How Hackers Use AI, and How to Protect Your Accounts
Documented cases show attackers using AI to speed up phishing and the hunt for software flaws. US agency CISA rates phishing-resistant sign-ins such as passkeys as the most secure form of MFA.
// geopolitics & security
How criminals use AI for phishing, deepfakes and voice-clone scams, how AI systems are attacked through prompt injection, and how passkeys and multi-factor authentication protect accounts.
This section covers the overlap between artificial intelligence and online security:
Reported losses are large and rising. The FBI's Internet Crime Complaint Center received 1,008,597 complaints in 2025, with reported losses of $20.877 billion, up 26% from 2024. Of those complaints, 22,364 referred to AI and carried losses above $893 million, according to the center's annual report. Verizon's 2026 breach report was released in May 2026. At organizations, it found that exploiting software vulnerabilities had overtaken stolen credentials as the most common starting point for a breach, at 31% of cases.
AI tools are targets as well as weapons. The software security nonprofit OWASP ranks prompt injection first on its 2025 list of the top 10 risks to applications built on large language models. In prompt injection, crafted input causes a language model to behave in unintended ways. The UK's National Cyber Security Centre said in December 2025 that such attacks may never be fully mitigated. Law enforcement and consumer agencies such as the FBI and the Federal Trade Commission are among the main players. So are security and standards bodies including CISA and NIST. The others are the FIDO Alliance behind passkeys, and the AI developers and security vendors that publish threat reports. Vendor figures are attributed as such. Coverage here is defensive. Attacks are described in enough detail to recognize and prevent them, and no further.