AI vs. AI: How Artificial Intelligence Is Both Fueling and Combating Cybercrime
Artificial intelligence is undeniably reshaping the landscape of technology, offering solutions that were once unimaginable. However, there’s a growing assumption in both the tech and cybersecurity communities that AI’s rise will simply make cybercrime more efficient and harder to detect.
Just take deepfake as an example. If you browse through r/ChatGPT on Reddit, you’ll come across AI-generated images that are so convincing they blur the lines between reality and fiction.
Or how about AI videos mimicking voices so well that you’re left wondering if that’s even fake?
As new AI models are being introduced and massive funding flowing into the space, AI tools are becoming more powerful—and more accessible. A prime example of this is DeepSeek which is making headlines these days for training their models at just 1/30th the usual cost.
But as AI becomes more accessible and its capabilities expand, they’re also opening the floodgates for cybercrime. We’re now at a point where AI tools are as accessible as any smartphone app, allowing anyone—whether skilled or not—to carry out sophisticated attacks with ease.
Don’t believe me?
We’ll just read this article by the BBC where a French woman got conned out of $850,000 by scammers posing as actor Brad Pitt.

Yes, you heard that right. She got conned with AI-generated images and videos, making her believe she was in a romantic relationship with Brad Pitt.
The number of AI scams reported in July 2024 doubled compared to July 2023. To put ‘double’ into perspective, Americans lost over $108 million to AI-related scams in 2023.
And… according to a McAfee study, one in four adults has reported experiencing an AI scam, with voice cloning technology playing a key role. While the elderly were once the primary targets, these scams now impact a much broader range of demographics.
So yeah, instead of just worrying about AI taking our jobs, maybe we should be more concerned about it stealing our data, cloning our voices, or deepfaking us—for the love of God.
That said, there’s a nuance to this conversation that I think is being overlooked.
Yes, AI is undeniably making cybercrime more scalable, but it’s also becoming a critical tool for cybersecurity experts trying to stay one step ahead of these threats. I guess I’m trying to say that AI isn’t just an adversary—it’s also a defender.
Let me break down how AI is both enabling cybercriminals and offering solutions to fight back. It’s a complicated landscape, and I believe understanding both sides of the equation is key to truly grasping the future of cybersecurity in an AI-driven world.
Part 1: The Dark Side of AI – How Cybercriminals Exploit Artificial Intelligence
1. AI-Powered Phishing: Smarter, More Convincing Scams
AI-powered phishing is quickly becoming one of the most alarming cybersecurity threats. With the help of AI tools, cybercriminals are now able to generate phishing emails that look and feel indistinguishable from legitimate communications.
These sophisticated emails can trick even the most cautious users. AI can replicate real-world communication with eerie accuracy, making it easier for scammers to manipulate their targets.
One particularly concerning example is how AI-powered chatbots are being used to mimic customer support agents in phishing attacks. These bots can engage in natural conversations and convince individuals to provide sensitive data without ever suspecting foul play.
In 2023, AI-driven phishing attacks increased by 1,265%, which is a staggering jump that should have everyone on high alert (source).
I myself came across a fascinating yet concerning example of how easy it is to manipulate AI into generating a convincing phishing email.
For example, if I ask ChatGPT to write an email for a business email compromise (BEC) scam, it refuses outright. But with a slight rewording—like requesting a professional email from a CEO instructing a clerk to process an urgent invoice—it provides something like this:
Subject: Urgent Payment Request for Invoice – Vendor ABC
Dear [Clerk’s Name],
I hope you’re doing well. I need your immediate assistance with an outstanding invoice from Vendor ABC.
Invoice Number: [Insert Invoice Number]
Invoice Amount: [Insert Invoice Amount]
Due Date: [Insert Due Date]
Please ensure this payment is processed today to avoid any delays. Let me know once it’s completed or if you need further details.
Best,
[CEO’s Name]
This is exactly how cybercriminals refine their tactics. And with the rise of dark LLMs like FraudGPT and WormGPT, attackers no longer need to rely on tricking ChatGPT—they have AI models specifically designed for phishing.
With AI models capable of mimicking writing styles and personalizing messages based on stolen data, traditional email security measures may no longer be enough. The question is—how do we keep up when cybercriminals have AI on their side?
2. Deepfake Deceptions: How AI is Faking Reality
Deepfake technology, powered by AI, is revolutionizing cybercrime by enabling fraudsters to create incredibly realistic fake videos and voice recordings.
