AI supercharges scams: social engineering goes industrial as cybercrime-as-a-service booms

Hacking Humans

The gist

AI has turbocharged cybercrime, turning social engineering into a booming, industrialized business that’s outsmarting traditional defenses and draining billions from consumers.

What to know

  • AI-powered vishing attacks soared 449% while phishing scams now use deepfakes and branded landing pages to easily fool even savvy users.
  • Turnkey phishing kits and malware-as-a-service platforms like ClickFix—available for as little as $800—are letting even novices launch massive, professional-grade attacks.
  • Consumer fraud losses hit $12.5 billion in 2024, with AI-driven scams responsible for 99% of crypto theft and a 900% spike in fake travel listings.

AI Turns Scams Personal

Attackers wield AI to create hyper-targeted, psychologically tailored lures that exploit trusted platforms and internal company dynamics, making social engineering nearly indistinguishable from genuine communication.

AI is fundamentally reshaping social engineering by enabling attackers to scale and personalize their campaigns with unprecedented speed and sophistication. KnowBe4's 2025 Phishing Threat Trends Report revealed a staggering 449% spike in AI-powered vishing attacks and a 67% surge in the abuse of legitimate platforms, as cybercriminals increasingly exploit trusted environments to bypass traditional defenses. This evolution is especially evident during seasonal events like tax deadlines and major holidays, when attackers deploy psychologically tailored lures that exploit heightened stress and urgency, dramatically increasing their success rates.

The technical prowess of AI-driven social engineering is on full display as threat actors such as Scattered Spider orchestrate post-breach phishing campaigns that impersonate high-profile brands, including M&S, Co-Op, and Harrods, causing hundreds of millions in damages. These campaigns leverage highly personalized phishing emails—often mimicking internal departments like HR or IT—and utilize branded landing pages, domain spoofing, and familiar file types like PDFs to deceive even the most vigilant employees. KnowBe4's Q3 2025 report underscores the effectiveness of these tactics, noting that 90% of user interactions with phishing emails are driven by messages personalized with company names and internal topics, while 70% of simulated attacks employ branded landing pages and 66% use domain spoofing.

AI’s multi-modal capabilities are expanding the social engineering arsenal far beyond traditional email phishing. Attackers now deploy deepfake voice snippets for vishing, generate convincing video clips of executives, and orchestrate interactive live chats—so-called 'ChatOps Phishing'—that walk victims through compromising steps like approving MFA prompts or installing malicious apps. As one expert notes, 'An AI can spit out thousands of unique, personalized lures in the time it takes a human to write one,' and these attacks increasingly target high-trust zones such as Slack, Teams, Jira, and ServiceNow, where users are conditioned to trust internal communications.

By early 2026, AI-powered social engineering attacks have reached a level of technical and psychological sophistication that renders traditional detection methods—such as spotting poor grammar or generic messages—largely obsolete. Attackers meticulously tailor phishing pages to mimic exact corporate branding, exploit authentication gaps in email infrastructure, and leverage compromised legitimate domains to evade security tools. The rise of platforms like 'Quantum Route Redirect,' which automates phishing against Microsoft 365 users and facilitates QR code-based 'quishing,' exemplifies how AI is automating and scaling multi-channel attacks, with over 1,000 domains hosting such platforms and 76% of victims concentrated in the US.

The surge in AI-driven voice and identity fraud has elevated imposter scams to a top enterprise risk, with Americans losing nearly $3 billion annually and organizations spending hundreds of hours investigating incidents. Despite widespread adoption of AI-based voice-fraud detection tools, nearly half of organizations lack confidence in their effectiveness, underscoring a critical gap between perceived readiness and actual resilience. As Carter Huffman, CTO of Modulate, observes, 'The real differentiator won’t just be spotting synthetic voices — it will be proving authenticity in real time without slowing customers down,' highlighting the urgent need for adaptive, seamless verification solutions that balance security with customer experience.

AI-powered social engineering is rapidly evolving to exploit new technical vectors, such as OAuth authentication, by tricking users into granting permissions to legitimate applications and capturing credentials through user-assisted actions. The 'consent fix attack' illustrates how attackers, adapting to tightened security measures, now rely on psychological manipulation and iterative refinement—launching multiple rounds of phishing and leveraging user interaction to bypass even advanced defenses. This relentless innovation underscores the need for layered security strategies that combine phish-resistant MFA, out-of-band verification, and frequent, realistic training.

Sources
PR Newswire - Consumer TechnologyPR Newswire - Business TechnologyToxSec - AI and CybersecurityTechRadarCyberWire DailyPR Newswire - Business Technology

Cybercrime-as-a-Service Goes Mainstream

Professionalized dark markets and affordable, turnkey phishing kits have democratized cybercrime, empowering even novices to launch large-scale, sophisticated attacks with minimal effort.

