๐ February 2024. A finance worker in Hong Kong got a video call. On screen: his Chief Financial Officer, looking totally normal. Several familiar colleagues, all talking. The CFO had one urgent request โ transfer funds to multiple accounts immediately. Total amount: HK$200 million. About $25.6 million USD.
He transferred it. Every single person he saw on that call was a deepfake. Every voice, every face โ generated by AI in real time. The real CFO was at his actual desk, completely unaware. The real colleagues had no idea either.
The company? Arup โ one of the world's most respected engineering firms. The attack? Perfectly executed. The money? Gone.
And that happened in 2024. AI has gotten significantly better since. This is what we're dealing with now.
๐ Remember the Old Phishing Emails? Almost Miss Them.
Cast your mind back to 2005. Your inbox had an email from "Prince Abdullahi of Nigeria" who desperately needed your bank details to transfer $15 million. The email looked like it was typed by someone fighting their keyboard. Grammar? Optional. Spelling? Decorative. Urgency? Through the roof.
"DEAR RESPECTED CUSTOMER, YOU ACCOUNT HAS BEEN SUSPENDE. PLZ CLICK LINK IMIDIATELY OR YOU MONEY WILL BE LOST FOREVER."
You spotted it in 0.3 seconds and deleted it. And you felt very smart doing so.
Here's the uncomfortable truth: that terrible grammar was actually a feature, not a bug. Security researchers later figured out that scammers intentionally kept the spelling awful. Why? Because it filtered out "smart" people who would raise complaints later. They only wanted the most gullible targets to reply. It was an efficient sorting system โ crude, but it worked.
But that era is over. And what replaced it is genuinely unsettling.
๐ค Then AI Walked In. And Everything Got Worse.
Here is the fundamental problem. For decades, cybercriminals faced a dilemma. They could either go wide โ send millions of identical garbage emails and hope 0.1% of people click โ or go deep โ spend hours researching one specific target and craft a perfectly tailored attack. Wide meant low quality. Deep meant slow and expensive.
AI killed that trade-off entirely.
Today, an attacker can target a thousand people with emails that are each individually researched, perfectly written, and psychologically tailored โ in the time it used to take to write one mediocre email. The cost of quality dropped to almost zero. The speed went through the roof.
A Singapore Government Technology Agency study proved this. They sent two sets of phishing emails to 200 employees: one written by humans, one generated by AI. The AI emails got significantly more clicks. Researchers called the AI-generated text "weirdly human." That was 2021. The models being used today are generations ahead.
๐ฏ 5 Ways AI Is Weaponised Against You Right Now
โ ๏ธ Attack #1: The Email That Looks Perfectly Real
The easiest way to spot a phishing email used to be bad English. Attackers operating from non-English-speaking countries struggled badly with natural corporate language. "Please to clicking the link for verify your account." Dead giveaway.
Now, an attacker types a simple prompt into an AI: "Write an urgent payment reminder email in the formal tone of an HR department from a mid-sized UK company. Reference an overdue invoice from last quarter. Make it sound genuinely worried."
The AI produces something like this in seconds:
Would you click that link? Honestly? Most people would. There is no typo. No strange phrasing. No shouting in capitals. It reads exactly like a real internal email. And that, right there, is the problem.
๐ Attack #2: They Already Know Your Schedule
Here is where it gets properly creepy. Before AI, researching a single target โ say, a company's Finance Manager โ required hours of manual work. Scrolling through LinkedIn. Reading old tweets. Checking company press releases. Very tedious. Only the most motivated attackers bothered for most targets.
Now an attacker feeds an AI tool your name and company. The AI automatically scrapes everything: your LinkedIn connections, your recent conference appearances, your public Instagram posts, any media mentions, your company's press releases, even your comments on industry forums.
The result? An email that lands in your inbox saying:
You did speak at that summit. You did talk about API security. The "colleague" who sent this feels real. The report is malware.
This technique is called spear-phishing. AI has made it available to every attacker on the planet, at zero extra cost per target.
๐ค Attack #3: Your Boss's Voice Is Now a Weapon
In 2019, a British energy company received a call from what sounded exactly like the CEO of their German parent company. His accent, his speech patterns, even his "slight German lilt." He needed an urgent wire transfer to a Hungarian supplier. โฌ220,000. Confidential, naturally.
The British manager transferred it. The CEO had never called. An AI voice cloning tool had listened to roughly three seconds of the real CEO speaking โ probably from a YouTube interview or a public earnings call โ and replicated his voice.
That was 2019. Today's voice cloning tools need even less audio and produce results that are essentially indistinguishable from the real thing.
In 2024, someone tried this on Ferrari's CFO โ impersonating Ferrari's CEO via WhatsApp using a cloned voice. The CFO became suspicious and asked a question only the real CEO would know. The attacker panicked and ended the call. Ferrari was saved by one suspicious question. Most companies aren't that lucky.
The Hong Kong case at the start of this article took it even further โ not just voice, but full video deepfakes of multiple people, live on a Zoom-style call. All fake. All convincing enough to authorise a $25.6 million transfer.
