Article illustration

Fraud and cyber crime - how much worse can it get?

A perspective on how digital transformation and generative AI widen both business opportunities and fraud risks, and why defenders need to keep learning.

6 min read

Digital transformation cuts both ways

Digital transformation is among the main strategic initiatives for all companies and, justifiably, at the top of their priorities. Digitizing analog information and digitalizing current processes is no small feat and has delivered substantial tangible benefits, such as accessing data across organizations faster and more cheaply than ever before and measuring and monitoring operations, sometimes even in real time.

But given the scale of fraud and cybercrime, it's hard not to see 1 that the same thing that provides many tangible benefits to an organization also opens new attack vectors for people with nefarious intentions. Digital information can be accessed, moved/stolen in volumes no one could with physical records. Such data can be used to be sold to the highest bidder and, in worst-case scenarios, could even lead to bankruptcy.

Consumer Sentinel Network reports by type, 2002-2022 (FTC).
Figure 1: Consumer Sentinel Network reports by type, 2002-2022 (FTC). 1

People exposed to fraud and cybercrime, or those who "handle" it across diverse organizations, understand that digital technology is a major fraud enabler, while the countering technology to eliminate current fraud and cybercrime trends is still trying to catch up and offers only partial mitigation. Moreover, terms like democratization in technology mean that more and more non-technical people, or even laypeople, can use technology without extensive training or formal education.

It is similar in education. Here, we formally still follow the same conventional paradigm - passing through grades with a standardized curriculum- while in the digital space, this concept is quickly becoming obsolete. Knowledge is not restricted to those attending school. It is available, and most of it is free. Similarly, as in the paragraphs above, while it provides many benefits (educating children and people in general, especially in areas where knowledge wouldn't otherwise be available), we can't ignore the negative aspects that come hand in hand. Knowledge always was, is, and will be power. And not always the power to do good.

Generative AI lowers the barriers

Very few (me included) believed that AI could easily step into the domain of art and creative professions, as they require "human creativity," which can't be easily translated into algorithms, and yet, one of the first instances of AI we saw in this area were use cases linked to images and graphics. Early applications included web-based AI tools that erase unwanted parts of a picture, upscale low-quality photos of your grandparents, expand/outpaint a picture, or create a seamless transition between two different images 2. Today you can ask the algorithm to generate an image based on your descriptive text input in a desired graphical style and combine it with your pictures or photos (like the one at the top of this article - a hand with six fingers - created by Midjourney AI).

An example of AI outpainting between existing artworks.
Figure 2: An example of AI outpainting between existing artworks. 2

A few weeks back, we saw the world-changing (at least in terms of media attention and social-network hype) event of ChatGPT's release. Even with its practical boundaries, which come from the underlying technology, it's clear it will reshape many industries 3.

Goldman Sachs chart of industry exposure to potential AI automation.
Figure 3: Goldman Sachs chart of industry exposure to potential AI automation. 3

You might be asking: How does it relate to fraud and cybercrime? I believe digital transformation and the democratization of tools, technology, and knowledge will follow the same pattern described above. AI assistants will be integrated into our various tools, like email clients, time management apps, MS Teams, etc. 4 New specialized assistants will be created for specific use cases like healthcare 5, finance 6, and many others. Within a few weeks, we have seen adoption and modifications to scale down or optimize the ChatGPT-like assistants to fit into the memory of our standard PC or even wearables and IoT devices 7.

We may have already felt that the advancements were coming too fast, and we struggled to keep up with all the changes. These last few weeks have been a preview of what's to come. I'm sure most people are already looking forward to this future. The future, where knowledge couldn't be any closer to any individual. Some will immediately explore how to exploit this new future for their own benefit.

When useful assistants create new risks

Imagine an AI integrated into a cyber-security platform 8 with complete oversight of what is happening (SIEM, IDS, EDR, EDX, and others). An assistant you can task to consolidate available data and generate a report of incidents and their resolution. An assistant who can notify you of new vulnerabilities and their impact on your organization. I'm sure you have many more applications in your mind, but have you thought about the possibility that such an assistant can be asked what would be the best way to breach the current security perimeter, which attack vector would be least visible, or which way to exfiltrate the sensitive data, knowing your internal IT landscape and IT assets as well as the technology deployed? Or which user failed the most phishing attempts or got the most antivirus alerts within the finance department?

Imagine an assistant that can optimize the company's logistics and operations based on current inventory data and the usage/expenditure of components, parts, and raw materials in production, along with the production plan. Now imagine someone asking the same assistant how to run the most efficient supply chain attack.

Finally, imagine an assistant trained on the best-performing companies' data to support top-level managers' critical decisions. We don't even have to go to the future, as since last August, there is already an AI-based CEO - Mrs. Tang Yu 9.