The commercialization of cybercrime has reached new heights with the proliferation of sophisticated phishing kits and malware-as-a-service platforms, as seen in campaigns like ClickFix. These operations not only deploy advanced infostealers such as Shemos and remote access trojans like Pure RAT, but also integrate social engineering elements—ranging from instructional videos to countdown timers—within their phishing kits. This blend of technical automation and psychological manipulation allows attackers to scale their campaigns efficiently, targeting high-value sectors and maximizing the effectiveness of their scams.

Underground cybercrime markets have matured into highly professionalized ecosystems, where stolen credentials and exfiltrated data are actively traded on forums like LolzTeam. These platforms mirror legitimate e-commerce sites, complete with reputational systems based on customer reviews and complaints, which are crucial in an environment defined by anonymity and mistrust. The result is a thriving, resilient marketplace that not only supports ongoing cybercrime operations but also adapts rapidly to law enforcement disruptions by fragmenting into more specialized, niche offerings.

The professionalization and democratization of cybercrime-as-a-service have significantly lowered the barrier to entry, enabling even low-skilled actors to launch effective attacks. Commercially available toolkits like ClickFix, now sold for as little as $800 and boasting success rates as high as 60%, allow virtually anyone with minimal technical knowledge—or just stolen funds—to participate in large-scale social engineering campaigns. This SaaS-like model, exemplified by platforms such as ErrTraffic, has transformed cybercrime into a scalable, accessible business that challenges traditional security defenses.

AI has become a force multiplier in the cybercrime ecosystem, automating everything from phishing lures to the laundering of illicit funds at unprecedented speed. With generative AI enabling sophisticated social engineering attacks through natural language commands, the technical barrier for launching attacks has plummeted—making it possible for 'anyone to hack anyone.' This commoditization of hacking, paired with AI’s lack of 'street-savvy,' not only expands the attack surface but also accelerates the pace and scale at which cybercrime-as-a-service platforms can operate.

Sources
CyberWire DailyIBM TechnologyCoinDesk Podcast NetworkNew York Stock Exchange

Trust Hijacked at Every Level

AI-powered scams now exploit organizational blind spots and human psychology, leveraging brand impersonation and event timing to infiltrate even the most secure environments.

Attackers have become adept at exploiting both human and organizational trust by hijacking legitimate platforms and impersonating well-known brands, making their social engineering campaigns increasingly difficult to detect. According to KnowBe4's 2025 Phishing Threat Trends Report, there was a 67% surge in the abuse of legitimate platforms, as cybercriminals leveraged trusted channels to bypass traditional defenses. Notably, groups like Scattered Spider targeted retailers such as M&S, Co-Op, and Harrods, launching phishing campaigns that capitalized on the credibility of these high-profile brands to deceive both organizations and consumers.

The psychological sophistication of social engineering attacks has escalated sharply, with AI-powered vishing attacks rising by an astonishing 449% in 2025 alone. Attackers now deploy advanced voice phishing tactics that manipulate victims through convincing audio interactions, exploiting innate human tendencies to trust familiar voices and urgent requests. This evolution underscores a broader trend: as attackers harness AI to refine their psychological manipulation, organizations face a growing challenge in defending against threats that target the human element rather than technical vulnerabilities.

Organizational blind spots remain a persistent vulnerability, as attackers time their campaigns around predictable events like tax deadlines and holidays, and exploit internal dynamics by impersonating departments such as HR and IT. KnowBe4's Q3 2025 Phishing Simulation Roundup revealed that 90% of user interactions with phishing emails were driven by messages personalized with company names and internal topics, while emails mimicking internal departments proved especially effective. This highlights the critical need for continuous employee training and adaptive security measures, as attackers consistently refine their tactics to exploit both seasonal patterns and internal trust structures.

Social engineering attacks have proven remarkably persistent and adaptive, seamlessly shifting across platforms—from email to messaging apps like Slack, Teams, and WhatsApp—as organizations bolster defenses in one area. This resilience is evident in the use of multi-brand phishing kits, the exploitation of high-trust internal platforms, and the deployment of AI-generated deepfakes and chatbots to manipulate victims into compromising security controls such as MFA and SSO. As Flare’s research and multiple case studies show, the underground economy of phishing-as-a-service has matured, enabling even low-skilled actors to launch large-scale, identity-based attacks that exploit the ever-evolving landscape of human and organizational vulnerabilities.

Sources
PR Newswire - Consumer TechnologyToxSec - AI and CybersecurityPR Newswire - Business TechnologyGlobeNewswire - Industry News on TechnologyCyberWire Daily

Defenses Shift from Tech to Team

Organizations are combining adaptive behavioral analytics with real-time employee engagement to counter AI-driven phishing, recognizing that empowered people are as critical as advanced technology.

