Cybercriminals have been using forms of artificial intelligence for decades. However, it is especially the most recent technologies—particularly those based on  Generative AI  and  Large Language Models (LLM)1  —that have radically changed the landscape in recent years. Today, anyone can fall victim to a scam, not only online but also offline, through phone calls, home visits, or other direct contact.

These technologies enable the creation of extremely realistic content while simultaneously automating scams on a large scale. Several researchers2 have identified three main pillars through which GenAI amplifies social engineering attacks:

  1. creating realistic content
  2. advanced targeting and personalization
  3. automated attack infrastructures

The types of artificial intelligence used vary depending on the type of scam and the stage of the attack.

The first phases: information gathering and profiling

In the initial phases – defining the target and gathering information – techniques such as:

  • AI scraping
  • AI automation
  • AI analysis

AI scraping (an advanced form of web scraping), combined with automation, enables the systematic extraction of information from websites, social media, public databases, and other sources. The collected data can include text, metadata, images, and videos.

AI analysis, on the other hand, allows identifying patterns within data, understanding context and sentiment, and building increasingly detailed profiles of potential targets.

The next stages: content and interaction

In the operational phases of the scam one most frequently finds:

  • Generative AI
  • Agentic AI
  • Chatbot AI  (or Conversational AI)

GenAI is used to create fake websites and portals, fake profiles, fraudulent emails, and even audio and video content. The level of realism achieved is now such that it’s increasingly difficult to distinguish authentic from fake.

AI-powered chatbots are able to not only simulate believable conversations but also personalize interactions based on the preferences, behavior, and even emotional state of the person involved.

A further evolution is represented by Agentic AI : a proactive technology capable of autonomously initiating actions and adapting responses in real time, without the need for constant human supervision. This type of AI can decide which communication channels to use, how to continue a conversation, and, in some cases, even deploy self-managed malware.

Even the “good guys” use AI

At the same time, AI-based fraud prevention and detection are also evolving rapidly. Today, tools exist that can detect deepfakes in voice, video, and images, verify the authenticity of documents and texts, and utilize advanced liveness detection systems.

AI is used, among other things, for:

  • anomaly detection , identifying behaviors that deviate from the norm
  • generation of synthetic data , useful for recognizing even rare or emerging scams
  • investigations and analysis , supporting analysts in managing large volumes of data
  • adaptive defense systems , capable of learning and anticipating new threats
  • Real-time detection and response , even within milliseconds

Thanks to these technologies, cybersecurity is evolving almost in step with the tools used by criminals.

The human factor remains central

Despite this, the human factor remains the most vulnerable link. Many citizens lack access to advanced protection systems and, above all, there is still a lack of widespread knowledge and awareness of how scams really work.

And it is precisely this point that it is essential to focus on: understanding how we think, who we trust, and why, in certain situations, we lower our defenses.

Further reading

If you’d like to explore some of the topics mentioned in more depth:

What Large Language Models (LLMs) really are
A clear and accessible explanation of the language models that power much of today’s generative AI.
👉 https://www.cloudflare.com/it-it/learning/ai/what-is-large-language-model/

How generative AI amplifies social engineering and phishing
An analysis of how AI-generated content makes scams more convincing, scalable, and highly personalized.
👉 https://doi.org/10.1007/s10462-024-10973-2

What AI data scraping is — and why it matters for scams
An overview of how AI systems can automatically collect and analyze large amounts of online data, and how this capability can be misused.
👉 https://www.miquido.com/ai-glossary/what-is-ai-data-scraping

Impostor scams and GenAI: what’s really happening
An in-depth look at how generative AI is fueling new forms of impersonation-based fraud.
👉 https://thepaypers.com/expert-opinion/genai-developments-in-2025-impact-regulations-and-the-rise-of-impostor-scams–1273127

The evolution of AI chatbots
How chatbots are becoming increasingly sophisticated, adaptive, and conversational.
👉 https://medium.com/@Quickway_Infosystems/the-evolution-of-ai-chatbots-whats-shaping-2025-and-beyond-70b3cd0715c8

Agentic AI and autonomous malware
An exploration of how agentic AI could transform the way malware is created, deployed, and managed.
👉 https://www.scworld.com/perspective/how-agentic-ai-will-drive-the-future-of-malware

AI and fraud prevention
How organizations are using artificial intelligence to detect and prevent fraud at scale.
👉 https://www.thomsonreuters.com/en-us/posts/corporates/technological-considerations-fraud-prevention/

What liveness detection is
A technology used to verify that a real person — not an image or a video — is present behind the screen.
👉 https://chekin.com/it/blog/liveness-detection-sicurezza-per-il-check-in-digitale/

AI for online fraud detection
A practical introduction to how AI systems are used to identify fraudulent activity in real time.
👉 https://datadome.co/learning-center/ai-fraud-detection/


  1. In simple terms, an LLM is a computer program that has been given enough examples to make it capable of recognizing and interpreting human language or other types of complex data ↩︎
  2. Schmitt, M., Flechais, I. Digital deception: generative artificial intelligence in social engineering and phishing. Artif Intell Rev 57, 324 (2024). https://doi.org/10.1007/s10462-024-10973-2 ↩︎