MODULE 1 ยท LESSON 3

Free โ€” no login required

Sign in to track progress, save quiz attempts and enrol in the full course.

Sign in to track progress / enrol

What Actually Changed

AI did not add a fifth move. What it did was change the price of the first two, and price changes behaviour at scale. Three shifts matter, and each one has evidence behind it.

Shift one: personalisation stopped costing anything

Convincing fraud used to require research. Somebody had to learn who reports to whom, what a deal is called internally, how a particular manager writes. That effort had to be repeated for every target, which meant well crafted attacks were reserved for valuable victims, and everyone else received obvious generic spam.

That constraint is gone. The research and the writing can now be produced at effectively zero marginal cost, in fluent local language, for every target in a list. The quality once reserved for a bank's finance director is now available against a fifty person company.

The practical consequence: being small or uninteresting is no longer protection. A great deal of informal security thinking rests on the assumption that nobody would bother. Somebody will, because bothering is now free.

Shift two: the seams disappeared

A generation of security awareness training taught people to look for imperfections. Poor grammar, an odd greeting, a stretched logo, a strange turn of phrase. That advice worked because producing polished material in a second language was expensive.

It is now free, which means the advice has quietly inverted. Teaching people that well written messages are safe leaves them defenceless against every message they will actually receive.

The same applies to voice and video. Cloning a voice convincingly needs only a few seconds of reference audio, and the results have crossed the point where listeners cannot reliably identify them by ear. Roughly 41 percent of organisations report having encountered a deepfake on an audio call, and about 35 percent on a video call. Deepfake attempts have risen from a negligible share of fraud in 2022 to several percent of all fraud attempts.

Shift three: skill stopped being a barrier

Carrying out an intrusion once required real expertise, which limited how many people could do it.

That limit has weakened. In 2025 Anthropic published details of activity on its own systems in which an actor used AI tooling to automate reconnaissance, credential harvesting and extortion against multiple organisations, with the model making many of the operational decisions. A separate case involved someone selling functional ransomware they had no ability to write themselves. In a later campaign, the reported estimate was that the AI carried out 80 to 90 percent of the operation with only intermittent human direction.

Treat these as early indicators rather than as the settled state of the world. The direction is what matters: the skill required to run a competent intrusion is falling, and the number of people able to attempt one is therefore rising.

๐Ÿ“… Timeline
Before roughly 2022Personalised attacks cost human hours, so they were aimed at valuable targets. Everyone else got obvious spam with visible flaws.
2023Fluent generated text removes the language and grammar tells. Awareness training built on spotting errors begins to fail quietly.
2024Real time voice and video synthesis becomes practical. The Arup fraud demonstrates that a live multi person video call can be fabricated convincingly.
2025Documented cases of AI performing most of the operational work in intrusion and extortion campaigns, lowering the skill barrier substantially.
NowAssume any message, in any medium, can be perfectly fluent and can carry a familiar face and voice. Defences that rely on noticing imperfection are no longer load bearing.

What this invalidates

Three pieces of common advice are now actively harmful, in the sense that following them produces false confidence.

"Check for spelling and grammar mistakes." Retire it. Its replacement is in Module 4: examine the structure of the request rather than the quality of its prose.

"Confirm by calling or video." Correct in spirit, dangerously incomplete as stated. Confirm using contact details you already held, never details supplied in the message and never a call the requester initiated.

"We are too small to be targeted." This was always weak and is now simply false, because the cost of including you in a campaign has fallen to nearly nothing.

What did not change, and became more valuable

Everything structural. Because attackers got better at the human layer, the defences that do not depend on the human layer carry more weight than before.

  • Patching. Most successful exploitation still uses a known flaw with an available fix. AI has not changed this.
  • Phishing resistant authentication. A passkey does not care how convincing the fake page was.
  • Least privilege. Limits what a successful first move is worth.
  • Tested backups. Still the difference between ransomware as a crisis and ransomware as an inconvenience.
  • Dual authorisation on payments. Survives a completely convinced employee, which is exactly the Arup scenario.

There is a pattern here worth naming. Every item on that list works without requiring anyone to notice anything. That property was always desirable. It is now the deciding factor, because human detection is the capability that AI degraded.

Numbers in this field mostly originate with companies selling remedies, so a little scepticism is a professional skill rather than cynicism.

Three habits are worth adopting.

Ask what the denominator is. "Deepfake fraud attempts rose 2,137 percent" sounds apocalyptic and is compatible with a rise from a very small base to a still modest share. The more informative version is the one used earlier in this lesson: from roughly 0.1 percent of fraud attempts to several percent. That is a genuine and serious change, and it is not the end of the world. Both facts fit the same data.

Ask who counted, and how. Vendor telemetry measures what that vendor's customers experienced, which is not a random sample of the world. Survey findings measure what respondents believed and were willing to report, which is not the same as what happened. Neither is worthless; both need the qualifier attached.

Prefer incidents to aggregates. A documented case with a named organisation, a sequence of events and a known outcome supports specific conclusions. That is why this module is built on Arup and on published incident reports rather than on a chart of projected losses. You can reason from a case. You cannot reason from a projection.

Apply this to the numbers in this course as well. Where a figure here is soft, it is stated as approximate, and the argument does not rest on the exact value.

โ“ Knowledge Check

Given that AI has made social engineering far more convincing, what is the most rational allocation of additional security effort?

๐Ÿ“š Flashcards1 / 5
Term

Marginal cost of an attack

Click to flip
Definition

The cost of adding one more target. AI drove this close to zero for personalised social engineering, which is why small organisations lost their obscurity.

Click to flip back
๐Ÿ’กKey Takeaway

Three things changed: personalisation became free, so being small stopped protecting you; the imperfections we trained people to spot disappeared, so error spotting advice now creates false confidence; and the skill barrier fell, so more people can attempt more. Nothing structural changed, which means patching, phishing resistant authentication, least privilege, backups and dual authorisation all became more valuable rather than less. What they share is that none of them require a human to notice anything, and human noticing is exactly the capability that AI degraded.