According to CNN, a finance worker at a multinational firm was tricked into paying out $25 million to fraudsters using deepfake technology to pose as the company’s chief financial officer during a video conference call.
This case is just one example of how criminals are leveraging deepfake technology to manipulate people.
As deepfake-related scams surge, it’s clear that these sophisticated AI-generated images and voices are only going to get more realistic, making it harder for people to distinguish fact from fiction.
3. AI-Driven Malware: Self-Learning Cyber Threats
Yeah…this is something I just had to research. Since we all use OpenAI and I’ve been using it from the very start, I’ve seen it evolve over time with new features. For example, ChatGPT can now provide answers with sources. It can actually pull information from the web. This was something that was not available in earlier versions.
This made me wonder, how rapidly is malware being generated. And that is when I came across the terms: Adaptive malware.
Unlike traditional malware, these threats are adaptive, learning from detection systems in real time and modifying their attack patterns accordingly. This makes them incredibly difficult to stop using conventional security tools.
One alarming example is BlackMamba, an AI-powered malware that dynamically generates polymorphic keylogging code on the fly. Unlike traditional malware, it doesn’t store a predefined malicious payload, making it nearly impossible for signature-based detection tools to flag it.
Security researchers demonstrated how BlackMamba could bypass endpoint detection and response (EDR) systems, raising concerns about its potential real-world use.
Another concerning trend is the emergence of dark LLMs—large language models specifically built for cybercrime. FraudGPT and DarkBard are two such tools designed for phishing, malware distribution, and social engineering attacks. Unlike mainstream AI tools that have ethical safeguards, these models are sold in underground forums for as much as $1,700 a year, offering criminals automated attack scripts, exploit generation, and even AI-powered social engineering capabilities.
These advancements are reshaping the cyber threat landscape, making AI-powered malware more elusive and scalable. While cybersecurity experts are using AI to counter these threats, it’s clear that we’re in an escalating arms race where attackers and defenders are both leveraging AI to outmaneuver each other.
4. The Privacy Crisis: How AI is Fueling Mass Data Collection
As AI technologies become more pervasive, they rely heavily on vast amounts of data to function. Unfortunately, much of this data is collected without explicit consent, raising serious privacy concerns. I’ve come across studies highlighting just how much personal data is being fed into AI models—data that’s often unknowingly shared by users.
Take ChatGPT, for example. This popular AI tool has been scrutinized for how it collects data, much of which comes from publicly available sources, including personal information from social media and forums. While AI models rely on these datasets to improve their algorithms, the privacy risks are significant. A recent survey revealed that 74% of Americans are concerned about how AI could misuse their personal data (source).
This growing concern over data privacy is compounded by incidents like OpenAI’s recent spotlight in July 2024, when senior Swift developer Pedro José reported on threads that the ChatGPT app was storing user conversations in plain text in an unprotected location.
This highlights the ongoing risks to privacy as AI tools continue to scale and collect more personal information.
Part 2: How AI is Combating Cybercrime?
As I pointed out earlier, the nuance that’s often overlooked is that AI isn’t just a tool for cybercrime; it’s also playing a proactive role in fighting back.
In this part of the blog, I’ll dive into how AI is turning the tables and fighting back against AI-driven cybercrimes.
AI’s Role in Combatting AI-Driven Threats
AI is being deployed in cybersecurity not just to combat traditional threats but to tackle the rapidly escalating AI-powered attacks. Take Amazon, for example. The company has seen its daily cyber threat attempts skyrocket from 100 million to 750 million. To stay ahead of this massive surge, Amazon utilizes AI in advanced tools like graph databases and honeypots, designed to analyze attack patterns, especially those from AI-driven cybercriminals.
This proactive AI strategy helped Amazon thwart attacks from cybercriminal groups like Anonymous Sudan in collaboration with the U.S. Justice Department, highlighting the vital role of AI in tackling nation-state level threats.
Meanwhile, Microsoft has invested $20 billion in cybersecurity over the past five years, focusing on AI solutions to protect against cybercriminals leveraging advanced machine learning techniques. Through tools like Microsoft Pluton and Microsoft Purview, the company is arming itself with cutting-edge defense systems that track real-time data and improve threat detection, ensuring that AI-powered attacks don’t slip through the cracks.
