LLMs automate the labor-intensive parts of complex scams, like creating fake websites, conducting personalized communication, and monitoring victims. This dramatically reduces the cost, enabling attackers to target a much broader audience with highly tailored cons previously reserved for high-value targets.
Sophisticated fraud operations function like rational businesses with supply chains, training, and P&Ls. They target areas with the highest potential return on investment, such as crypto, and will pivot to new opportunities as technology like LLMs lowers their operating costs.
While Single Sign-On (SSO) solved the problem of users reusing passwords, it created a new "one ring to rule them all" vulnerability. Compromising a single identity provider account, like a Google or Apple login, can grant an attacker access to an entire ecosystem of connected high-value services.
LLMs make it cheap for attackers to monitor a compromised account (e.g., email) for months. Instead of quickly selling credentials, they can now act as "persistent threats" against individuals, building a detailed profile and striking at the moment of maximum financial opportunity, like a house sale.
Users are conditioned to clunky experiences from legitimate financial and government websites. This creates a dangerous paradox where a broken or janky phishing site doesn't seem suspicious; it feels authentic, lowering the user's guard because it mimics the poor quality of real services.
Many professional scamming operations, especially in post-Soviet states, are state-adjacent. These "patriotic hackers," often former intelligence agents, are given freedom to operate against foreign targets as long as they avoid domestic ones, acting as a reserve force for state cyber warfare.
Attackers can easily spoof incoming communication like email addresses and caller IDs. The only reliable security practice is to never trust inbound requests for sensitive action. Instead, always initiate your own communication to a verified endpoint, like the phone number printed on your bank card.
In an insidious tactic, scammers re-contact previous victims pretending to be investigators. They then offer a "work from home opportunity" which is actually a role as a money mule, tricking the victim into using their personal bank accounts to launder stolen funds.
When legitimate institutions use unbranded, third-party URLs for processes like mortgage applications, they erode a critical security habit: checking the domain name. This trains users to trust unfamiliar URLs, making it easier for scammers to create convincing phishing sites for financial transactions.
