AI supercharges the cyber hacker’s toolkit
In 2025, a North Korean hacking group called PutridSlug used deepfake video and audio to pose as company executives during Zoom calls, in order to trick tech employees into downloading malicious code.
The efforts marked an example of extreme social engineering — where attackers psychologically manipulate people to dupe them into performing actions or divulging sensitive information — in this case, allowing them to conduct financial theft.
Wielding new AI tools to generate hyper-realistic fake personas or clones of existing people, hackers are increasingly able to gain unauthorised access to private data and otherwise secure environments.
According to Cloudflare’s 2026 threat report, PutridSlug is one of three North Korean hacking groups that have now “industrialised” the use of generative AI in this way.
“Social engineering works because it exploits the same human pressures it always has: urgency, authority, trust, fear and confusion, generating emotive knee-jerk responses,” says Matthew Lloyd Davies, principal cyber security author and researcher at tech education platform Pluralsight.
But, he adds, AI has “changed attacker economics”, by making it cheaper and easier to carry out sophisticated attacks.
Gone are the days of broad, opportunistic efforts using clunkily written emails laden with spelling mistakes and jarring cultural errors. Instead, large language models and generative text tools can help attackers scale outreach that is personalised and compelling, at a lower cost than ever before.
By scraping from LinkedIn, company websites and other public filings, attackers can then generate highly customised emails that might trick a user into clicking on a malicious link — a tactic known as phishing.
Even hackers who are not technologically savvy are able to wield AI coding assistants to analyse stolen data and build victim profiles to then target people.
We have officially crossed the threshold where a live video call is no longer proof of lifeDavid Warburton, F5 Labs
We have officially crossed the threshold where a live video call is no longer proof of life
According to data from security group DeepStrike, phishing attacks rose by 1,265 per cent in 2025, attributed to the growth of generative AI tools.
“Attackers know your organisational chart, your vendors and your executives’ communication styles before they send a single message,” says Douglas Wadkins, chief technology officer at network group Opengear.
“The more important shift is how AI is helping attackers industrialise the back office of fraud operations,” says Gabriel Bernadett-Shapiro, a senior AI research scientist at cyber security group SentinelOne. “The notable pattern is the use of AI across the entire fraud supply chain.”
On top of phishing emails, AI is supercharging the creation of more sophisticated scams that use deepfakes — cloned or faked voices and visuals. This includes so-called celeb bait, creating fake adverts featuring AI-generated clones of celebrities to manipulate victims, all the way through to a fake applicant appearing in manipulated video interviews for a remote job, in order to get inside a company’s systems.
“We have officially crossed the threshold where a live video call is no longer proof of life,” says David Warburton, director of the threat intelligence arm of security group F5. “Threat actors are executing flawless, real-time corporate espionage and identity fraud directly over platforms like Zoom.”
Cyber analysts note a rise in hackers creating entire personas with backstories, or so-called synthetic identities, in order to later carry out fraud or espionage.
“Social engineering is shifting towards identity as its primary target, and synthetic identities are emerging as one of the most complex threats to defend against,” says Gus Tomlinson, chief product and technology officer at identity verification group GBG. These identities might “open accounts, build histories and accrue trust”, she adds.
Recommended
According to Opengear’s Wadkins, there is also a trend towards multi-vector attacks. “Rather than a single email, threat actors combine SMS, messaging platforms, and follow-up voice calls to build credibility before the malicious request arrives,” he says. “The attack unfolds over days or weeks, making it much harder for employees to recognise the manipulation in real time.”
For companies, the challenge appears existential. “The real risk isn’t simply that people believe fake content. It’s that they begin to question genuine content as well,” says Amit Sinha, chief executive at digital security company DigiCert. “Once people lose confidence in the authenticity of the information they’re receiving from an organisation, every interaction requires an extra layer of verification.”
But defenders are themselves wielding advanced AI tools to help root out attacks. According to Tomlinson, some organisations concerned about fake identities are now using advanced “liveness detection” systems, which analyse “subtle biological signals such as micro-texture variations and the way light reflects off the face” to confirm whether someone is real or not.
On top of biometric indicators, other contextual data can help make an assessment, such as “the cadence of typing, the way a device is handled”, he adds.
Matthew Ferraro, a partner specialising in cyber security at law firm Crowell & Moring, argues that businesses must also educate their staff and adopt a “zero trust” framework where all important requests, such as financial transfers or password resets, require human verification. Executives, finance teams and their family members should also establish “pre-established passphrases” to confirm each other’s identity, he says.
Leadership teams should rehearse these scenarios, run cyber crisis exercises and simulations of attacks that include AI-enabled social engineering, agrees Adam Finkelstein, a managing director of disputes and investigations at consultancy Alvarez & Marsal. “In our experience, preparation is the difference between a contained incident and a business crisis.”
“The human vulnerability hasn’t changed, but the attack has,” says David Maimon, head of fraud insights at software company SentiLink and a professor at Georgia State University. “Train your people to pause before they act, and verify through a channel they trust independently. The scam only works if you move fast.”
But Darren Meyer, security research advocate at IT security company Checkmarx, argues that “no amount of security training fixes this issue”. Instead, he adds, companies need to draw up ways to reduce the fallout of an inevitable social engineering campaign, including “creating proactive controls” to limit the impact of attacks.