Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security Why do AI-powered tools increase the risk of…
Cyber Security

Why do AI-powered tools increase the risk of fraud, blackmail, and cyber attacks for criminal groups?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 19, 2026 Domain: Cyber Security

AI increases risk because it lowers skill barriers and speeds up operational tasks that criminals once had to do manually. It can help with target research, malware coding, translation, persuasion content, and synthetic voice or video creation. That combination lets less capable actors attempt more schemes and lets experienced groups scale their campaigns across regions much faster.

Why AI lowers the barrier for fraud and cybercrime

AI-powered tools do not create new criminal intent, but they remove a lot of the effort that used to filter out weaker operators. Tasks such as reconnaissance, message drafting, code adaptation, translation, and synthetic media generation become faster, cheaper, and more scalable. That means more low-skill groups can attempt attacks, and existing crews can run more campaigns at once across more regions.

For fraud and blackmail, the practical shift is volume and credibility. AI can help criminals write convincing lures, localise scams into multiple languages, and produce voice or video impersonation that is harder for victims to dismiss. For cyber attacks, the same tooling reduces the time needed to find targets, customise malware, or automate follow-up actions after initial access.

A useful reference point is the pattern documented in NHIMG’s 52 NHI breaches Report, which shows how attackers repeatedly turn scalable access mechanisms into broad compromise. The criminal logic is similar here: whenever a tool lowers repetition cost, abuse tends to scale faster than human review or manual defence processes can absorb.

How criminals use AI across the attack chain

AI is most dangerous when it is used as an accelerator at multiple points in the same operation. It can support target selection, open-source research, exploit adaptation, phishing content, translation, and post-compromise scripting. In practice, that means criminals spend less time on overhead and more time on the parts that directly create loss.

That also changes the economics of experimentation. Before AI, many scams failed because the writing was poor, the translation awkward, or the technical steps too slow for a small group to execute. With AI assistance, criminals can test more variations, refine them faster, and keep the ones that work. The result is not just more attacks, but more adaptive attacks.

Where the abuse involves synthetic audio or video, the fraud risk rises because victims may trust what looks or sounds familiar. In cybercrime, generated code and guided workflow assistance can help attackers stitch together tooling even when they lack deep engineering skill. NHIMG’s DeepSeek breach is a useful reminder that AI systems themselves can also expose sensitive material if logging, prompts, or outputs are handled carelessly.

Risk and Threat Considerations

AI increases the attack surface for crime because it improves scale, persuasion, and speed at the same time. The main risk is not that AI makes every criminal more sophisticated, but that it makes many more actors competent enough to try. Defenders therefore face higher message volume, more convincing impersonation, and faster iteration across fraud, extortion, and malware operations.

Failure mechanism: Criminal groups use AI to compress the time needed for research, content creation, translation, coding, and impersonation, which lowers the effort required to launch or refine attacks. That lets weak operators punch above their skill level and lets organised groups industrialise campaigns across jurisdictions.

Impact: Organisations see more believable fraud attempts, more effective social engineering, more frequent malware variation, and more blackmail schemes built on synthetic audio or video. Detection, victim verification, and incident response all become harder when attackers can generate large numbers of tailored variants quickly.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK, OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKT1598 — Phishing for InformationAI-generated lures and impersonation directly support phishing and social engineering.
T1059 — Command and Scripting InterpreterAI can help attackers generate and adapt scripts for follow-on malicious activity.
T1583 — Acquire InfrastructureAI helps criminals scale the infrastructure and operational setup behind campaigns.
Recommendation — Hunt for AI-amplified phishing patterns and strengthen verification on high-risk requests. Monitor script execution paths and constrain interpreters used for automated attack tooling. Track staging infrastructure and block disposable attack infrastructure patterns early.
NIST CSF 2.0PR.AA — Identity Management, Authentication, and Access ControlFraud and impersonation exploit weak trust and verification in access decisions.
DE.CM — Continuous MonitoringAI-driven attack variation increases the need for continuous detection and anomaly monitoring.
Recommendation — Strengthen authentication and step-up verification for sensitive requests and actions. Tune monitoring to spot rapid campaign variation, not just known signatures.
CIS Controls v86 — Access Control ManagementAI-assisted crime often succeeds when access decisions are too easy to socially engineer.
14 — Security Awareness and Skills TrainingAI improves the realism of fraud and blackmail attempts aimed at users and staff.
8 — Audit Log ManagementFaster criminal operations demand better evidence and faster detection of abuse patterns.
Recommendation — Restrict and review access paths that can be triggered by unverified requests. Train users on synthetic impersonation and require verification for unusual requests. Centralise logs so investigators can correlate rapid, multi-stage campaign activity.
OWASP Agentic AI Top 10A1 — Goal Misalignment and Prompt InjectionAI tools can be manipulated or misused to produce harmful outputs and assistance.
Recommendation — Limit autonomous tool use and validate outputs before they influence security-sensitive decisions.
OWASP Non-Human Identity Top 10NHI-01 — Secrets Exposure and SprawlAI-enabled operations frequently depend on stolen or exposed secrets and tokens.
Recommendation — Reduce secret exposure and rotate credentials that could be reused in automated abuse.

Practitioner Guidance

What to prioritise: Focus first on controls that reduce the value of AI-generated persuasion, especially strong out-of-band verification for payment, credential, and executive-request workflows. If a request can cause immediate financial loss or privileged access, treat voice, chat, and video as untrusted until independently confirmed.

What to verify: Measure whether your fraud and phishing defences can detect high-volume, high-variation lures rather than only known templates. Teams often overestimate their readiness because they test obvious scams, not multilingual, locally styled, or synthetically voiced variants that AI now makes cheap to produce.

Practitioner takeaway: The defensive shift is from spotting obviously bad content to controlling trust decisions under conditions of scale, variation, and impersonation quality.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 19, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org