01 logo

The Dark Side of Generative AI in Cybercrime.

Cyber crime.

By DDM ATIQ Published 5 months ago 8 min read
Cyber attack

‎The Dark Side of Generative AI in Cybercrime ‎ ‎How ChatGPT, Deepfakes, and AI Tools Are Revolutionizing Digital Crime ‎ ‎We hear a lot about the wonders of generative AI. ChatGPT writes our emails. Midjourney creates stunning artwork. Sora generates hyperrealistic videos from text prompts. Businesses use these tools to save time, cut costs, and unlock creativity. It feels like magic. ‎ ‎But here is the uncomfortable truth that no one wants to talk about at those shiny tech conferences: the exact same tools that make your life easier are making a cybercriminal's life even easier. ‎ ‎While you are using AI to draft a birthday card for your aunt, someone on the other side of the world is using generative AI to drain bank accounts, destroy reputations, and dismantle companies. And they are getting frighteningly good at it. ‎ ‎I have spent years covering cybersecurity, and I have watched threats evolve from clumsy Nigerian prince emails to sophisticated, personalized attacks that would fool almost anyone. But the rise of generative AI has accelerated this transformation in ways that keep me up at night. Let me walk you through exactly what is happening, because the first step to protecting yourself is understanding what you are up against. ‎ ‎The Death of the Obvious Phishing Email ‎ ‎Remember the old phishing emails? The ones with subject lines like "URGENT: Your Account Has Been Compromised" and sentences riddled with spelling errors like "pleese click the link to varify your information"? They were almost comically bad. Only the most vulnerable or distracted people fell for them. ‎ ‎Those days are over. Permanently. ‎ ‎Generative AI has killed the telltale signs of phishing. A cybercriminal no longer needs to speak fluent English or even understand basic grammar. They simply feed a prompt into an AI model: "Write a convincing email from my bank asking me to verify a suspicious transaction." What comes out is flawless. Perfect grammar. Natural phrasing. No red flags. ‎ ‎But it gets worse. Much worse. ‎ ‎AI can now scrape your social media profiles, your company's website, your LinkedIn connections, and even your public posts to craft hyper-personalized attacks. Imagine receiving an email that mentions your recent vacation to Italy, references your boss by name, and includes a seemingly legitimate attachment related to a project you are actually working on. That is not a lucky guess. That is generative AI doing what it does best: pattern recognition and personalized content generation. ‎ ‎Security firm Darktrace reported that in 2024 alone, AI-powered phishing attacks increased by over 4,000% compared to pre-AI levels. Four thousand percent. Let that number sink in. ‎ ‎--- ‎ ‎Deepfakes: When Seeing Is No Longer Believing ‎ ‎We have all seen the videos. Tom Cruise playing ping pong badly. Barack Obama calling Donald Trump a "total dipshit." Keanu Reeves doing weird things with his face. They are funny. They are entertaining. And they are training us to believe that deepfakes are harmless parlor tricks. ‎ ‎They are not. ‎ ‎Generative AI has reached a point where creating a convincing deep fake requires nothing more than a few minutes of someone's voice or a handful of photographs. Free, open-source tools are widely available on GitHub. And cybercriminals are using them to commit fraud on an unprecedented scale. ‎ ‎Let me give you a real example. In early 2024, a multinational engineering firm lost $25 million. How? An employee in the finance department received a video call. On the screen was the company's CFO, along with several other senior executives. The CFO gave a direct, urgent instruction: transfer funds to a new supplier immediately to complete a confidential acquisition. The employee did as they were told. ‎ ‎The CFO and the executives were not real. They were deepfakes. The entire video call was fabricated using generative AI. The employee saw their boss's face, heard their boss's voice, and watched them interact naturally with other fake colleagues. Every defense mechanism the human brain has—trusting what we see, believing what we hear—was weaponized against them. ‎ ‎This is not science fiction. This is happening right now. And the technology is only getting better. ‎ ‎ ‎AI-Generated Malware: The Rise of Polymorphic Code ‎ ‎Traditional antivirus software works by recognizing signatures. When a piece of malware is identified, its unique code is added to a database. The next time that same malware tries to infect a computer, the antivirus says, "I have seen this before," and blocks it. ‎ ‎Generative AI has rendered this approach almost obsolete. ‎ ‎Cybercriminals are now using AI to write polymorphic malware—code that changes every single time it is deployed. Think of it like a shapeshifter. The malware's core function remains the same, but its digital fingerprint is constantly evolving. Antivirus software that relies on signature recognition is chasing a ghost. ‎ ‎Researchers at a leading cybersecurity firm recently demonstrated an AI tool that could generate thousands of unique, functional malware variants per minute. Each variant was different enough to evade detection but similar enough to carry out its malicious purpose. Traditional defenses simply could not keep up. ‎ ‎And here is the real kicker: you do not need to be a skilled programmer to do this. Generative AI has democratized malware creation. A teenager with a laptop and malicious intent can now generate sophisticated attack code by simply asking an AI chatbot to write it for them. Some AI models have safeguards, but they are trivial to bypass with basic prompt engineering. ‎ ‎--- ‎ ‎Voice Cloning: The Weaponization  of Trust ‎ ‎Your voice is unique. It is how your mother knows it is you on the phone. It is how your spouse knows you are really calling from the grocery store. It is a fundamental building block of human trust. ‎ ‎Generative AI can clone your voice with three seconds of audio. ‎ ‎Three seconds. ‎ ‎A voicemail greeting. An Instagram story. A video clip from a work Zoom call that someone recorded. That is all it takes. The AI analyzes your vocal patterns, your pitch, your cadence, your accent, and then it can make you say anything. Anything at all. ‎ ‎The "grandparent scam" has been around for decades. Someone calls an elderly person, pretends to be their