Scammers are using artificial intelligence to generate personalized fraudulent emails at a scale that was not possible before, and cybersecurity experts say the trend is accelerating. According to a report by CNET, the combination of AI content generation and a tactic called Phishing-as-a-Service has made these attacks more convincing and harder for filters to catch.
Phishing-as-a-Service provides ready-made templates to bad actors and lowers the technical skill required to run a scam. With AI generating the actual text, fraudulent messages can be tailored to specific individuals quickly and cheaply.
"From deepfake audio and video impersonation scams to highly polished phishing, smishing and email campaigns that exploit fear, urgency and trust, these AI-powered tactics are making scams more convincing and harder to spot than ever," said Abhishek Karnik, head of threat research at McAfee.
The personalization is a key part of what makes these scams effective. AI tools can scrape publicly available information about a target and use it to craft messages that appear to come from someone who knows them or their work. The more invested a target becomes in early exchanges, the more likely they are to miss warning signs when the scammer later sends a malicious link, attachment, or payment request.
Cybersecurity incident response analyst Taylor Peltzman said AI has not changed what scammers ultimately want, but it has made their operations faster and more adaptable. "AI can continuously rewrite messages, use legitimate services such as Google Drive or Microsoft 365, and construct multi-step attacks rather than relying on a single email," Peltzman said. "Organizations are more likely to trust links from widely used platforms, which makes these attacks harder to detect."
More sophisticated versions of these scams can push targets toward fake services, malicious downloads, or situations that result in identity theft and financial loss. Experts say the best defense is awareness of how these scams are structured, including the delayed delivery of suspicious content that comes only after a target has already engaged.
