CipherWatch All articles
Scam & Fraud Awareness

Fluent in Fraud: How Large Language Models Became the Scammer's Most Dangerous Tool

CipherWatch
Fluent in Fraud: How Large Language Models Became the Scammer's Most Dangerous Tool

Photo: artificial intelligence chatbot cybersecurity phishing email threat, via incubator.ucf.edu

For years, the telltale sign of a phishing email was its imperfection. Broken English, misplaced punctuation, implausible urgency, and a sender address that barely resembled the brand it was impersonating — these were the red flags that security awareness training drilled into employees and consumers. That era is effectively over.

Large language models (LLMs) — the technology underpinning tools like ChatGPT, Claude, and their lesser-known counterparts — have handed criminal operators something they never previously possessed at scale: native-level fluency in persuasion. The result is a new generation of fraud campaigns that security professionals describe as qualitatively different from anything that came before.

The Anatomy of an AI-Assisted Attack

To understand what has changed, it helps to consider what crafting a convincing phishing message historically required. Before LLMs became widely accessible, a threat actor operating from outside the United States needed either a native English speaker on the team or the willingness to deploy clumsy, machine-translated prose. Neither option was ideal. The first was expensive; the second was detectable.

Today, that barrier has collapsed. A criminal with access to any consumer-grade AI chatbot — or one of the jailbroken variants circulating on underground forums — can generate a polished, contextually appropriate message in seconds. Researchers at cybersecurity firm SlashNext documented a 1,265 percent increase in malicious phishing emails in the twelve months following the public release of ChatGPT, a figure that underscores just how rapidly threat actors adapted to the new tooling.

The mechanics are straightforward. An attacker inputs a prompt instructing the model to write a message impersonating, say, a payroll department notifying an employee of a direct-deposit update. The model produces something grammatically sound, tonally appropriate, and contextually believable. The attacker refines it, adds a spoofed sender address and a credential-harvesting link, and deploys it at volume. The entire process takes minutes.

Social Engineering at Machine Speed

Phishing emails represent only one dimension of the problem. Researchers have documented AI-assisted scripts being used in voice phishing — known as vishing — operations, where callers engage targets in extended, improvised conversations designed to extract sensitive information or authorize fraudulent transactions. The sophistication of these interactions has increased notably.

In documented cases reviewed by the FBI's Internet Crime Complaint Center (IC3), victims reported that fraudulent callers demonstrated an unusual degree of familiarity with their personal circumstances — referencing recent purchases, employer names, or geographic details that lent the interaction an air of legitimacy. While some of this specificity can be attributed to data harvested from prior breaches, AI-generated scripts allow operators to weave that information into a coherent, adaptive narrative in real time.

Business email compromise (BEC) schemes have similarly benefited. In a BEC attack, the objective is typically to impersonate a senior executive or trusted vendor and redirect a financial transaction. The emails that support these schemes now routinely pass grammar checks, mirror the stylistic patterns of the person being impersonated, and arrive with contextually appropriate references to ongoing business matters — all achievable with minimal human effort when an LLM is involved.

Why Traditional Defenses Are Struggling

Conventional email security filters were trained, in part, to flag anomalies in language — unusual phrasing, inconsistent formatting, and the syntactic signatures of non-native speakers. AI-generated content eliminates many of those signals. A message produced by a well-prompted LLM does not exhibit the irregularities that legacy filters were designed to catch.

Some security vendors are responding by developing AI-based detection systems capable of identifying statistical patterns in LLM-generated text. These tools exist and are improving, but the adversarial dynamic is inherently asymmetric: detection models must be retrained continuously as generation models evolve, and the generation side currently enjoys a meaningful head start.

There is also the question of personalization. AI systems can be fed scraped data from LinkedIn profiles, social media accounts, and data broker repositories to produce messages tailored to a specific individual's professional context, relationships, and recent activities. This technique — sometimes called spear phishing at scale — was previously reserved for high-value targets because of the manual research it required. LLMs have made it economically viable against ordinary consumers.

Recognizing the New Threat

If fluency is no longer a reliable indicator of legitimacy, what signals remain available to a vigilant reader? Security researchers suggest several reorientation points.

Scrutinize the request, not the prose. The purpose of a fraudulent message is almost always to prompt an action — clicking a link, providing credentials, authorizing a payment, or disclosing personal information. Regardless of how polished the language is, any unsolicited communication requesting one of these actions warrants independent verification through a known, trusted channel.

Verify through a separate channel. If an email purportedly from your bank, employer, or a government agency requests sensitive action, do not use the contact information provided in that message. Navigate directly to the institution's official website or call a number you have independently confirmed.

Be alert to urgency and emotional pressure. LLMs are adept at generating text that conveys appropriate urgency without sounding panicked or implausible. A message that creates time pressure — even calmly — deserves heightened scrutiny.

Examine the sender domain carefully. AI can produce flawless message bodies, but it cannot change a fraudulent sending domain. Look for subtle substitutions: a zero replacing the letter O, an additional character, or a top-level domain that differs from the legitimate organization's.

Trust institutional skepticism. Legitimate banks, federal agencies, and established businesses do not request credentials, Social Security numbers, or payment authorizations via unsolicited email or phone call. That norm has not changed, even as the messages themselves have grown more convincing.

The Regulatory and Industry Response

Policymakers in Washington have begun acknowledging the threat. The Federal Trade Commission has issued guidance on AI-enabled fraud, and several bills introduced in the 118th and 119th Congress propose disclosure requirements for AI-generated communications in commercial contexts. Whether those measures will move quickly enough to matter in the near term remains an open question.

In the private sector, major AI developers including Anthropic and OpenAI have implemented usage policies and technical guardrails intended to prevent their models from being used to generate malicious content. Those measures have demonstrable value, but they are not absolute. Jailbreaking techniques — methods of bypassing a model's safety constraints through carefully constructed prompts — are documented extensively on underground forums, and purpose-built criminal LLMs with no safety restrictions have appeared on dark web marketplaces.

The fundamental tension is one that will define the cybersecurity landscape for years to come: the same technology that enables AI-assisted fraud also powers the detection systems attempting to counter it. For now, the most reliable defense remains a skeptical, deliberate human reader who understands that eloquence and legitimacy are no longer the same thing.

All Articles

Related Articles

When the Camera Lies: The Deepfake Fraud Wave Hitting American Businesses

When the Camera Lies: The Deepfake Fraud Wave Hitting American Businesses

The Long Shadow of a Stolen Password: How a 2013 Breach Is Still Opening Doors in 2025

The Long Shadow of a Stolen Password: How a 2013 Breach Is Still Opening Doors in 2025

Crime as a Subscription Service: The Ransomware Economy That Is Costing America Billions

Crime as a Subscription Service: The Ransomware Economy That Is Costing America Billions