Bangladesh needs preparation to fight AI cyberthreats: Sergey Lozhkin

Md. Zahidur Rabbi
Md. Zahidur Rabbi

Sergey Lozhkin spends much of his time trying to understand how hackers think — how they get in, how they stay hidden and how they adapt when their methods are discovered. He is the head of Kaspersky’s Research Centre for APAC and META, specialising in malware, advanced cyber threats and reverse engineering. He previously worked with Kaspersky’s Global Research and Analysis Team and served as a vice-president of cybersecurity operations at JPMorgan Chase.

In a recent conversation with The Daily Star, Lozhkin discussed the changing cyber threat landscape, the growing role of artificial intelligence (AI), and what Bangladesh needs to do to prepare.

Rising threat landscape

Bangladesh faces many of the same cyber threats seen across the Asia-Pacific region, Lozhkin said, including backdoors, information stealers and other forms of crimeware.

“It's not a big difference from the APAC region globally,” he said.
But Bangladesh's large population, growing smartphone use and level of digital literacy can make the impact of familiar threats significant, he said.

Kaspersky's data illustrates the scale. Between April and June 2026, the company detected more than 2.18 million internet-borne cyberthreats in Bangladesh. It said 23.4 per cent of its users in the country were affected by web-borne threats, placing Bangladesh second globally in its ranking for dangers associated with web surfing.

The same period saw more than 5.35 million local incidents, with 29.2 per cent of users affected. Bangladesh ranked 14th globally in that category. The figures come from Kaspersky's Security Network, which aggregates anonymised data from millions of voluntary participants.

When the scam sounds like family

Some of the threats Lozhkin sees do not depend on sophisticated malware. Instead, they exploit trust. He said AI-generated voices and images are increasingly being used to impersonate relatives. A fraudster might call claiming that someone's son or daughter has been involved in an accident and urgently needs money.

“In Bangladesh I have seen fraud schemes using AI-generated voices and images to impersonate relatives,” Lozhkin said.

Such scams can work even when people know they exist, he said, because fear and urgency can override caution. “People trust this a lot,” he said.

The problem is part of a wider trend that Lozhkin said he has seen in several countries, including Bangladesh, Thailand and Myanmar. For victims, the challenge is no longer simply recognising a suspicious message or attachment. It can involve determining whether the person speaking to them is actually who they claim to be.

Hackers are changing how they hide

More sophisticated attackers are also changing how they operate.

Lozhkin's team tracks advanced persistent threat (APT) groups and operations around the world. He said attackers are increasingly looking for ways to hide malicious activity inside legitimate digital services.

When asked if there are any new techniques seen as of 2026 Lozhkin cited examples of attackers using tools such as Visual Studio Code to exfiltrate data and Microsoft Outlook calendar events as part of command-and-control activity.

“The AP groups with the help of AI are going to develop in the fields of stealth communication and data exfiltration,” he warned. “The objective is to make malicious activity appear increasingly like ordinary digital traffic. If attackers can hide data theft inside legitimate communication channels, detecting the activity may require analysing behaviour rather than simply looking for known malicious files.”

He also described APT groups as adaptable, technically sophisticated and focused on remaining undetected. 

The Bangladesh Bank lesson

Bangladesh has already experienced the consequences of a sophisticated cyberattack.

Lozhkin referred to the 2016 Bangladesh Bank heist, which was linked to the Lazarus group. He said the incident prompted changes in the country's approach to cybersecurity.

“Before the incident, Bangladesh's cybersecurity policies, products and implementation were at a relatively low level. After the attack, the government began paying greater attention to protecting not only government organisations but also large private enterprises,” Lozhkin said.

But he said Bangladesh still has room to improve.

“Bangladesh is not on the same level as countries like Singapore or Malaysia. Singapore, for example, is one of the most effective countries in this area and is doing a lot at the government level to protect its cybersecurity,” he said.

A place for young Bangladeshi talent?

The changing threat landscape also raises a question about Bangladesh's young technology workforce.

Lozhkin said he regularly hears from Bangladeshi students seeking advice on how to build careers in cybersecurity and join Kaspersky's research teams.

The company's GReAT team includes researchers from several APAC countries, including Malaysia, China, South Korea, India and Australia. It currently does not have a researcher directly from Bangladesh, Lozhkin said, partly because of Kaspersky's local office structure.

“If in future there's going to be a regional office, absolutely we can think about employing Bangladeshi researchers,” he said.

For students hoping to enter the field, Lozhkin's advice is straightforward: learn the fundamentals and do not rely too heavily on AI. He encouraged young researchers to develop skills in reverse engineering, programming and cybersecurity, alongside a genuine curiosity about how technology works.

“The rest, we can teach anybody,” he said, pointing to talent, passion and hard work as important qualities.

When AI fights AI

Over the next few years, Lozhkin expects cyberattacks and defence to become increasingly automated, with AI systems eventually carrying out much of the work now performed by humans.

“My biggest prediction is that there would be a fight with almost zero human interaction,” he said.

An AI system could search for weaknesses and attempt to penetrate an organisation, while another could detect and stop it. Humans, initially, would remain in control. But Lozhkin believes even that role could diminish as the systems become more complex.

He also warned about the possibility of highly capable AI systems reaching sophisticated criminal groups or nation-state-backed actors.

For Bangladesh, that makes preparation broader than simply deploying better security software. It means strengthening institutions, protecting financial and government systems, improving public awareness and developing people who can understand the technology behind emerging threats.

The attackers, Lozhkin's research suggests, will continue to adapt. The challenge for Bangladesh will be keeping pace.