How AI Is Changing the Crimes That Succeed Against Organizations

Generative AI is raising success rates on fraud, impersonation, and intrusion by making those attacks cheaper and harder to dismiss as fake. The FBI now tracks AI-linked internet crime as its own category.

In 2025 the FBI’s Internet Crime Complaint Center recorded 22,364 complaints that referenced artificial intelligence, with reported losses of nearly $893 million. That was the first dedicated AI section in nearly 25 years of IC3 reporting, inside a year when Americans reported nearly $21 billion in internet crime losses overall (FBI). The AI total is a floor. It counts only what victims noticed and reported as AI-related.

Video-conference impersonation has already produced eight-figure corporate losses. INTERPOL said in 2026 that artificial intelligence was enabling 55 percent of reported cybercrimes across Africa. That is why this sits on the CISO and CFO agenda now.

What counts as AI-enabled crime

AI-enabled crime is ordinary criminal tradecraft that uses machine-generated text, speech, images, video, code, or targeting data to raise hit rates or cut the skill needed to run the attack. It is not one offense. It cuts across investment fraud, business email compromise, romance scams, ransomware, employment scams, and forged identity documents.

A phishing email written by a large language model is still phishing. A ransomware affiliate that uses a coding assistant to debug an encryptor is still running ransomware. The production function changed. Content that once needed a native speaker, a designer, or a malware author can be generated, iterated, and localized in minutes.

Two mix-ups are common. The first is treating AI as an autonomous attacker that independently picks victims. Most cases still have a human operator choosing targets, moving money, and handling cash-out. The second is using “deepfake” as a synonym for all AI crime. Deepfakes, synthetic audio or video that impersonates a real person, are one high-impact subset. LLM-written lures, fake identity documents, cloned websites, and AI-assisted malware sit in the same family without always involving a fabricated face.

From the criminal’s side, the job these tools do is conversion. Traditional BEC failed when grammar, timing, or a mismatched voice gave the scheme away. Generative models reduce those tells and raise volume: more lures, more languages, more personalized pretext, without a matching increase in headcount.

How the attacks actually run

The mechanism is a pipeline.

Inputs are public and stolen material. Earnings-call audio, LinkedIn photos, voicemail, names from a compromised mailbox, and open-source code all feed models. A short voice sample can support a clone that survives a phone call. A handful of stills can support a talking-head video that holds up on a compressed conference link.

Process depends on the crime. For social engineering, an operator drafts a pretext with an LLM, then uses voice or video synthesis at the moment of pressure, often after email or chat has already set context. For document fraud, image models produce passports, bills, or selfies that pass a weak KYC check if liveness detection is thin. For intrusion, coding assistants help write loaders, obfuscate scripts, and generate kits. TRM Labs described AI entering ransomware at three stages in its 2026 AI-in-Crime Adoption Index: how attacks are built, how they are executed, and how proceeds are cashed out.

Outputs are what victims see. A fluent email from “finance.” A meeting full of apparent executives. A job-interview avatar. A celebrity selling a crypto product. Malware that looks less handmade.

Cash-out still runs through wires, mules, and cryptocurrency, which is why tracing on the money side belongs in the same incident as the deepfake lure. The case that still shows up in board packs is Arup in January 2024. A Hong Kong employee joined what appeared to be a video call with senior colleagues, including a deepfake of the CFO, and authorized 15 transfers totaling about $25.6 million (CNN). Nothing in that attack broke encryption. It broke a human who believed the people on the call were real.

The control points are narrow: whether the media is authentic, whether the request is authorized on a second channel the attacker cannot occupy, and whether a high-value transfer can complete on the strength of a meeting alone.

What is already in production, and what is not

Current, meaning visible in 2025 and 2026 caseloads: AI is an official U.S. internet-crime reporting category. The FBI described fake social profiles, voice clones, forged identification, and videos of public figures, and placed AI-related complaints among the costlier subsets of a nearly $21 billion year. Phishing still leads complaint volume. AI is raising the quality of those lures rather than replacing the category.

Law enforcement outside the United States is measuring share, not just anecdotes. INTERPOL’s 2026 Africa assessment tied AI to more than half of reported cybercrime, citing speed, scale, and detection difficulty, against more than 1.1 billion mobile subscribers recorded in 2025.

Emerging over the next 12 to 24 months is AI-assisted malware development, and voice phishing aimed at taking over single sign-on. TRM Labs’ ransomware finding cuts against a common story. AI is collapsing the skill and time needed to build and run an intrusion, but TRM reported that total ransom payments were roughly flat-to-down in 2025 even as the number of variants rose. The method is changing faster than the payouts.