A historical comparison of NetDragon Websoft and the Hang Seng Index.
Figure 4: A historical comparison of NetDragon Websoft and the Hang Seng Index. 9

Fraudsters do not need your permission

The above examples might make you think that not adopting the technology internally might mitigate the risk sufficiently - at least in these early days. But it doesn't end there.

Imagine groups (independent APT groups or even state-sponsored ones) that can train a cyber-specific model. Such a model can focus on collecting and consolidating information from publicly available sources (OSINT). How authentic will the new spear-phishing email look when the model generates it based on the social network profiles of the head of the finance department? How authentic will it look when it considers public information and partnership announcements to write a Business Email Compromise email leveraging a database of leaked email credentials or mobile numbers?

How efficient would such an assistant be in advising the hackers on the best possible targets for spear phishing or even on the shortest path to exploitation, considering all the publicly available information about the organization - used technologies and associated known vulnerabilities?

Keeping pace with the threat

A Spider-Man comic panel linking power with responsibility.
Figure 5: A Spider-Man comic panel linking power with responsibility.

As Stan Lee wrote in 1962 in Spider-Man comics through the character of Uncle Ben: "With great power comes great responsibility."

This new technology and its adoption across businesses and our lives will bring many challenges and risks. Some voices oppose its wide adoption without proper risk assessment (as is already happening 10), but, as Bloomberg states, it may be too late now, as the technology is already out there. Governments, companies, and academics will further develop guiding principles to mitigate abuse of this technology. However, fraudsters and cyber criminals will get their hands on it and exploit it without any hesitation or moral limits. Immediately.

For us - people trying to fight against these criminals - we must prepare ourselves, primarily through self-education and upskilling, to ensure our capabilities and prowess are at par with theirs, if not above.

References & Further Reading

  • [1] Consumer Sentinel Network Data Book 2022

    2022 consumer-report data, published in February 2023. Reports are not a population survey or a measure of all cybercrime.

    by Federal Trade Commission · February 2023

  • [2] Merging art with AI

    DALL-E 2 outpainting demonstration connecting existing artworks. Original video link retained; publication date not confirmed.

    by Orb Amsterdam

  • [3] The Potentially Large Effects of Artificial Intelligence on Economic Growth

    Figure 3 reproduces the US panel of Exhibit 5, page 7. The link opens Goldman Sachs' April 5, 2023 public overview of the research, not the original report PDF. Estimates concern potential task automation, not observed job losses.

    by Joseph Briggs and Devesh Kodnani; Goldman Sachs Global Investment Research · March 26, 2023

  • [4] Microsoft to integrate ChatGPT into Teams

    Tech Monitor report on Teams Premium meeting summaries and tasks powered by OpenAI language-model technology.

    by Ryan Morrison · February 2, 2023

  • [5] What does ChatGPT mean for Healthcare?

    News-Medical overview, reviewed by Emily Henderson. Discusses potential uses and limitations, not proof of clinical effectiveness. Date is the publisher's last-updated/citation date.

    by Sarah Moore · March 28, 2023

  • [6] Introducing BloombergGPT, Bloomberg’s 50-billion parameter large language model, purpose-built from scratch for finance

    Bloomberg's announcement of its finance-specific language model. Supporting research: BloombergGPT: A Large Language Model for Finance, arXiv:2303.17564.

    by Bloomberg L.P. · March 30, 2023

  • [7] How to Locally Run a ChatGPT-Like LLM on Your PC and Mac

    Beebom desktop tutorial. The current page was updated after this 2023 article; it supports local PC/Mac use, not the separate wearables/IoT assertion.

    by Arjun Sha · Updated October 15, 2025

  • [8] Microsoft introduces an A.I. chatbot for cybersecurity experts

    CNBC report on the private-preview launch of Microsoft Security Copilot. The article's malicious-use scenarios are the author's analysis, not demonstrated product capabilities.

    by Jordan Novet · March 28, 2023

  • [9] Meet 'Tang Yu', the first AI CEO of a company

    Showmetech coverage of Fujian NetDragon Websoft's virtual CEO and historical stock comparison. The displayed date is later than comments on the page, so it is not confirmed as the original publication date. Stock performance alone does not establish an AI management effect.

    by Gilmar Faria · June 30, 2023 (current page date)

  • [10] Elon Musk Wants to Pause AI? It’s Too Late for That

    Bloomberg Opinion column, also published by Bloomberg Law. Commentary on the proposed pause and already-deployed technology; not a research finding. Full access may require a subscription.

    by Parmy Olson · March 30, 2023

Continue reading

All articles →
Cyber

Fear Not The AI, But The Automation!

Automation magnifies both useful work and human mistakes. Historical incidents illustrate why speed, connected systems and weak oversight need practical safeguards.

April 16, 202513 min read

Responses (0)

Join the conversation

Responses are available to read. Reader sign-in is temporarily disabled.

Responses

Loading responses…

Article image

Loading image…