Cybercriminals are increasingly leveraging artificial intelligence to enhance the effectiveness and scale of phishing and scam operations. Generative AI technologies now enable attackers to create highly convincing deepfakes, fabricate entire personas, and automate the setup of phishing websites and email campaigns. Romance scams, such as 'pig butchering,' have evolved from being operated by large scam farms to being powered by AI bots that can simultaneously engage with multiple victims, building emotional connections over extended periods before soliciting fraudulent investments. Catfishing has become more sophisticated, with neural networks capable of imitating a person’s appearance, voice, or writing style, making impersonation attacks more convincing and harder to detect. Attackers are also using AI development tools to craft realistic phony CAPTCHA pages, which are designed to trick users into believing they are interacting with legitimate security checks, thereby harvesting credentials or other sensitive information. A new phishing automation platform, SpamGPT, has emerged, offering a full suite of email campaign tools powered by generative AI. SpamGPT mimics professional email marketing services but is tailored for cybercrime, featuring modules for campaign management, deliverability testing, and analytics. The platform’s built-in AI assistant, KaliGPT, can generate persuasive phishing email templates, subject lines, and targeting advice, removing the need for attackers to write their own content. SpamGPT is marketed as a spam-as-a-service solution, promising guaranteed inbox delivery for major email providers by fine-tuning messages to bypass security filters. The platform also abuses trusted cloud providers like Amazon AWS and SendGrid to blend malicious emails with legitimate traffic, further evading detection. These advancements mean that phishing campaigns can now be launched at scale with minimal technical expertise, increasing the threat to both individuals and organizations. The use of AI in scams extends to social engineering, where attackers can convincingly impersonate friends, family, or colleagues, increasing the likelihood of successful attacks. Security experts warn that the rapid evolution of AI-powered phishing tools is outpacing traditional defense mechanisms, necessitating updated awareness and technical controls. Organizations are advised to educate users about the risks of AI-driven scams and to implement advanced email filtering and authentication technologies. The convergence of generative AI and cybercrime is expected to continue, with attackers constantly refining their tactics to exploit new AI capabilities. Vigilance and proactive security measures are essential to mitigate the growing threat posed by AI-enhanced phishing and scams.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Kaspersky published analysis outlining how phishers and scammers are using AI across fraud workflows, including generating convincing text and scaling social-engineering operations. The report reflects broader industry recognition that AI is being integrated into phishing and scam activity.
Separate reporting on the same date described an AI-enabled phishing platform that automates parts of phishing campaign creation and execution. This marked an escalation from ad hoc AI-assisted content generation to more systematic attack automation.
Security blog coverage in late September 2025 described attackers using AI development tools to create phony CAPTCHA pages and other phishing content, indicating growing operational use of AI in social-engineering attacks. The reporting highlights AI-assisted lure creation as an active tactic rather than a theoretical risk.
3 references tracked. Mallory keeps watching after this page renders.
kaspersky.com
Open sourceblog.knowbe4.com
Open sourceblog.knowbe4.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.