The defensive playbook against AI-driven social engineering has evolved from static, signature-based detection to a layered, behavior-centric approach that integrates people, processes, and technology. As attackers leverage generative AI to craft infinite phishing variations, organizations are moving beyond obsolete signature checks, instead deploying dynamic behavioral analytics and embedding employees as active sensors through mechanisms like mandatory out-of-band verification and one-click phishing reporting. This multi-pronged strategy recognizes that combating industrialized social engineering requires not just smarter tools, but also smarter, more engaged human defenders.

Human vigilance remains a cornerstone of modern defense, with organizations ditching ineffective annual training in favor of frequent, AI-generated Just-in-Time Micro-Drills that simulate realistic attack scenarios and provide immediate feedback. Clear, actionable policies—such as specifying exactly how IT or Finance will contact employees—empower staff to recognize and reject phishing attempts, transforming the workforce from a vulnerability into a critical line of defense. By making security intuitive and accessible, companies are closing the gap between technical innovation and practical resilience.

Technological defenses are rapidly advancing to counter the sophistication of AI-powered attacks, with a strong emphasis on phish-resistant multi-factor authentication (MFA) like FIDO2/passkeys, strict email authentication protocols (SPF, DKIM, DMARC), and behavioral anomaly detection that moves beyond static text analysis. As phishing campaigns become hyper-personalized and multi-modal—sometimes involving live AI chatbots in so-called 'ChatOps Phishing'—legacy controls are being replaced by adaptive, intelligence-driven systems capable of identifying and responding to the entire attack process in real time. This shift is underscored by the rise of companies like Doppel, which recently secured $70 million to develop AI-based defenses specifically targeting manipulated digital information.

Despite these innovations, the limits of current security are starkly revealed by the persistence of legacy systems, the complexity of modern attack surfaces, and the relentless pace of adversarial adaptation. Incidents like the malicious AI Helper Chrome extension—which compromised data from over 900,000 users—highlight how unregulated browser extensions and outdated verification methods remain weak links. Experts such as Bobby Ford and Carter Huffman stress that while awareness and AI-driven tools are growing, there is a critical gap between perceived readiness and actual resilience, necessitating not just new technologies but also holistic organizational strategies, continuous auditing, and a relentless focus on user behavior.

Sources
ToxSec - AI and CybersecurityNew York Stock ExchangeGlobeNewswire - Industry News on TechnologyCISO Talk by James Azar

Consumer Losses Reshape Security

Soaring fraud losses and relentless AI scams are forcing businesses and regulators to overhaul identity verification and enforcement, even as cybercriminals outpace traditional defenses.

The surge in consumer fraud losses—up 25% in 2024 to over $12.5 billion, according to the FTC—signals a deepening crisis in digital trust and personal financial security. This escalation is not simply due to more fraud attempts, but rather to cybercriminals' growing effectiveness, as a higher percentage of victims now suffer monetary losses. The impact reverberates beyond individuals, undermining corporate bottom lines and compelling businesses to urgently innovate identity verification methods that enhance security without alienating customers.

AI-driven social engineering attacks have dramatically amplified operational burdens and consumer risks across sectors, from crypto to travel and voice communications. In 2025 alone, $3.4 billion in crypto was stolen—99% via social engineering—while AI-powered scams surged by 500%, and travel platforms like Booking.com faced a 900% spike in fraudulent listings. These threats not only erode consumer trust but also force enterprises to balance costly, often cumbersome security measures with seamless user experiences, as evidenced by 44% of organizations reporting customer complaints about verification processes and 39% noting increased call center volumes.

Regulatory and law enforcement responses have grown more coordinated and forceful, treating cyber-enabled fraud as a national security priority and leveraging global partnerships to disrupt criminal networks. Landmark actions in 2025 and early 2026—such as the US DOJ and Treasury's $15 billion forfeiture, international sanctions on the Prince Group, and Cambodia's crackdown on scam kingpins—reflect a new era of cross-border enforcement. Yet, as cybercrime marketplaces professionalize and adapt, regulators face the ongoing challenge of dismantling resilient, reputation-driven underground economies.

The urgent need for public-private collaboration has shifted from mere partnership rhetoric to a call for real-time, data-driven disruption of cybercrime. Initiatives like TRM's Beacon network, which covers 80% of centralized crypto transaction volume and enables immediate fund seizures, exemplify this evolution. Legislative steps such as the SAFE Crypto Act and the push for adaptive, AI-powered verification systems underscore a growing consensus: only by integrating technology, intelligence sharing, and rapid interdiction can digital trust be restored in the face of relentless, AI-enabled threats.

Sources
CyberWire DailyUnchainedCoinDesk Podcast NetworkHacking HumansGlobeNewswire - Industry News on Technology

Get the stories behind the trends

Deep-dive reporting and the weekly brief, in your inbox.