Skip to main content

AI is giving hackers an edge. Here’s how to protect yourself from online scams

(CNN) — Cybercriminals are increasingly using artificial intelligence to target people: Americans lost more than $893 million from AI-related crimes last year, according to the FBI.

Just last week, OpenAI and Anthropic revealed that their AI agents accessed the internet during testing and hacked into other companies’ systems. Although customer-facing data wasn’t breached, the incidents raised fresh concerns over cybersecurity.

AI is growing more accessible, inexpensive and effective for pulling off attacks, said Chris Whyte, a professor at Virginia Commonwealth University.

Here’s what experts suggest to protect against cyber scams.

Deepfakes

A deepfake can replicate faces or voices as well as videos or images depicting events that never happened. Roughly 12% of US scam victims last year said the hoax they fell for involved AI or a deepfake, according to a Gallup report.

Some deepfakes can even be used in Teams and Zoom meetings, Whyte said.

Face filters can be advanced, but images may break if a scammer turns their head or is asked to stand and spin around, Whyte said. He recommended asking potential scammers to move on camera if possible.

“It’s going to be difficult for the filter to maintain 100% of a veil,” he said.

Scams may also involve deepfakes of celebrities, CEOs and trusted figures, according to the FBI, which creates “fraudulent, high-stakes opportunities.” Last year, victims reportedly lost more than $632 million to investment scams involving AI, according to the FBI.

If the person or video recording requests money or account access, experts recommend first verifying the request with the person or organization through a known contact.

Voice cloning

AI-trained voices may be used for distress scams, such as posing as a loved one asking for money or creating real-time pressure, according to Laurel Cook, a marketing professor and digital well-being researcher at West Virginia University. Victims claimed over $5 million in fraud losses due to distress scams last year, according to the FBI.

“Our own human abilities to detect issues are ill-fitting, so they often fall behind the sophistication of the tech,” Cook said. She suggests establishing ways to verify a relative or friend, such as choosing a safe word.

Just a few seconds of audio can be used to create as much as an 85% voice match using AI, according to Whyte. And people accurately decipher an automated voice just 60% of the time, he said.

If you’re unsure whether a caller is authentic, hang up and call back on a different number or one that is associated with an institution, like a bank, said Sam Gregory, executive director of Witness, a technology and human rights organization.

Password access

Gaining access to your password is more complicated than using AI to decrypt your account details, experts say.

AI makes guessing “more efficient” because it detects patterns from leaked passwords, says Siwei Lyu, director of the University of Buffalo’s Institute for AI and Data Science. AI can also use someone’s information to come up with more personalized password guesses.

To protect themselves, people can turn on multifactor authentication and use passwords with at least 12 characters, said Whyte. He also recommended using passkeys and password managers.

Whyte warned against requirements for passwords — like one special character, number and capital letter — because it provides a checklist for hackers. A phrase, like a line from a poem, can work effectively.

“As long as (the password is) long, you really only have to change when there’s evidence of some kind of compromise,” he said.

Fake authorizations and celebrity scams

Some scammers attempt to trick people using phony authentication methods. For instance, CAPTCHA verifications have prompts to check a box or verify images. A fake version will ask users to type a command, download software or change security settings, Lyu said.

Scammers may also convince users to authorize malicious apps that provide access to emails, contacts, files or other data, he warned. Lyu recommends using Google and Microsoft to review the apps connected to your accounts. Social media platforms like Instagram may also have security settings to review devices that have access to your account.

While AI detection software has been recommended for spotting scams, experts warn they’re not always foolproof.

“We’ve got to defend ourselves in simple ways and be more cognizant of the digital footprint that we’re leaving,” said Kroll’s Burg.

The-CNN-Wire
™ & © 2026 Cable News Network, Inc., a Warner Bros. Discovery Company. All rights reserved.

Man used spike strip to keep children off his lawn, charges say

Click here for updates on this story    Minnesota (WCCO) -- A Minnesota man is accused of using a spike strip to keep children off his lawn, according to a criminal complaint filed in Chisago County last week.The 39-year-old from Wyoming, Minnesota, is facing one count of setting a spring gun, pitfall, deadfall, snare or other like dangerous weapon or device. The charge is a gross misdemeanor.Charges say police received a complaint regarding spikes in a yard near Goodview Park in Wyoming on April 28. The reporting party said a man at the nearest residence had been yelling at children to stay out of his yard.Officers who responded to the complaint observed a 3-foot-long, 5-inch-wide piece of thick, clear plastic set in the grass next to the residence, which abuts Goodview Park. Approximately 40 3-inch screws were sticking up from the plastic, with each screw placed about an inch apart. The plastic was also anchored to the grass with metal pieces so the screws stayed sticking straight up, according to the complaint.Charges say that bike tracks were running under and around the plastic piece and that it appeared bikes would often go from Goodview Avenue into the yard as a shortcut to enter the park.Police officers talked to the homeowner, identified in the complaint as the defendant, who allegedly admitted to placing the plastic device there to keep kids off his lawn. Charges say the man told police that he yelled at the kids "hundreds of times" and they "bike through his yard out of spite."The man added that he did not intend to injure anyone, only to scare them away. Police said he seemed frustrated that the device did not keep kids out of his yard.The man's first court appearance is scheduled for Aug. 25.Please note: This story was provided to CNN Wire by an affiliate and does not contain original CNN reporting. This content carries a strict local market embargo. If you share the same market as the contributor of this article, you may not use it on any platform.
Read Next Story