grandchild in legal trouble, and asks for money to be wired immediately. These scams worked on some people, but the voice never quite sounded right. The accent was off. The phrasing was unnatural. ‎ ‎Now imagine that same call, but the voice is perfect. It sounds exactly like their grandchild. It uses their pet names. It references specific family memories scraped from social media. The elderly person has no reason to doubt. They hand over their life savings. ‎ ‎The Federal Trade Commission reported that voice cloning fraud losses exceeded $1 billion in 2025. And that is only what was reported. The actual number is almost certainly much higher. ‎ ‎ ‎AI-Generated Fake Identities: The End of Verification ‎ ‎Creating a fake identity used to be hard work. You needed fake documents, fake references, fake history. It was time-consuming and risky. ‎ ‎Now, generative AI can create an entirely fictional person with a complete life story, professional history, social media presence, and even realistic photographs in minutes. These are not crude cut-and-paste jobs. They are indistinguishable from real people. ‎ ‎Cybercriminals use these synthetic identities to open bank accounts, apply for credit cards, rent apartments, and even secure jobs at target companies. Once inside an organization—whether as a remote employee or a contractor—they have access to internal systems, sensitive data, and financial accounts. ‎ ‎One criminal network in Eastern Europe used generative AI to create over 200 synthetic identities. They used those identities to open bank accounts, which they then used to launder money from ransomware attacks. The accounts looked legitimate. The identities checked out. It took banks over a year to realize that none of these people actually existed. ‎ ‎ ‎Bypassing Biometric Security ‎ ‎Biometric authentication—fingerprint scanners, facial recognition, voice verification—was supposed to be the future of security. Unlike passwords, which can be stolen or guessed, your physical characteristics are unique to you. Or so we thought. ‎ ‎Generative AI is cracking biometric security wide open. ‎ ‎Researchers have demonstrated that AI can generate synthetic fingerprints that fool up to 80% of commercial fingerprint scanners. Deepfake videos can bypass facial recognition systems. Voice clones can defeat voice authentication for banking and customer service lines. ‎ ‎A recent experiment showed that an AI-generated deepfake could unlock a smartphone using facial recognition. The phone belonged to a journalist. The attacker had no physical access to the journalist. They simply trained the AI using photographs scraped from the journalist's public social media accounts. The phone unlocked on the first attempt. ‎ ‎Your face is not a secret. You post it on Instagram. You use it on LinkedIn. It appears in news articles and on video calls. Every time you share a photo, you are potentially handing a cybercriminal the key to your digital life. ‎ ‎ ‎What Can You Do? Practical Defenses ‎ ‎I have painted a grim picture, and I do not apologize for that. You cannot defend against a threat you do not understand. But there is good news: awareness alone is a powerful weapon. Here are practical steps you can take right now to protect yourself and your organization. ‎ ‎Establish verification protocols. Never trust a request for money, sensitive information, or password resets based on a single communication channel. If you receive an urgent email from your CEO, call them. If you get a panicked call from your child, hang up and call them back on a number you know is theirs. Use a code word with family members for emergencies. ‎ ‎Invest in AI-powered defenses.The irony is not lost on me: fighting AI with AI. Next-generation security tools use machine learning to detect anomalies that traditional signature-based antivirus misses. They look for behavioral patterns, not just known malware signatures. ‎ ‎Limit your digital footprint. Do you really need to post your birth date, your children's names, your pet's name, and your vacation plans on social media? Every piece of information you share publicly is ammunition for an AI-powered attacker. Lock down your privacy settings. Think before you post. ‎ ‎Train your people relentlessly. Technology will only get you so far. Human judgment is still your best defense. Regular, realistic phishing simulations that use AI-generated content will prepare your team for the real thing. Make security awareness part of your culture, not just an annual compliance checkbox. ‎ ‎Demand multi-factor authentication everywhere. Passwords are dead. Biometrics are vulnerable. Multi-factor authentication—requiring two or more verification methods—remains your strongest defense. Use authenticator apps, not SMS-based codes. Physical security keys are even better. ‎ ‎The Road Ahead ‎ ‎Generative AI is not going away. The cat is out of the bag, and no amount of regulation or ethical guidelines will put it back in. The same tools that empower artists, writers, and entrepreneurs also empower criminals. That is the dual-use nature of all powerful technology, from the printing press to the internet itself. ‎ ‎The question is not whether generative AI will be used for cybercrime. It already is. The question is whether we will adapt our defenses quickly enough to stay ahead. ‎ ‎I believe we can. But it requires a fundamental shift in how we think about security. We cannot rely on the old tells—bad grammar, suspicious links, obvious fakes. Those are relics of a simpler time. We must build systems and habits that assume deception is possible, that trust must be verified, and that the person on the other end of the screen might not be a person at all. ‎ ‎Stay vigilant. Stay skeptical. And for heaven's sake, hang up and call back. ‎ ‎If you found this article helpful, please share it with your colleagues and family. The more people understand these threats, the harder we make it for cybercriminals to succeed. Have you or your organization experienced an AI-powered cyberattack? I would love to hear your story in the comments below. ‎ ‎Written by DDM ATIQ ‎

tech newscybersecurityhackers

About the Creator

DDM ATIQ

ll

Enjoyed the story? Support the Creator.

Subscribe for free to receive all their stories in your feed.

Subscribe For Free

Reader insights

Comments

There are no comments for this story

Be the first to respond and start the conversation.

Sign in to comment
    Written by DDM ATIQ