Dr Enoch Agyepong FBCS assess the most common AI based attack vectors and offers his views on strategies that should enable organisations to thrive.
Summary:
- Treat AI driven threats as a strategic business risk and enforce strong verification rules for high impact actions
- Continuously monitor for behavioural anomalies and adopt modern security tools that detect subtle, AI generated attack patterns
- Train staff using realistic AI based scam scenarios so they instinctively verify unexpected requests before acting
Talk to security analysts working in a security operations centre (SOC) and they will tell you that cyber criminals are already using AI to increase the intensity and variety of attacks. Indeed, the same technology that helps businesses work faster is also being used to create highly convincing emails, fake voices and even realistic videos that trick staff into transferring money or sharing sensitive information. This means that old style checks such as looking for typos or odd email addresses are no longer enough, because AI generated messages can look and sound completely normal.
A number of industry and academic publications report that AI is lowering the cost of fraud, accelerating hacking attempts and enabling more convincing deception at unprecedented scale. The risk is changing from solitary abuse to industrialised crime, where a small number of criminals could reach numerous victims at once if they have access to increasingly sophisticated AI capabilities. It is important to point out that AI doesn’t necessarily create new crimes, but it makes old ones far more effective; scammers can now craft realistic phishing messages, tailor them for each victim, translate them into multiple languages and send automated follow-ups. This changes the economics of online crime: the effort and technical skills needed have reduced dramatically.
The most common abuses
Amongst the biggest risks is phishing and impersonation. AI capabilities are being used by criminals to mimic executive writing styles and voices by creating messages that appear natural. They are also being used by criminals to create phoney voices or video clips for social engineering. AI crafted deceptive messages sound real, fake identities look authentic, and scams evolve faster than many organisations can respond. This makes it simpler to deceive employees into disclosing private information, approving payments or changing passwords. AI is also being used by criminals to write malicious code, test stolen credentials and refine malware more quickly. Ransomware criminals can also use AI to draft threatening messages and manage attacks automatically. Likewise, AI can generate realistic fake IDs or customer profiles that fool financial systems. Combined with stolen data, these scams feel convincingly personal and harder to spot.
How organisations could respond
As a security practitioner, I’d argue that this makes traditional awareness training and static technical controls less effective unless they are updated. Businesses need to respond by strengthening identity checks, improving approval processes, monitoring for strange behaviour and updating training with realistic scam examples.
Businesses really need to tighten how they verify high risk actions, especially anything involving money, identity or access to systems. The use and implementation of multi factor authentication is essentially on all important accounts as this also raises the bar for criminals, even if they manage to steal a password. Businesses need to consider training their staff to treat any unusual request involving a payment, a new supplier or a password reset as suspicious until it is confirmed by a separate, trusted channel, such as a phone call using a known number or an in-person check. Introducing rules for dual approval on large or unusual transactions and keeping critical financial duties separated between different people makes it much harder for a single fraudulent message to succeed.
Organisations also need to modernise how they detect and monitor threats, because traditional email filters and basic security tools may not spot AI generated scams or synthetic identities. Monitoring systems should be updated or replaced with tools that can recognise patterns such as rapid password attempts, unusual login locations or sudden changes in account behaviour. Many modern security platforms now use AI themselves to find subtle anomalies that humans would miss, and investing in these kinds of tools can help companies catch attacks earlier and respond more quickly.
For you
Be part of something bigger, join BCS, The Chartered Institute for IT.
Staff training must evolve as well, moving beyond simple ‘don’t click strange links’ advice. Employees should be shown realistic examples of AI driven scams, including deepfake audio and video, so they can see how convincing these attacks can look. The core message should be that a message can seem entirely genuine and still be part of a scam, so staff need to verify unexpected or urgent requests before acting. Every employee should know exactly who to contact and how to escalate a suspicious message, and organisations should run regular awareness sessions and simulated phishing tests to keep vigilance high.
Inside the business, leaders should also govern their own use of AI carefully, because poorly managed AI can create new security gaps. Employees should be instructed not to paste sensitive customer data, financial records or internal documents into public AI tools. Any AI systems used for decision making on money, contracts or hiring should include human oversight and clear rules for who is responsible if something goes wrong. Equally important is protecting the company’s own AI models and code, since leaks of internal systems can give criminals insight into how to exploit weaknesses or design tools that bypass defences.
Finally, boards and senior leaders must treat AI enabled crime as a strategic business risk rather than just an IT issue. This means including AI driven threats in risk registers, audit plans and crisis response discussions, and making sure cybersecurity teams have the budget and authority to act. As criminals use AI more routinely, the organisations that stay ahead will be those that combine stronger verification rules, better monitoring, smarter employee training, and disciplined internal use of AI. By taking these steps, even small or non-technical businesses can reduce their vulnerability to one of the fastest growing threats in the modern threat landscape.
A warning for the future
The main lesson is simple: AI is becoming a force multiplier for crime. It reduces effort, expands reach, and improves deception. The recently reported leak involving Anthropic’s AI code shows that AI systems are also high-value targets and require the same level of protection as other sensitive digital assets, which can be leaked to cause reputational damage to an organisation.
In the context of this leak, even if it did not expose model weights or user data, it could be argued that the leak provided useful insight into the architecture and where some risks lie. For cybercriminals, that kind of insight is gold. It can help them copy features, find loopholes, or design tools that bypass safeguards.
For organisations, the priority is to prepare for a world where criminals use AI as naturally as legitimate users do. The winners will be those that strengthen controls, train people well, and adapt fast enough to keep pace with an increasingly automated threat landscape.