Cybercrime is getting harder to recognise.
For years, organised fraud was associated with large scam compounds packed with operators running phishing, romance and investment scams at industrial scale. Law enforcement learned to identify and disrupt these operations.
Now the model is changing. Giles Thomson, president of the FATF, recently warned that criminals are moving towards much smaller operations powered by AI and significant computing capacity. Instead of hundreds of people working from a vast compound, a handful of people can use AI to impersonate people, create fake websites and sustain convincing conversations with victims.
The result is a cyber threat that is both more sophisticated and more accessible.
The new weapon: credibility
AI did not invent phishing, impersonation or financial fraud. But it has made them much easier to execute and harder to recognise.
Generative AI can produce convincing emails, messages, websites, social media profiles and increasingly realistic voices and videos. Criminals can personalise an attack. Fraud kits available through criminal marketplaces mean no technical expertise is required.
So, it’s not enough to ask whether an email looks suspicious. What happens when the email is grammatically perfect, knows the recipient’s name, refers to a genuine project and appears to come from the CEO?
Or when an employee receives a phone call that sounds exactly like their manager? Or when a customer appears on a video call and looks and sounds genuine, but is actually a synthetic identity?
The technology is undermining the assumption that familiarity is evidence of authenticity.
Cybercrime as an industrial process
The scale of malicious activity remains enormous. Research from NordVPN indicates that more than 4.4 million phishing attempts were blocked during the first half of 2026, while malware attacks reached more than five million just in January. Infostealers remain particularly valuable because stolen credentials, session information and personal data can be sold or used to gain access to accounts.
The same research identified billions of exposed cookies, including more than a billion active session cookies. That means an attacker does not need to steal a password if they can hijack an authenticated session.
Meanwhile, criminals continue to concentrate their phishing activity around trusted brands. NordVPN found that 99% of the phishing attacks it analysed impersonated just 300 brands.
This is the shift. Criminals are not trying to defeat sophisticated technology. They are exploiting the credibility that brands and legitimate identities have already established.
Does the human firewall need an upgrade?
All this makes traditional security awareness training increasingly inadequate.
Teaching employees to spot spelling mistakes or suspicious-looking links was useful when poorly constructed scams were common. But AI is removing those warning signs.
The question now is “What should I independently verify before I act on it?”
An employee receiving an urgent payment request from a senior executive should not have to decide whether the voice or email is genuine. There should be a process for independently verifying unusual instructions. A supplier changing its bank details should trigger verification through a trusted channel. A request for sensitive information should not be validated using the same potentially compromised communication channel.
The aim is to remove as much judgement as possible from situations where a convincing impersonation could cause real damage.
A phishing attack can quickly become a financial crime
The boundaries between cybercrime, fraud and money laundering are also becoming increasingly blurred.
A phishing message installs an infostealer. The malware captures credentials or session information. The criminal gains access to an account and impersonates the employee. That access is used to authorise a fraudulent payment. The proceeds are transferred through cryptocurrency infrastructure and moved across jurisdictions.
What began as a cybersecurity incident has become a financial crime investigation.
Cyber, fraud, AML and compliance teams need to stop treating these risks as entirely separate. The most useful warning signal may sit with another team.
An unusual login could be relevant to the cyber team. A sudden change in transaction behaviour could matter to fraud or AML. A new crypto counterparty could raise a compliance concern. Viewed together, those signals can reveal an attack much earlier.
Crypto adds another layer of complexity
The latest FATF assessment highlights how criminals are exploiting the borderless nature of virtual assets to facilitate fraud, sanctions evasion and money laundering.
FATF identifies scam-centre operations, “pig-butchering” investment scams, North Korea-linked cyber theft and cross-border laundering among the growing threats. It also warns that AI is increasingly being used in virtual-asset crime, including deepfakes, synthetic identities and AI-enabled recruitment scams.
The regulatory picture remains uneven. FATF reports that 83% of surveyed jurisdictions have now passed legislation implementing the Travel Rule, up from 73% in 2025. But countries continue to face difficulties identifying and supervising virtual asset service providers, especially offshore providers, and decentralised finance creates more challenges.
This means asking whether a crypto provider is regulated is not enough. Organisations need to understand where the provider operates, what services it offers, who ultimately controls it and whether transactions expose the business to additional AML, sanctions or fraud risks.
The same applies to customers and counterparties using stablecoins, unhosted wallets or other forms of virtual-asset infrastructure.
It’s time to defend the whole chain with cooperation and AI
Another layer of cybersecurity software is no longer enough. Companies need to examine what happens when technology, identity and human behaviour intersect. And speed can determine whether an incident becomes a contained security event or a major financial loss.
FATF is advocating closer cooperation between banks, technology companies, regulators and law enforcement, including anti-scam centres designed to share intelligence and identify fraud earlier. Businesses should take the same approach internally. The organisation needs mechanisms for information to move as quickly as the attack does.
The technology being used by criminals can also help companies detect them. AI can analyse transactions, identify unusual behaviour, connect apparently unrelated events and help investigators sift through enormous quantities of data.
FATF has even highlighted the potential for AI to be used by authorities to engage with scammers covertly and gather intelligence about their operations. The emerging contest is becoming AI-enabled crime versus AI-enabled defence.
Protecting systems or protecting trust?
Cybercrime can no longer be neatly divided into hacking, phishing, fraud, money laundering and crypto crime. A single criminal campaign can involve all of them.
AI can identify the victim and build the deception. Malware can steal access. Social engineering can turn that access into a transaction. Crypto can move the proceeds across borders. Money laundering can make them harder to trace.
For companies, the question is not: How do we keep criminals out of our systems?
It is: How could someone deceive one of our people, acquire or manufacture a trusted identity, gain access, move money or data and hide what happened and would we see the whole chain?
Criminals are using AI to make their attacks faster, cheaper and more convincing. Organisations need to start treating trust, identity, fraud and financial crime as parts of the same defence.
Don't miss our webinar, Implementing the UK’s Cyber Security and Resilience Act
Watch it here →
