AI scams go industrial: personalized phishing and deepfake vishing fuel record-breaking fraud losses

The Hacker News

The gist

AI-powered scams have gone industrial, unleashing hyper-personalized phishing and deepfake vishing waves that are driving fraud losses and digital trust to record lows.

What to know

  • AI-fueled vishing attacks soared 449% in 2025, with gangs like Scattered Spider hijacking trusted platforms such as Microsoft and LinkedIn for multi-channel phishing.
  • U.S. consumer fraud losses hit an all-time high of $12.5 billion in 2024, as 90% of phishing email clicks now stem from AI-personalized content.
  • Traditional cybersecurity is struggling to keep up, forcing a rapid pivot to identity-centric defenses, real-time behavioral monitoring, and urgent digital literacy campaigns.

AI Supercharges Social Engineering

Cybercriminals are using AI to craft hyper-personalized, multi-channel phishing attacks that blend seamlessly into trusted platforms, making scams nearly indistinguishable from legitimate communications.

AI is fundamentally reshaping social engineering tactics, fueling an unprecedented surge in both the scale and sophistication of attacks. In 2025, KnowBe4 reported a staggering 449% increase in AI-powered vishing—voice phishing—attacks, as cybercriminals like the Scattered Spider gang exploited AI to breach high-profile retailers such as M&S, Co-Op, and Harrods. These attackers leveraged AI to craft highly personalized phishing campaigns, often timed around seasonal events like tax deadlines and major holidays, making their lures more convincing and timely than ever before.

The abuse of legitimate, trusted platforms has become a hallmark of AI-driven social engineering, with attackers increasingly bypassing traditional cybersecurity defenses. KnowBe4’s 2025 report highlighted a 67% surge in the exploitation of platforms like Microsoft, LinkedIn, and Okta, as adversaries hijacked these trusted channels to deliver sophisticated, multi-channel phishing campaigns. This shift not only undermines the reliability of established security protocols but also demonstrates how AI enables attackers to seamlessly blend into the digital environments users trust most.

Personalization is now the linchpin of AI-powered social engineering, with attackers leveraging company names, internal topics, and even mimicking internal departments like HR and IT to dramatically increase engagement. KnowBe4’s Q3 2025 data revealed that 90% of user interactions with phishing emails were driven by such personalized content, while 62% of users interacted with branded phishing landing pages—Microsoft alone was impersonated in nearly a quarter of cases. By referencing internal projects, recent announcements, or even a colleague’s name, AI-generated lures have rendered traditional red flags like poor grammar obsolete.

AI-driven social engineering now extends far beyond email, orchestrating multi-modal and interactive attacks across channels like Slack, Teams, and even live chat. Attackers deploy deepfake voice vishing, video impersonations, and 'ChatOps Phishing'—where malicious bots guide victims through compromising actions in real time—layering these tactics for maximum effect. This evolution not only increases the likelihood of successful compromise but also highlights how AI can dynamically respond to user pushback, coordinate with MFA prompts, and maintain persistence through techniques like token replay and session hijacking.

Sources
PR Newswire - Consumer TechnologyPR Newswire - Business TechnologyPR Newswire - Business TechnologyTechRadarToxSec - AI and CybersecurityBusiness Wire

Psychological Precision of Scams

AI-driven fraud now exploits personal and organizational trust so effectively that victims suffer not just financial losses but deep emotional and reputational harm.

The psychological manipulation at the heart of AI-driven social engineering attacks has reached new heights, as attackers leverage company names, internal topics, and branded landing pages to convincingly mimic legitimate communications. According to KnowBe4's Q3 2025 report, 90% of user interactions with phishing emails were driven by such personalization, while 70% of simulated attacks used branded landing pages and 66% employed domain spoofing. This sophisticated mimicry not only increases the likelihood of user engagement but also erodes organizational trust and complicates detection, demonstrating how AI amplifies both the scale and subtlety of modern scams.

The human toll of AI-driven fraud is starkly illustrated by stories like the single mother who lost her entire savings following a data breach, underscoring that the consequences extend far beyond financial loss to include emotional trauma and a profound sense of violation. The Federal Trade Commission reported that consumers lost over $12.5 billion to fraud in 2024—a 25% increase from the previous year—not due to more reports, but because a higher percentage of victims are losing money, reflecting the increasing effectiveness and psychological precision of AI-powered scams. As the data-driven economy exposes more personal information, individuals become even more vulnerable to these targeted manipulations, fueling a cycle of rising losses and deepening mistrust.

