Skip to content
DopeSwagYolo

// geopolitics & security

AI & Cybersecurity: Attacks, Scams and Account Protection

How criminals use AI for phishing, deepfakes and voice-clone scams, how AI systems are attacked through prompt injection, and how passkeys and multi-factor authentication protect accounts.

Latest in AI & Cybersecurity

What we cover in AI & Cybersecurity

This section covers the overlap between artificial intelligence and online security:

  • how criminals use AI to write phishing messages, clone voices and fabricate video
  • how AI systems themselves are attacked through techniques such as prompt injection
  • major data breaches
  • the protections that work for ordinary accounts, including passkeys and multi-factor authentication (MFA)

Reported losses are large and rising. The FBI's Internet Crime Complaint Center received 1,008,597 complaints in 2025, with reported losses of $20.877 billion, up 26% from 2024. Of those complaints, 22,364 referred to AI and carried losses above $893 million, according to the center's annual report. Verizon's 2026 breach report was released in May 2026. At organizations, it found that exploiting software vulnerabilities had overtaken stolen credentials as the most common starting point for a breach, at 31% of cases.

AI tools are targets as well as weapons. The software security nonprofit OWASP ranks prompt injection first on its 2025 list of the top 10 risks to applications built on large language models. In prompt injection, crafted input causes a language model to behave in unintended ways. The UK's National Cyber Security Centre said in December 2025 that such attacks may never be fully mitigated. Law enforcement and consumer agencies such as the FBI and the Federal Trade Commission are among the main players. So are security and standards bodies including CISA and NIST. The others are the FIDO Alliance behind passkeys, and the AI developers and security vendors that publish threat reports. Vendor figures are attributed as such. Coverage here is defensive. Attacks are described in enough detail to recognize and prevent them, and no further.

AI & Cybersecurity reference

AI & Cybersecurity: common questions

Can AI hack you?
Criminals use AI to make familiar attacks faster and more convincing, such as fluent phishing messages, cloned voices and fake videos. The FBI's Internet Crime Complaint Center received 22,364 complaints that referred to AI in 2025, with reported losses above $893 million. The main defenses are sign-in methods that resist phishing, such as passkeys, and confirming unexpected requests through a separate channel before acting.
Can AI hack 2FA?
Some forms of two-factor authentication can be bypassed, with or without AI. A 2022 CISA fact sheet says codes sent by text message or generated by an app can be phished through fake login pages. It says approval prompts can be abused by flooding users with requests. In May 2026, Google described an exploit, which it believes was built with AI, that bypassed 2FA on one administration tool. Passkeys and security keys built on FIDO standards are designed to resist phishing.
How do you spot AI voice scams?
Judge the request, not the voice. The FTC says a scammer needs only a short audio clip to clone a relative's voice. Red flags are demands to wire money, send cryptocurrency or buy gift cards. Hang up and call the person back on a number you know is theirs. The FBI also suggests agreeing on a secret word or phrase with family to confirm identity.
How can you tell if a video is fake?
Look for glitches, but do not depend on them. A December 2024 FBI alert said AI-generated images and video can show warped hands or feet, odd-looking teeth or eyes, and blurred or uneven faces. It said they can also show shadows that fall wrongly, lag and unnatural movement. The FBI also warned in July 2026 that AI-generated content is now often hard to identify. The check the FBI and FTC recommend is to confirm the request through a separate, trusted channel.

Sources

  1. 2025 IC3 Annual Report, Federal Bureau of Investigation, Internet Crime Complaint Center (IC3)
  2. Vulnerability exploitation top breach entry point, 2026 industry-wide DBIR finds, Verizon
  3. LLM01:2025 Prompt Injection, OWASP Gen AI Security Project
  4. Prompt injection is not SQL injection (it may be worse), UK National Cyber Security Centre
  5. Implementing Phishing-Resistant MFA, Cybersecurity and Infrastructure Security Agency (CISA)
  6. GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access, Google Cloud, Google Threat Intelligence Group
  7. FIDO Passkeys: Passwordless Authentication, FIDO Alliance
  8. Scammers use AI to enhance their family emergency schemes, Federal Trade Commission, Consumer Advice
  9. Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud, Federal Bureau of Investigation, Internet Crime Complaint Center (IC3)
  10. FBI Warns of Scammers Impersonating the IC3, Federal Bureau of Investigation, Internet Crime Complaint Center (IC3)