๐ฌ Attack #4: The Chatbot That Won't Let You Go
Old phishing was a one-shot deal. You received an email, you either clicked or you didn't. If you were sceptical and replied with a question, the attacker had to manually write back โ which was slow, inconsistent, and often gave them away.
Now, cybercriminals deploy AI-powered chatbots on fake tech support pages, via SMS, and on WhatsApp.
Imagine you get a text: "Your Apple ID has been locked due to suspicious activity. Chat with our support team immediately." You click the link. A chat window opens. You type: "Can you verify who you are before I give you anything?"
The AI chatbot responds instantly: "Absolutely โ your verification is our priority. For your security, I'm not able to display your full account details here. But once you confirm your Apple ID email and we send you a reset code, I can walk you through restoring your full access within 5 minutes."
That response sounds completely reasonable. It addresses your concern, it uses security language, and it keeps nudging you toward handing over your credentials. If you push back again, it has another plausible answer ready. It never gets frustrated. It never makes a mistake. It keeps going as long as you do.
โ ๏ธ Attack #5: WormGPT โ AI With No Conscience
You might wonder: can't attackers just use ChatGPT for all this? The answer is mostly no โ mainstream AI models like ChatGPT and Gemini have safety guardrails. Ask ChatGPT to "write a phishing email to steal bank details" and it will politely decline, probably with a little lecture about ethics thrown in.
The cybercrime underground found the solution: build their own.
WormGPT appeared on dark web forums in 2023. It is a large language model โ similar in concept to ChatGPT โ but trained specifically to help with cybercrime. It has no safety filters. No ethical boundaries. No refusals. Ask it to write a Business Email Compromise template targeting a specific bank? Done. Write convincing malware code? Sure. Draft a phishing campaign for 10,000 targets in five different languages? Give it a moment.
It sold for roughly $100 per month. Subscription software for hackers who want to outsource their thinking to AI.
FraudGPT followed โ advertised explicitly as "without limitations" and "tailored for fraud." These tools lower the barrier so dramatically that a teenager with no technical knowledge can now launch sophisticated social engineering attacks that previously required years of expertise.
๐ Old Phishing vs. AI Phishing โ Spot the Difference
| What Changed | Old Phishing (Pre-AI) | AI-Powered Phishing (Now) |
|---|---|---|
| Email Quality | Broken grammar, obvious typos | Flawless, indistinguishable from real corporate email |
| Personalisation | Generic "Dear Customer" | References your name, recent conference, your colleague's name |
| Research Time | Hours per target | Seconds per target, automated |
| Scale | Quality OR volume โ not both | Quality AND volume simultaneously |
| Voice Attacks | Rare, obvious, easy to detect | Cloned voices from 3-second audio clips |
| Video Attacks | Almost impossible | Real-time deepfake video calls |
| Victim Responses | Manual, slow, gave attackers away | Instant AI chatbot, never gets caught off guard |
| Skill Required | Moderate technical knowledge | Minimal โ just a subscription to WormGPT |
๐ฐ Real Attacks That Already Happened
๐ก๏ธ How to Protect Yourself โ The Practical Guide
The good news: you don't need to be a cybersecurity expert to defend yourself. You need a handful of habits that become instincts. Here they are:
โ๏ธ The Good Guys Are Using AI Too
It is not all bad news. Cybersecurity firms are fighting back with AI of their own.
AI-powered email filters now analyse thousands of signals per email โ the sender's address history, the writing patterns, the links embedded, even the metadata โ and flag suspicious messages before they reach your inbox. Companies like Microsoft and Google have built AI threat detection directly into their email platforms.
Deepfake detection tools are being developed that analyse subtle inconsistencies in video โ unnatural blinking, pixel-level artifacts, audio-video sync issues โ that humans cannot perceive but AI can flag. Banks are deploying AI that detects unusual transaction patterns and pauses suspicious transfers automatically.
But here's the honest part: attack AI and defence AI are locked in an arms race. Each time defences improve, attackers retrain their models to bypass them. The tools get better on both sides simultaneously. Which means the human in the middle โ you โ remains the most important variable.
๐ฏ The Bottom Line
That Arup employee in Hong Kong was not stupid. He was not careless. He was a professional, doing his job, who encountered an attack that was engineered specifically to defeat every instinct he had. The voices sounded right. The faces looked right. The context felt right. Everything was wrong.
AI has not made cybercriminals smarter. It has made them faster, cheaper, and scalable. The Nigerian prince could only fool one person at a time. Today's AI-powered attacker is running the same operation on ten thousand people simultaneously, each attack perfectly tailored to its target.
Your best defence is no longer your ability to spot bad grammar. It is your willingness to pause, verify, and question urgency. One extra phone call. One question only the real person would know. One moment of "this feels weird, let me double-check."
That one moment is what stopped Ferrari's CFO from losing millions. It is the one skill no AI can train out of you โ if you choose to use it.
Stay sceptical. Stay slow. That is literally all it takes.