For organizations, the impact of AI-driven social engineering is twofold: operational disruption and reputational damage. Attacks that impersonate internal departments like HR and IT are especially effective, leading to compromised workflows, financial loss, and a breakdown in employee confidence. The prevalence of branded phishing and domain spoofing, as highlighted in KnowBe4's reports, further undermines trust in internal communications, while the surge in voice fraud—now a top enterprise risk according to Modulate—forces companies to balance stringent security measures with the need to maintain a frictionless customer experience. This evolving threat landscape is pushing organizations to adopt more innovative identity verification methods and foster a security-conscious culture, as technology alone cannot fully counteract the sophisticated psychological tactics employed by attackers.

The psychological manipulation underpinning AI-driven scams is meticulously engineered, following a multi-stage 'kill chain' that exploits emotional triggers—such as urgency, trust, and loneliness—to erode critical thinking and increase compliance. Scammer playbooks reveal a calculated approach: from reconnaissance using social media to rapid trust-building and emotional entrapment, culminating in financial exploitation and, often, victim isolation. This complexity explains why victims, regardless of background, are frequently 'outgunned' and left with lasting emotional scars, as shame and self-doubt compound the financial damage. As one Chinese scam manual bluntly states, 'once emotions are in place, money will follow naturally,' highlighting the chilling precision with which AI-powered fraudsters manipulate human psychology.

Sources
PR Newswire - Business TechnologyCyberWire DailyGlobeNewswire - Industry News on TechnologyBusiness WireN2K NetworksHacking Humans

Cybercrime Goes Industrial

Professionalized cyber gangs deploy modular attack services and regionally specialized tactics, fueling a global ecosystem where AI enables mass-scale, adaptive fraud.

AI and automation are dramatically amplifying both the scale and sophistication of cybercrime, as evidenced by a 67% surge in the abuse of legitimate platforms and a staggering 449% spike in AI-powered vishing attacks throughout 2025, according to KnowBe4's Phishing Threat Trends Report. Attackers are increasingly bypassing traditional cybersecurity defenses by hijacking trusted platforms and strategically timing their campaigns around seasonal events such as tax deadlines and major holidays, illustrating a shift toward more specialized and adaptive attack infrastructures within the cybercrime ecosystem.

The professionalization and specialization of cybercrime are unmistakable in the rise of sophisticated, modular tools and attack-as-a-service models. Platforms like Quantum Route Redirect, which automates phishing and supports multi-vector attacks—including QR code-based 'quishing'—have enabled threat actors to scale campaigns across more than 1,000 domains, with 76% of victims concentrated in the US. Meanwhile, groups like Scattered Spider and ShinyHunters leverage AI-driven social engineering and token replay techniques to breach high-profile organizations, bypass multi-factor authentication, and maintain stealthy persistence, underscoring the industrialization of credential theft and brand impersonation.

The global cybercrime ecosystem has become highly diversified and regionally specialized, with distinct organizational models and attack types emerging across geographic hubs. Eastern European and Russian actors operate with structured hierarchies to execute technically advanced, financially motivated attacks like ransomware, while West African groups focus on high-volume social engineering schemes such as business email compromise. Southeast Asia’s 'pig butchering' scams illustrate industrial-scale, long-form investment frauds, often run from warehouses with a clear division of labor—ranging from mule account procurement to spam campaign execution—highlighting the maturation and segmentation of underground markets.

Underground cybercrime marketplaces have evolved from large, multipurpose platforms into a fragmented landscape of niche markets, a shift accelerated by successful law enforcement takedowns such as the 2025 seizure of Biden Cash Marketplace. These specialized markets now operate with reputation-based systems akin to legitimate e-commerce, where user reviews and complaints shape trust and business continuity among anonymous actors. Despite ongoing disruptions, new marketplaces and attack services continue to emerge, fueling the resilience and adaptability of the cybercrime infrastructure.

Sources
PR Newswire - Consumer TechnologyTechRadarCISO Talk by James AzarCyberWire DailyCyberWire Daily

Security Controls Outpaced

Legacy defenses are failing as attackers bypass traditional barriers with generative AI, forcing organizations to adopt identity-centric, behavioral, and chokepoint-based detection strategies.

The relentless evolution of AI-driven social engineering has rendered legacy security controls—like static blocklists, signature-based detection, and even traditional multi-factor authentication—increasingly obsolete. Attackers now wield generative AI to craft hyper-personalized, multi-modal lures and deploy sophisticated tactics such as ChatOps Phishing, where AI chatbots impersonate IT support in real time, or large-scale OAuth token theft campaigns like those executed by ShinyHunters. As a result, defenders are shifting to layered, identity-centric strategies: enforcing phish-resistant MFA (such as FIDO2/passkeys), mandating out-of-band verification for sensitive requests, and empowering employees through frequent, realistic training drills and easy reporting mechanisms. This holistic approach—combining advanced technology, strict processes, and continuous user education—reflects a recognition that no single control can withstand the dynamic, adaptive nature of AI-powered deception.

