay calm and methodical when systems are under pressure.

How does AI help defenders? AI-powered monitoring tools can detect behavioral anomalies in real time — flagging a login from an unusual geography, catching a process running at an atypical hour, identifying data exfiltration patterns that a human analyst would need days to notice. The key insight: AI does not replace the security professional. It gives them leverage.

What does a cybersecurity career path actually look like? From SOC Analyst to Penetration Tester to Security Architect to CISO, Simon mapped the progression clearly. Entry-level is accessible for career changers. The progression is steep, but the demand for every level of expertise is consistently higher than supply.

The Phishing Survival Kit: What Simon Shared With Attendees

One of the most practical pieces of the session was a takeaway guide Simon created specifically for the First Class audience. The central idea he kept returning to was this: in 2026, your gut is not the detector — your method is.

AI has made attacks convincing enough that instinct alone is unreliable. What works instead is a consistent, practiced checklist applied to every unexpected message, request, or link.

The framework he shared covers five checks to run before trusting any message. First, verify the actual sender address rather than the display name a friendly name is trivially easy to fake, but the email domain is harder to spoof at scale. Second, hover over any link before considering whether to click it, and check whether the destination address matches what you would expect. Third, treat urgency as a warning sign rather than a reason to act quickly — pressure is engineered specifically to bypass critical thinking. Fourth, ask yourself whether you were expecting this message or request. An unexpected message that happens to be well-written is still unexpected. Fifth, verify through a completely separate channel when something feels off — call the company directly using a number you already trust, not one provided in the suspicious message.

He also covered how attackers gather the personal details that make targeted messages convincing. Public social media profiles, company websites, and professional networks are all sources that get mined. Reducing what is publicly accessible about you is a legitimate security measure, not paranoia.

The guide also included a point that gets less attention than it deserves: voice cloning has made phone calls as susceptible to social engineering as email. A caller can now sound like someone you know. The golden rule Simon reinforced is that no legitimate financial institution will ever ask you to confirm or read back an SMS authentication code over the phone. Ever. If someone is asking you to do that, they are attempting fraud.

Why Cybersecurity Is One of the Strongest Career Bets in Tech Right Now

The talent gap in cybersecurity is one of the most documented shortages in the professional labor market. Organizations across every industry — financial services, healthcare, retail, public sector — are actively competing for people with verified security skills and finding the pipeline consistently too small.

This is the structural context that makes a cybersecurity career change compelling in 2026. The demand is not tied to a product cycle or a particular economic moment. It is driven by the ongoing and accelerating need to protect systems that every company depends on. Ransomware attacks, data breaches, and compliance requirements are not going away. They are scaling up. The organizations defending against them need more people, and they need them now.

The roles that graduates of Ironhack's cybersecurity program have moved into include SOC Analyst, Security Engineer, Penetration Tester, IT Security Consultant, EDR Specialist, SIEM Engineer, and Cybersecurity Consultant. These are not niche specialties — they are the core operational roles that modern security teams run on.

What Ironhack's Cybersecurity Bootcamp Covers

The full program is built around the same "learn by doing" methodology that Simon demonstrated in the First Class. No passive consumption. You work in virtual labs and simulated environments from week one.

The curriculum covers network administration and traffic monitoring, cybersecurity frameworks and threat modeling, SIEM tools and techniques with Splunk and Kibana, digital forensics and malware analysis using tools like Autopsy and Ghidra, penetration testing in Kali Linux with Burp Suite, ethical hacking and incident response methodology, and security automation with Python and PowerShell.

You finish with a capstone project that simulates a complete attack and defense scenario — performing detection, analysis, and incident response as a professional security team, not as a student exercise.

The program is available in two formats: nine weeks full time (weekdays, 9am to 6pm) and six months part time (evenings and Saturdays). Both are 100% remote and live, with certifications including CompTIA Security+ upon completion. Total hours: 400+.

Career services run alongside and beyond the program, with a structured progression from job search fundamentals through portfolio building, mock interviews, and salary negotiation — and Ironhack's Talent Accelerator Program connects graduates directly with hiring startups for real-world project experience before the formal job search begins.

Don't Wait for the Next Email That Looks Legitimate

The main thing Simon left the room with is not a technical concept. It is a posture.

Cybersecurity work in 2026 is fundamentally about method. About maintaining a consistent process for evaluating what is real and what is engineered to look real. About understanding how attacks are built well enough to recognize them before they land.

That posture is learnable. The technical skills that support it are teachable. And the market for people who have both is larger than it has ever been.

First Class events are free, live, and limited in size. The next session will be announced shortly — follow Ironhack on LinkedIn or check events.ironhack.com to make sure you get a spot before they fill.

If you are ready to move faster, the cybersecurity bootcamp is open for applications now.

Related Articles

Recommended for you

Ready to join?

More than 10,000 career changers and entrepreneurs launched their careers in the tech industry with Ironhack's bootcamps. Start your new career journey, and join the tech revolution!