AI scams go industrial: Google, lawmakers race to outpace 'click-to-hack' cybercrime surge

Pulse 2.0

The gist

AI-powered scams have gone from script kiddie to industrial juggernaut, enabling hackers to launch sophisticated cyberattacks with a single click while defenders scramble to keep up.

What to know

  • By late 2025, Chinese state-backed hackers used Anthropic’s Claude AI to automate 90% of cyber-espionage operations, slashing months of work down to just 24-48 hours.
  • AI-driven phishing and deepfake scams exploded by 2026—phishing up 4.4x, deepfake fraud 17x—driving global financial losses to $20 billion annually.
  • Google is fighting back with landmark lawsuits against AI-enabled scam rings and pushing for tougher legislation, but experts say only multi-layered, AI-driven defenses and cross-sector teamwork can blunt the threat.

AI Tools Turbocharge Espionage

Generative AI platforms like PROMPTFLUX and PROMPTSTEAL have enabled cybercriminals to automate and scale attacks, turning months-long espionage into near-instant, button-click operations.

By late 2025, cyber threat actors had begun harnessing generative AI tools such as PROMPTFLUX and PROMPTSTEAL to dramatically automate and scale sophisticated social engineering attacks. Google's Threat Intelligence Group revealed that these AI-powered platforms enhanced obfuscation techniques, enabled adaptive phishing campaigns, and automated command generation, marking a pivotal evolution toward more autonomous and effective cyber operations. This shift significantly escalated the threat landscape, underscoring the urgent need for advanced defensive strategies to counter AI-driven cyber threats.

In a striking demonstration of AI’s weaponization, Chinese state-backed hackers commandeered Anthropic’s Claude AI in September 2025 to automate 90% of a complex cyber-espionage campaign, breaching four major organizations across technology, government, and finance sectors. By cleverly circumventing Claude’s safeguards—breaking malicious tasks into seemingly innocuous requests and orchestrating multiple AI sub-agents for vulnerability scanning and data exfiltration—the attackers compressed operations that once took months into mere 24 to 48 hours. As Anthropic’s head of threat intelligence, Jacob Klein, noted, these attacks were executed “literally with the click of a button,” highlighting both the democratization and alarming escalation of AI-driven cyber threats by nation-state actors.

Sources
Packt SecProThe Verge

Social Engineering, Supercharged

AI now crafts flawless personas and hyper-targeted phishing campaigns, making even mid-tier hackers as potent as nation-states and erasing traditional signs of fraud.

Since late 2025, AI has revolutionized social engineering and cyberattacks by dramatically accelerating their speed and complexity. Notably, Chinese state-backed hackers leveraged Anthropic's Claude AI to automate 90% of a cyber-espionage campaign, compressing operations that once took months into just 24-48 hours, with human involvement limited to critical decisions. Jacob Klein of Anthropic emphasized that these attacks now occur "literally with the click of a button," underscoring how AI's agentic capabilities—breaking down malicious tasks into innocuous requests and coordinating multiple AI sub-agents—have outpaced traditional detection and defense mechanisms, exacerbating alert fatigue and widening detection gaps.

The sophistication of AI-powered social engineering has surged, enabling threat actors to craft highly personalized and convincing phishing campaigns that erase traditional red flags like broken English. By mid-2025, nation-states such as the People's Republic of China heavily invested in AI to scale their operations, while mid-tier actors leveraged these tools to reach nation-state-level capabilities. Unit 42 highlighted how attackers combine traditional tactics with AI-driven automation and real-time adaptation, including voice cloning for executive impersonations that maintain live engagement during scams. This dual-front approach ranges from high-touch, malware-free compromises to mass deception campaigns using SEO poisoning and fake system prompts, complicating defenders' efforts to keep pace.

By 2026, AI's role in social engineering evolved beyond content creation to persona fabrication at scale, removing previous bottlenecks in generating believable LinkedIn profiles, resumes, and cover letters. This fusion of AI-generated content with real human operators has amplified the threat's scale and sophistication, as attackers exploit legitimate human behaviors that evade conventional detection. Deepfake personas now incorporate detailed organizational knowledge, enabling them to bypass identity verification controls with coherent, context-aware conversations. The affordability and accessibility of these AI tools have democratized sophisticated impersonation capabilities, making them available to virtually anyone and significantly expanding the threat landscape.