Europol titled its 2026 Internet Organised Crime Threat Assessment around encryption, proxies, and AI expanding cybercrime together. AI improves the lure and the tooling. Proxies and encryption still hide the operator.

Speculative: crime agents that select victims, negotiate ransoms, and cash out with no human in the loop. Treat conference demos as demos.

Questions to ask before treating this as ordinary phishing

Will a video call still count as identity verification for a high-value transfer?

The organization should ask whether a live-looking conference is still accepted as proof that a senior officer authorized money movement.

A useful answer is no, not by itself. A video meeting is now an untrusted channel for payment authorization, the way email became untrusted for wire instructions after BEC matured.

Synthesis models operate on compressed audiovisual streams. Artifacts that are obvious on a studio monitor disappear on a laptop call. The Arup pattern combined multi-person presence, urgency, and a finance employee already primed by a message. Dual control that still lives inside the same call, with a second synthetic participant agreeing, does not close the gap.

Evaluate payment policies that require a pre-registered callback to a known number, dual approval inside the treasury system, and holds on new beneficiaries. Check whether those controls fire even when the request appears to come from the CFO on camera.

How will incidents be labeled when AI was involved?

Ask whether tickets, insurance notices, and board metrics can separate AI-assisted cases from conventional social engineering.

Most organizations cannot. The FBI’s nearly $893 million is an undercount of complaints that mentioned AI. If internal records only say “BEC” or “vishing,” funding will follow the old label, not the failed control.

The human failure is often identical: someone approved a transfer. Evidence of AI lives in the media, cloned audio, meeting recordings, synthetic ID images. If those artifacts are not retained, attribution is guesswork. Look for an incident taxonomy that captures lure medium (email, voice, video, KYC image), whether media was kept, and whether a second factor independent of that medium existed.

Does AI-written malware change what endpoint detection is for?

Ask whether “AI malware” is being used as a reason to replace EDR, or as a reason to measure detection on new variants.

A grounded answer is that AI changes the volume and polish of commodity tooling more than it creates a new undetectable payload class. Treat it as faster variant production. TRM’s 2026 index argued that AI is altering how ransomware is built and run without yet rewriting payment totals. More variants mean more hash diversity. Behavior-based detection, identity telemetry, and backup integrity matter more than counting named families.

Ask the SOC how quickly a new packer or lure kit from the last quarter was covered, and whether success is still scored mainly on known ransomware names.

Who is allowed to publish executive voice and video?

Ask which high-value voices are treated as public training data.

Public executive audio and video are now source material for clones. Earnings calls, all-hands recordings, and high-resolution headshots are exactly the samples models want. Voice and face models improve with clean, multi-sentence, multi-angle audio and video. Marketing and investor-relations teams are rewarded for producing those samples.

Inventory CFO, CEO, treasury, and help-desk voices. Restrict unpublished internal recordings where that is practical. This does not stop a determined clone. It raises the cost.

Who is building the response

Defensive activity is lining up along the same pipeline as the crime.

One approach is media authentication: detecting synthetic audio and video, or attaching provenance to real recordings. Another is identity proofing at onboarding and at high-risk actions, including liveness checks that a replayed video should fail. A third is process redesign in finance and IT so that no single channel can both request and approve money or access. A fourth is financial-crime intelligence on cash-out, especially cryptocurrency.

Detection without a payment hold still loses the wire. A strong KYC check does not stop an employee who believes the CFO is on the call.

TRM Labs is publishing structured analysis of AI adoption inside cybercrime and ransomware cash-out. Public baselines for volume and loss are coming from the FBI, INTERPOL, and Europol rather than from vendor ROI slides.

Microsoft’s identity and email security stack is still where many enterprises catch the first lure, because BEC and vishing often start as a mailbox or Teams message. OpenAI and Google sit on a different layer: abuse reporting, rate limits, and refusals on impersonation and cybercrime prompts. Those controls leak. Operators use uncensored local models and stolen API keys. Provider-side limits change the average case more than the determined one.

Specialist identity and liveness vendors occupy KYC and contact-center traffic, where synthetic IDs and cloned voices hit onboarding and password reset. The buying question is whether a product scores a file after the fact or interrupts a live session before money or access moves.

A one-hour next step

Skip a branded “AI crime program.” Map the three highest-value actions that still treat a call, a video meeting, or a well-written email as proof of identity.

Write them down: a wire to a new beneficiary, an MFA reset, a vendor bank-detail change. For each, name the channel that currently authorizes it, and name one channel the attacker cannot occupy at the same time. If the answer is the CFO on a video call, or a voice call to the help desk, that path belongs in the same risk class as an unsigned email wire request did a decade ago.

Then put treasury and the SOC on one question: in the last 12 months, which incidents involved retained audio or video, and would the payment still have gone out if the meeting had been treated as untrusted.