A recurring human-risk service that tests frontline employees, fixes vulnerable procedures, and rehearses responses to realistic AI-generated scams.
Added Aug 16, 2026
AI enables criminals to send polished, personalized phishing and social-engineering messages at unprecedented scale. Small businesses are especially vulnerable because cashiers, administrators, and other frontline employees often handle payment systems, email, and sensitive requests without practical security training. Conventional advice about spotting typos is becoming obsolete.
Provide a managed service that maps how money and sensitive information move through a business, runs authorized phishing and impersonation drills, and coaches employees immediately after each exercise. The operator also installs simple verification procedures for payment changes, password resets, executive requests, and suspicious customer communications. Customers receive recurring drills and brief remediation sessions rather than a passive training library.
Generative AI is reducing the skill and cost required to create convincing scams while allowing attackers to target far more employees. Small businesses need procedures and repeated practice that account for personalized messages, not one-time awareness presentations.
Showing 1-20 of 27 signals
This attack marks a shift from stealing passwords to abusing trusted authentication systems. Attackers have become more sophisticated by using generative AI to create highly personalized emails tailored to victims' roles. The result is that a full attack chain is automated end-to-end, which increases success rates. First, we'll share a link to the full article in the show notes, my commentary on this one. Bad actors throughout history have figured out ways to create maximum chaos for maximum gain. AI is an attractive threat vector because security protocols are far behind user behaviors. We speak frequently about when to trust decisions automated by AI.
But what are the costs to a community for getting those trinkets? What the real power that we're getting is how these technologies will be used for businesses to run more efficiently, businesses to understand their customers more and their consumers deeper, but governments also to basically penetrate deeper into our lives, banking the same way, and our military systems. So right now we're seeing a 1200% increase in phishing and fraudulent emails because we're as of even four years ago, there were products on the dark web, such as fraud GPT, worm GPT, chaos, GPT, actual AI applications designed to create malicious software. So as AI improves, so will the attacks against our society.
Cybersecurity experts are sounding the alarm like never before. What do you think is driving this sudden upswing in AI-powered attacks? Speaker 1: It's a confluence of factors, for starters. The technology has evolved to the point where it can automate sophisticated attacks at scale. Also, with more businesses and governments relying on AI for critical operations, the stakes are higher. What are some specific examples of recent breaches attributed to AI? Speaker 2: Sure, let me lay out a couple. In the tech sector, we have seen AI being used to bypass traditional security measures. For instance, AI generated phishing emails that perfectly mimic human behavior in content, and then Therese, the use of AI in ransomware attacks, where malware evolves to stay one step ahead of defenses.
What are some specific ways AI is being leveraged in these attacks? Speaker 1: Well, AI can automate the process of identifying vulnerabilities. Let's look at some historical context. In 2017, the WannaCry ransomware attack utilized an AI-like approach by rapidly spreading through unpatched systems, exploiting Eternoblue, a vulnerability that had been known for months but remained undetected. This shows the potential for AI to accelerate the attack lifecycle. Right. Speaker 2: And moving on, AI also plays a critical role in the customization of attacks. For instance, in the context of spear phishing, AI can analyze target email data to craft highly personalized and convincing messages.
And they're getting more fishing emails. And they're getting more fishing emails. And they're getting more advanced. They're getting they're advanced. They're getting they're advanced. They're getting they're getting harder to detect as well because getting harder to detect as well because getting harder to detect as well because again these threat actors are utilizing again these threat actors are utilizing again these threat actors are utilizing AI to, you know, to create these AI to, you know, to create these AI to, you know, to create these initiatives to try to basically breach initiatives to try to basically breach initiatives to try to basically breach an organization.
+24 more signals