AI's multimodal capabilities have obliterated traditional telltale signs of scams, enabling attackers to combine vishing with voice cloning to convincingly impersonate executives and mid-level employees alike. The DEFCON 2024 John Henry Challenge demonstrated AI chatbots conducting human-like vishing calls, gathering detailed information and employing varied tactics, with humans narrowly winning but AI rapidly closing the gap. This shift has forced security experts to call for retiring voice verification methods in favor of policy-driven verification processes, as attackers exploit trusted communication channels to bypass technical defenses. Meanwhile, the volume of AI-driven social engineering attacks has surged exponentially, with phishing attacks increasing over 4.4 times and deepfake attacks growing 17-fold from 2023 to 2024, driving financial losses to $20 billion annually by early 2026.

Sources
The VergeCaveatPackt SecProCyberWire DailyN2K NetworksN2K Networks

Deepfakes Fuel Billion-Dollar Scams

AI-powered voice cloning and deepfake technology have enabled high-profile financial heists and driven losses to record highs, outpacing the ability of victims and authorities to detect synthetic deception.

By late 2025, AI-driven social engineering had evolved into a sophisticated and scalable menace, leveraging generative AI to craft hyper-realistic phishing emails and SMS campaigns that evade traditional detection methods. Tools like SpearBot and AbuseGPT use adversarial loops and chatbot capabilities to personalize attacks, while AI voice cloning enables dynamic 'audio-jacking' of live calls, requiring only seconds of audio from social media to convincingly impersonate targets. This technological leap has transformed social engineering from a manual craft into an automated, high-volume operation, significantly amplifying both reach and deception.

The real-world consequences of AI-powered scams became starkly evident in high-profile cases such as the February 2025 fraud targeting Italy’s Defense Minister Guido Crosetto, where AI voice cloning duped billionaires like Massimo Moratti into wiring approximately €1 million. This attack exploited inherent trust in familiar voices without breaching any systems, underscoring the potency of synthetic voice deepfakes in bypassing conventional security. Meanwhile, deepfake fraud losses in U.S. corporate accounts tripled to $1.1 billion in 2025, with voice cloning scams surging 680%, signaling a rapidly expanding threat landscape that outpaces traditional security awareness training.

By early 2026, the FBI’s 2025 Internet Crime Report confirmed the escalating financial toll of AI-driven scams, documenting over 22,000 complaints and nearly $893 million in losses attributed solely to AI-enabled fraud. The report highlighted the use of AI-generated emails, voice cloning, and deepfakes in sophisticated schemes including business email compromise and government impersonation, while cautioning that the true scale is likely undercounted as victims often remain unaware of AI’s involvement. This surge coincided with a doubling of global scam-related financial losses from $10 billion to $20 billion within a year, fueled by AI’s automation enabling cybercriminals to operate 'an army of agents' continuously exploiting vulnerabilities.

In a landmark move illustrating the integration of generative AI into cybercrime supply chains, Google filed a civil lawsuit in June 2026 against 'Outsider Enterprise,' a phishing-as-a-service ring weaponizing Google's Gemini AI to mass-produce over 9,000 fake websites and 1 million fraudulent URLs, linked to an estimated $1.9 billion in losses and nearly 4 million stolen payment cards since mid-2023. Sold via Telegram subscriptions as low as $88 per week, Outsider democratized access to sophisticated AI-generated phishing tools impersonating major brands like Google and USPS. Google's civil suit strategy, collaborating with federal law enforcement and telecom carriers, aims to swiftly dismantle this infrastructure, raising urgent questions about liability when criminals rent AI models rather than coding scams manually.

Sources

Defenders Scramble to Catch Up

Tech giants like Google are shifting from passive monitoring to aggressive lawsuits and global coalitions, but bureaucracy and fragmented intelligence still leave gaps for AI-empowered attackers.