While technical innovation is vital, the limits of current security are starkly illustrated by the persistent success of attackers in bypassing even advanced defenses. Research from StrongestLayer and Modulate highlights how trusted platforms like DocuSign, Google Calendar, and enterprise voice systems have become primary attack surfaces, with traditional controls such as SPF, DKIM, and DMARC routinely circumvented. Nearly half of organizations surveyed by Modulate lack confidence in their AI-based voice fraud detection tools, despite 91% planning to increase investment in advanced prevention technologies. This gap between perceived readiness and actual resilience underscores the need for adaptive, real-time verification systems that protect against evolving threats without degrading user experience—a delicate balance, as 44% of organizations report customer complaints about cumbersome verification processes.

Emerging technical solutions are beginning to exploit the very complexity of modern AI-powered attack chains. Recent analyses of campaigns like SmartApe reveal that, despite the sophistication of multi-stage JavaScript injections, redirects, and fake CAPTCHAs, these attacks depend on stable traffic-distribution chokepoints. By monitoring and analyzing these funneling behaviors at scale, defenders can transform chokepoints into high-confidence detection and tracking opportunities, turning the attackers’ own infrastructure against them. This approach, coupled with behavioral anomaly detection and endpoint baselining, offers a promising path forward in detecting and disrupting AI-driven deception tactics that evade traditional controls.

Ultimately, defending against AI-powered social engineering is no longer just about protecting the perimeter—it’s about safeguarding organizational credibility, resilience, and the entire digital ecosystem. CISOs are now tasked with reviewing vendor and law enforcement cooperation, auditing international payments for mule accounts, and enforcing strict content security policies to mitigate threats from malicious code and SEO poisoning. As Bobby Ford of Doppel notes, verifying online information in the age of generative AI is an uphill battle, demanding holistic, adaptive, and identity-centric security strategies that extend beyond technology to encompass people, processes, and the broader business context.

Sources
ToxSec - AI and CybersecuritySoftware Analyst Cyber ResearchN2K NetworksPR Newswire - Business TechnologyCISO Talk by James AzarCISO Talk by James Azar

Restoring Digital Trust

Rebuilding public confidence demands that organizations blend advanced identity verification, aggressive legal action, and widespread digital literacy to counter relentless AI-powered deception.

The erosion of public trust in digital systems has reached a critical juncture, as evidenced by the Federal Trade Commission's 2025 data showing consumer fraud losses soaring to $12.5 billion—a 25% increase from the previous year, even as the number of fraud reports remained steady. This alarming trend underscores the urgent need for organizations and CISOs to innovate in consumer identity verification, seeking methods that enhance accuracy without introducing friction to the user experience. As fraudsters leverage increasingly sophisticated AI-driven tactics, restoring trust will depend on striking a delicate balance between robust security and seamless digital engagement.

Restoring trust in the digital age demands a multi-layered approach that extends beyond technical defenses to encompass legal, legislative, and cultural strategies. Companies like Google are setting the pace by combining aggressive legal action—such as lawsuits against phishing operations like 'Lighthouse'—with support for bipartisan legislation and the deployment of AI-powered tools to counter smishing and robocalls. This evolving landscape also requires CISOs to embrace broader responsibilities, protecting not just organizational assets but also reputation and national stability, as the line between cybersecurity, geopolitics, and public policy continues to blur.

Digital literacy has emerged as the cornerstone of digital resilience, particularly as AI-driven scams become more personalized and psychologically manipulative. From seniors navigating increasingly complex online environments to employees facing internal phishing campaigns that exploit trusted brands like Microsoft, education and practical countermeasures—such as enforcing phishing-resistant MFA and teaching users to recognize urgency as a red flag—are essential. As KnowBe4's Q4 2025 report highlights, fostering a security-conscious culture where individuals are empowered to pause and verify suspicious communications is now as important as any technological safeguard.

The responsibility for combating AI-driven social engineering is shifting from individuals to organizations, with businesses increasingly expected to implement proactive protective measures and innovative solutions. Tools like TNS Call Guardian® and Doppel’s AI-driven defense platforms are gaining traction as essential safeguards, while booking platforms such as Booking.com face mounting liability if they fail to curb AI-generated fraudulent listings. Regulatory and law enforcement responses are also adapting, with rare but notable successes in recovering stolen funds and dismantling sophisticated scam operations, signaling a new era of accountability and collaboration in the fight to restore digital trust.

Sources
CyberWire DailyN2K NetworksCISO Talk by James AzarN2K NetworksBusiness WireHacking Humans

Get the stories behind the trends

Deep-dive reporting and the weekly brief, in your inbox.