AI-Powered Attacks
Phishing and Social Engineering at Scale
GenAI removes the cost barrier to high-quality, personalized, multi-language phishing. Voice cloning enables vishing. Real-time deepfake video is operational for targeted fraud. The volume × quality curve has shifted permanently.
Deepfake Fraud Is Now a Board-Level Risk
The canonical case: in 2024, engineering firm Arup lost $25M when an employee joined a video call where every other participant — including the CFO — was a real-time deepfake. Since then, deepfake-enabled BEC has moved from novelty to standard tradecraft. The defense is procedural, not technological: out-of-band verification for payment changes, code words for executive requests, and treating video presence as weak authentication. This case is worth retelling to your own leadership because it converts "AI risk" from abstract to concrete.
Polymorphic and Adaptive Malware
LLMs generating obfuscation variants, AI-assisted exploit development, automated vulnerability discovery. Patch-to-exploit times are compressing. The defender patching cycle is now in a race against AI-accelerated weaponization.
Reconnaissance and Targeting
Automated OSINT aggregation, victim profiling, attack chain planning. Capabilities that once required skilled human operators are increasingly available as commodity tools.
Quantify the Shift for Your Organisation
Questions that surface this exposure in your own organisation: "Has our phishing simulation click-rate changed in the last 18 months?" (AI-written lures beat template lures consistently). "How would our finance team verify a video call from the CFO requesting an urgent transfer?" (most have no answer). "What is our current patch SLA, and was it set before AI-accelerated exploit development?" These questions reframe AI from a product category to a change in the threat landscape you are already living in.
Prefer slides, quizzes, and saved progress? Read this lesson in the library — free, no sign-up.