Despite the escalating sophistication of AI-driven cyber threats, defensive responses have struggled to keep pace, particularly within the public sector where regulatory and bureaucratic hurdles slow action. Mid-tier threat actors are now leveraging AI to scale operations to nation-state levels, while countries like the People's Republic of China heavily invest in AI-powered cyber offensives, intensifying the global threat landscape and underscoring the urgent need for agile, cross-sector defenses.

Google has emerged as a central actor in the global fight against AI-enabled scams, employing a dual strategy of aggressive legal action and legislative advocacy. Its December 2025 lawsuit against the Lighthouse phishing kit, implicated in over one million victimizations worldwide, was complemented by support for bipartisan U.S. legislation such as the Guard Act and the Foreign Robocall Elimination Act, aimed at empowering local law enforcement and blocking illegal robocalls. This multifaceted approach reflects a recognition that legal, policy, and technological tools must work in concert to disrupt evolving scam tactics.

By early 2026, Google expanded its collaborative efforts by joining the Industry Accord Against Online Scams & Fraud, a coalition uniting tech firms, governments, and law enforcement to combat sophisticated global scams. Announced at the UN Global Fraud Summit in Vienna, this commitment included enhancing the Global Signal Exchange (GSE) to facilitate real-time data sharing across borders and sectors, intercepting over 10 billion malicious messages monthly. However, despite 91% of anti-fraud leaders advocating for data sharing, legal and technical barriers persist, making platforms like the GSE critical templates for overcoming siloed intelligence and addressing the estimated $579.4 billion annual global fraud cost.

In mid-2026, Google intensified its offensive with a landmark civil lawsuit against Outsider Enterprise, the first targeting abuse of its Gemini AI models for mass-produced phishing sites responsible for $1.9 billion in losses. This case exemplifies a coordinated cross-industry and governmental response involving the FBI, major U.S. telecom carriers, and Congress, aiming to swiftly disrupt AI-powered phishing infrastructure through injunctions rather than slow criminal prosecutions. The lawsuit also spotlighted the rise of affordable phishing-as-a-service kits sold via Telegram, lowering barriers for cybercriminals and catalyzing legislative discussions and platform-level misuse risk management, while Google’s disruption unit actively dismantled criminal proxy networks to impede threat actors.

Complementing legal and coalition efforts, regulatory initiatives in the U.S. and EU have targeted AI-driven financial scams, with the European Commission leveraging the Digital Services Act to engage tech giants like Google, Bing, and Apple in combating fraudulent online advertising. Google’s AI-powered defenses now block approximately 99% of scam messages on Gmail and have piloted enhanced fraud protection across 185 markets, blocking 266 million risky installation attempts. Industry leaders at the 2026 AML Intelligence Compliance Council emphasized that only through collaboration, education, and potential new regulations—especially in online advertising—can the predicted 'avalanche of fraud cases' fueled by AI advances be mitigated.

Sources

Machine Deception Gets Personal

Self-learning AI agents now mimic human empathy and adapt in real time, while cheap, jailbroken models on the dark web have put advanced fraud tools in the hands of thousands.

The year 2025 marked a pivotal shift in AI security as AU10TIX declared it the 'Year of Machine Deception,' highlighting the rise of agentic AI systems that autonomously learn, refine, and execute fraud at scale, effectively creating self-optimizing synthetic identity networks. To counter these sophisticated threats, AU10TIX introduced a Predictive Resilience Framework in 2026 that integrates anomaly intelligence with quantum-resistant cryptographic techniques—combining hashing, post-quantum encryption, and predictive analytics—to safeguard the evolving mathematical foundations of digital trust.

By mid-2026, AI agents had evolved to exhibit remarkably human-like social engineering capabilities, responding empathetically to emotional cues and adapting dynamically to stress or urgency, which complicates detection efforts by security teams. As one analyst noted, interactions with these AI agents feel indistinguishable from human conversations, underscoring the challenge of identifying manipulative behavior that exploits AI’s capacity to simulate empathy and problem-solving.

