AI-powered attacks: agents that hack, bots that lie, and voices that aren't real
20 September 2026
Agentic automation: recon at machine speed
The newest shift reported across industry threat tracking (see Cisco's threat-trends reporting): AI agents chaining reconnaissance on their own — enumerating targets, testing phishing lures, and moving laterally with minimal human input. What took a crew days now runs overnight. Defence implication: speed is the attacker's edge, so patching windows and detection response times matter more than ever.
Shadow AI: your chatbot is a leak vector
Employees paste source code, customer lists, and credentials into public chatbots daily; attackers also poison AI tools with malicious instructions (prompt injection) to exfiltrate data or execute commands. Rules: nothing confidential into public models, prefer enterprise tiers with no training retention, and treat AI-suggested commands/links with the same suspicion as any stranger's — verify before running.
Multichannel social engineering: the four faces
- Deepfake audio/video: cloned voices of "the boss" or family; video-call fraud has already produced confirmed multi-million-dollar losses (Hong Kong police documented a $25M video-call deepfake case in 2024). Tell: unnatural blinking, lip-sync drift, and refusal to do a live challenge ("turn your head", "hold up three fingers").
- Vishing: AI voice clones make any caller ID + any voice combinable. Tell: urgency + secrecy + a request that bypasses procedure.
- Quishing: QR codes that skip the "read the URL first" habit entirely. Tell: scan with a preview-enabled scanner, then run the destination through our scam-link scanner.
- Hyper-personalised spear phishing: breached data + AI writing = lures referencing your real orders, colleagues, and habits. Tell: the request (money, credentials, bypass), never the polish — legitimate process survives a callback on a known number.
The household defence
Agree one verification ritual for voice/video money requests: hang up, call back known numbers, use the family safe word (see why awareness matters). AI made fakes cheap; procedure makes them useless.