The Evolution of Cloud Security with AI
AI is reshaping cloud security strategies, especially in the context of generative AI. According to a McKinsey study, 72% of companies now use AI, with 65% utilizing generative AI, a powerful tool that unfortunately brings along a wave of security challenges. That’s where Cloud-Native Application Protection Platforms (CNAPPs) come in.
These AI-enhanced platforms are transforming cloud security by providing real-time threat analysis, slashing the detection time for incidents from 16 days to just 10 minutes. This drastically reduces the response time, keeping cloud systems safe from AI-driven attacks that evolve rapidly. As businesses embrace generative AI, they are becoming more vulnerable, but AI tools like CNAPPs are creating a strong defense to match.
Combating Deepfake Scams with AI
Deepfake scams have become a serious concern in the cybercrime world, with 20% of businesses experiencing attacks in the past year. AI is fighting back by identifying these increasingly sophisticated scams.
MasterCard, for example, is employing AI to detect deepfakes in real-time and educate its employees on how to spot these fraudulent activities. This is crucial, as deepfake scams often rely on convincing fake audio or video content to deceive individuals into transferring funds or divulging personal information.
AI-Powered Defense Against Phishing and Credential Attacks
The surge in phishing emails and credential theft attacks is alarming. A recent survey showed a 1,265% increase in phishing emails and a 967% spike in credential phishing since late 2022. To counter this, nearly 85% of Chief Information Security Officers (CISOs) are now turning to AI to combat these threats.
The automation and intelligence that AI provides in detecting phishing attacks is unmatched. AI algorithms can analyze behavioral patterns and spot anomalies that might indicate phishing attempts, blocking them before they even reach the target. This AI-driven intervention has become an essential part of modern cybersecurity defense.
AI in Threat Detection: A Game-Changer
One of the areas where AI is proving invaluable is in real-time threat detection and prevention. Traditional methods struggle to keep up with the enormous data volumes generated by modern connected systems. AI excels in processing this data, spotting patterns that human analysts might miss. For instance, AI can monitor network traffic, system logs, and even user behaviors, quickly identifying signs of malicious activity.
Take Wells Fargo, which uses AI to analyze vast amounts of data from emails, network traffic, and files. Upon detecting anomalies, AI systems automatically block malicious actions, preventing any further damage.
In the same vein, PayPal leverages AI to scan millions of transactions daily, spotting fraud and blocking potential threats. This system works by analyzing transaction patterns and predicting fraudulent behavior before it can cause harm. With cybercrime projected to cost the global economy $10.5 trillion annually by 2025, PayPal’s AI-enhanced fraud prevention is a shining example of how AI is already helping businesses manage these colossal threats.
Endpoint Security and the Role of AI
As remote work has become the norm, securing endpoints has become an essential part of any cybersecurity strategy. Traditional antivirus software often falls short in detecting zero-day threats, but AI-driven endpoint protection systems are always learning and adapting.
These systems establish baselines of normal behavior and flag deviations, spotting potential threats before they even occur. AI is also enhancing password security, integrating advanced authentication methods like facial recognition and fingerprint scanning to ensure that only authorized individuals can access sensitive data.
AI and Vulnerability Management: Staying Ahead of the Curve
AI isn’t just reactive; it’s also incredibly proactive. AI-driven platforms like Splunk are capable of continuously analyzing network traffic, system events, and user behavior to predict and mitigate vulnerabilities before they can be exploited. This proactive defense allows organizations to focus their resources on addressing the most critical security risks, preventing breaches before they happen.
AI’s Future in the Cybersecurity Arms Race
AI is no longer just a defensive tool but is quickly becoming a key part of the offense in cybersecurity. As the cybercrime landscape continues to evolve, AI’s role in protecting against AI-driven threats will only become more critical. From real-time threat detection to predictive analytics, AI is arming businesses with the tools needed to stay one step ahead of the criminals. In a world where cyberattacks are more frequent and more sophisticated, AI is no longer a luxury—it’s a necessity.
As we’ve seen, companies like Amazon, Microsoft, and PayPal are already leveraging AI to combat AI-based cybercrime. But with the rise of new threats, the potential for AI to outpace cybercriminals is significant. This technology is evolving quickly, and its ability to learn, adapt, and act autonomously will continue to be a game-changer in the cybersecurity space.
In the end, AI’s role in fighting cybercrime is a powerful reminder that the same technology driving innovation in cybercrime is being harnessed for good. The battle between AI and cybercriminals is just beginning, and with AI on our side, the future of cybersecurity is looking brighter than ever.