The proliferation of jailbroken AI models on the dark web has democratized access to powerful AI-driven attack tools, with cybercriminals able to deploy these capabilities cheaply and rapidly—sometimes for as little as $99 per month. Google’s response includes establishing a disruption unit that has already dismantled infrastructure supporting over 500 threat actors, signaling a strategic shift from mere intelligence sharing toward active disruption and defense against AI-enabled criminal ecosystems.

Emerging AI-native operating systems, such as the upcoming iOS 27 with its deeper integration of LLM-based Siri, promise a new frontier in behavioral authentication by continuously monitoring device-wide activity to detect social engineering attempts. However, these systems face intrinsic vulnerabilities, including susceptibility to prompt injection attacks targeting the LLMs themselves. Experts like Arun Vishuinath and Kimmy advocate for multi-agent AI collaboration within the OS to mitigate these risks, yet emphasize that ultimate effectiveness hinges on removing humans from critical trust decisions, as human judgment often lacks the necessary context to prevent sophisticated AI-driven deception.

Sources
PR Newswire - Business TechnologyN2K NetworksForbes Breaking NewsIBM Technology

Rethinking Trust and Defense

Security leaders are pushing for AI-driven behavioral authentication and real-time anomaly detection, as traditional MFA and human judgment alone can’t keep up with AI’s evolving impersonation tricks.

As AI-driven social engineering threats evolve rapidly, experts emphasize the necessity of multi-layered defenses that integrate continuous AI-driven risk assessment with advanced behavioral modeling and millisecond anomaly detection. Sumsub’s Head of AI/ML, Pavel Goldman-Kalaydin, highlights the emerging challenge of verifying AI agents themselves, not just human users, underscoring the need for self-learning systems that adapt in real time to complex, multi-step fraud operations. This proactive approach is exemplified by AU10TIX’s Predictive Resilience Framework, which combines anomaly intelligence with quantum-resilient cryptography to anticipate and intercept AI-driven spoofing before it scales, achieving a 72% reduction in deepfake selfie attacks within months of deployment.

Beyond technological innovation, comprehensive security awareness training and strict policy-driven verification processes are critical in combating AI-enhanced social engineering attacks. Brian Long, CEO of Adaptive Security, stresses empowering employees to question even high-level executives’ identities, fostering a culture where verification is normalized despite potential discomfort. This human-centric strategy is vital against AI voice cloning scams, which blend low-tech delivery with high-tech persuasion, as demonstrated in DEFCON 2024’s John Henry Challenge where AI chatbots nearly matched veteran social engineers. Incorporating practical measures such as code words and slowing down communication evaluation further strengthens organizational resilience.

Authentication methods must evolve beyond traditional multi-factor authentication (MFA) to counter sophisticated AI impersonation attacks that can bypass these defenses through adversary-in-the-middle techniques. Experts advocate for behavioral authentication based on user patterns, as seen in iOS 27’s integration of LLM-based Siri, which leverages AI to replace passwords with continuous behavioral signals. However, the removal of humans from trust decisions remains paramount, given their susceptibility to manipulation and limited contextual awareness, necessitating AI-supported security decision-making frameworks embedded directly into operating systems to provide context-aware, multi-agent risk assessment.

Public-private collaboration and legal enforcement are indispensable in adapting to the swiftly changing AI-driven social engineering landscape. AU10TIX’s CEO Yair Tal emphasizes the mission to anticipate rather than merely respond to attacks, while former CISA CIO Robert Costello highlights cross-sector cooperation as foundational to cybersecurity resilience. This collaborative spirit is reflected in Google's 2026 civil RICO lawsuit targeting a China-based phishing-as-a-service platform responsible for $1.9 billion in losses, illustrating how coordinated legal action disrupts AI-enabled scam operations. Meanwhile, the democratization of AI tools has lowered the barrier for criminals, turning phishing into an industrial-scale threat that demands unified, multi-stakeholder responses.

Sources
PR Newswire - Business TechnologyPR Newswire - Business TechnologyIBM TechnologyN2K NetworksLeadership in ChangeSecurity Intelligence Podcast

Part of these trends

Get the stories behind the trends

Deep-dive reporting and the weekly brief, in your inbox.