Quick answer: Attackers use AI to make their attacks faster, more convincing and more scalable. The most common uses are: phishing emails written with flawless grammar and personalized to the target, deepfake frauds that imitate an executive's voice or face, quickly producing malicious code and attack scripts, automatically collecting target intelligence from open sources and social media, and continuously changing content to bypass security filters. AI does not give the attacker a new weapon; it makes existing attacks cheaper and more scalable and makes them more convincing with less skill. The root defense is to respond to AI's speed with AI supported defense, but to verify every critical decision with human oversight.

AI is not only in the hands of defenders but also of attackers. The same technology makes a fraudster's job easier and lets them cause greater harm with less skill. This article explains how attackers actually use AI and the correct defense against this threat.

How AI changes attacks

AI does not invent new attack types; it makes existing ones cheaper and scalable. Jobs that used to require skill and time are now automated and fast. Phishing emails written with poor grammar and easily noticed give way to flawless and personalized messages. This increases the volume and success rate of the attack.

Areas where attackers use AI

Area What AI does Result
Phishing Flawless, personalized email Higher click rate
Deepfake Voice and face imitation Executive fraud, BEC
Malicious code Script and variant generation Fast and varied attacks
Intelligence Automated target research More accurate attacks
Filter bypass Continuously changing content Making detection harder

The common point of these areas is: AI strengthens the places where the attacker is weakest (language, scale, speed). So an attacker with fewer resources can build a more convincing attack.

Deepfake, the most dangerous leap

The most striking use of AI in attacks is deepfake. An urgent money transfer can be requested with a fake call imitating an executive's voice, or a fake face can be used in a video conference. This directly targets trust. To distinguish whether a medium is real or artificial, deepfake forensics methods become increasingly critical.

AI itself is also a target

Attackers do not only use AI as a weapon; they also target the defenders' AI. A language model in a security or business application can be tricked with prompt injection or corrupted with data poisoning. So every organization using AI must think about both defending with AI and defending the AI.

The correct defense

1. Respond to AI with AI

The attacker's speed must be met with AI supported detection and scale in defense too. Human speed alone cannot keep up with this volume.

2. Human verification layer

AI supported defense must verify every critical decision with human oversight. Actions such as money transfer and authorization change must rely not on voice or video confirmation but on a second secure channel.

3. Deepfake awareness and verification

Employees must be trained that voice and video can be imitated; a reflex of confirming sensitive requests through a second channel must be built. This should be part of the phishing simulation and awareness program.

4. Protect your own AI

The AI applications the organization uses must also be hardened against prompt injection and data poisoning.

The DSET and KAOS approach

DSET responds to attackers' AI with AI in defense while preserving human oversight. The local AI engine KAOS assesses the AI supported attack surface (phishing resilience, deepfake detection, AI application security) at scale and reports every finding with evidence, under expert oversight. Because KAOS runs offline, corporate data does not leave during the assessment. The goal is to keep up with the attacker's speed while leaving the decision to the human.

Frequently asked questions

Does AI give attackers new attacks? Usually no. Rather than inventing new attack types, AI makes existing attacks cheaper, scalable and more convincing. Known attacks such as phishing, fraud and malicious code become faster and more effective with AI.

How do I verify a request that comes with a deepfake? Do not trust voice or video. A money transfer or a sensitive action must be confirmed not by voice and video but through a previously known second secure channel. Because deepfake directly targets trust, the process must not rely on a single channel.

Is defending with AI enough? Necessary but not enough alone. AI supported defense keeps up with the attacker's speed but can speak as if certain even where it is not. So every critical decision must pass through human oversight. The right model is AI and human working together.

Sources

To assess your organization against AI supported attacks and measure its resilience, contact DSET. We provide security with KAOS and expert oversight from our Ankara Hacettepe Teknokent laboratory.