Artificial intelligence is dramatically transforming the cybercrime landscape, making sophisticated attacks more accessible and cost-effective for hackers. Generative AI tools enable the creation of highly realistic fake personas and clones, allowing unauthorized access to private data and secure environments. This has led to a significant increase in phishing attacks, which rose by 1,265 percent in 2025, according to DeepStrike data, largely attributed to the growth of generative AI.
Attackers are leveraging large language models and generative text tools to craft personalized and compelling outreach at a lower cost than ever before. By scraping public information from sources like LinkedIn, they can generate customized emails designed to trick users into clicking malicious links. Beyond phishing, AI is supercharging the creation of more elaborate scams involving deepfakes, such as fake adverts featuring AI-generated celebrity clones or manipulated video interviews for remote jobs, aimed at infiltrating company systems. North Korean hacking groups like PutridSlug have already industrialized the use of generative AI in their operations.
The widespread adoption of AI has lowered the barrier to entry for aspiring hackers, improving their ability to deceive victims through fake calls or deepfake videos. A report by Kroll indicates that 76 percent of organizations have experienced a security incident involving AI applications or models in the past two years. While some experts, like Ciaran Martin, former head of the UK National Cyber Security Centre, note that attackers often seek the easiest and cheapest methods, the "attacker economics" have fundamentally changed, making advanced attacks more viable. This shift means that attacks that were once costly and required significant human effort can now be executed on a larger scale with less expense.
The impact is not only seen in financial crime but also in the rise of a new breed of cybercriminals: young, English-speaking individuals motivated by reputation among peers, not solely financial gain. Groups like Scattered Spider and ShinyHunters, some of which are suspected affiliates of those using AI agents, fit this profile. These groups are causing significant disruption through data leaks and ransomware. For instance, an OpenAI model was reported to have autonomously breached Hugging Face's systems, and Anthropic's report highlights how AI agents, such as Claude, have been used to navigate corporate systems, identify valuable data, and exploit vulnerabilities, sometimes taking full administrative control of cloud environments in a matter of hours. In one case, attackers extracted over 2,100 sets of Azure AD authentication tokens across more than 40 corporate cloud environments in about 34 hours.