According to a report by cybersecurity firm SlashNext, cybercriminals are leveraging artificial intelligence (AI) generation tools like ChatGPT to write phishing emails targeting businesses and others. In a survey of over 300 cybersecurity professionals in North America, nearly half reported experiencing a phishing attack targeting their business, and 77% said they had been targeted by malicious actors.
SlashNext CEO Patrick Harr said these findings further reinforce concerns about AI-generated content contributing to the rise of scams. Criminals often use AI to develop malware or social engineering scams to increase their chances of success.
According to the report, an average of 31,000 online scams occur every day.
The launch of ChatGPT in late 2022 coincided with the timeframe in which SlashNext saw a surge in phishing attacks, Harr added.
Citing the FBI's Internet crime report, the scam involving sending phishing emails to businesses caused approximately $2.7 billion in losses in 2022.
Despite some debate about the true impact of AI generation on cybercrime, Harr believes that chatbots like ChatGPT are being turned into "weapons" for cyberattacks. For example, in July, SlashNext researchers discovered two malicious chatbots named WormGPT and FraudGPT, which were seen as tools helping criminals carry out sophisticated phishing attacks.
Chris Steffen, research director at Enterprise Management Associates, said hackers are exploiting AI generation tools and natural language processing (NLP) models to perpetrate scams. By using AI to analyze information, old articles, and mimic text from government agencies or businesses, phishing emails become extremely convincing and difficult to distinguish.
To counter the increase in attacks, people need to raise their security awareness and be vigilant against suspicious emails or activities. Another solution is to deploy AI and machine learning-based email filtering tools to prevent phishing. Organizations also need to conduct regular security audits, identify system vulnerabilities and weaknesses in employee training, and promptly address known issues to reduce the risk of attacks.
Source link






Comment (0)