AI-powered fraud is becoming personal: How cybercriminals are exploiting trust at unprecedented scale


Cybercrime has long relied on deception, but 2026 appears to mark an important turning point. According to a new cybersecurity report from NordVPN, criminals are increasingly using artificial intelligence to transform scams from mass-distributed attacks into highly personalised campaigns designed to exploit trust, familiarity and human psychology.

The company’s first flagship Consumer Cybersecurity Report: Dismantling the Evolving Threat Landscape analyses threat intelligence gathered between January and June 2026 and paints a picture of cybercrime becoming simultaneously more sophisticated and more accessible. Rather than focusing on technical vulnerabilities alone, criminals are increasingly targeting the weakest point in many security systems: human behaviour.

Trust has become the primary target

One of the report’s central conclusions is that trust has become the most exploited vulnerability in today’s cyber threat landscape. Generative AI systems can now create convincing emails, messages, websites and social media content with remarkable speed and realism. Coupled with readily available fraud kits sold on criminal marketplaces, sophisticated scams that once required specialist knowledge can now be launched by individuals with relatively little technical expertise.

According to Marijus Briedis, Chief Technology Officer at NordVPN, this dramatically changes the threat environment facing ordinary consumers: “Bad actors are weaponising our natural instinct to believe what we see and hear. These attacks no longer require advanced skills or significant resources.” The significance of this change should not be underestimated. Historically, many online scams contained obvious errors, poor grammar or other warning signs. AI-generated content increasingly removes these flaws, making fraudulent communications appear professional and credible.

A criminal industry operating at scale

The report highlights the sheer volume of malicious activity now confronting internet users. According to the analysis, NordVPN examines approximately 12 million unique URLs every day and blocks around 130,000 malicious webpages daily before they can reach users. These figures illustrate the industrial scale at which cybercrime now operates. The transformation is being driven partly by automation. AI tools allow criminals to create fake websites, phishing campaigns and fraudulent communications at a pace that would have been difficult to achieve manually.

As a result, cybercrime increasingly resembles an industrialised business sector, complete with supply chains, commercial tools and specialised service providers. This growing professionalisation mirrors concerns raised by industry organisations which have warned about the increasing availability of cybercrime-as-a-service platforms.

Malware remains the dominant threat

While AI-generated scams are receiving significant attention, traditional malware continues to represent the largest threat category by volume. The NordVPN report found that malware attacks reached a peak in January 2026, with more than five million attacks blocked during that month alone, largely targeting consumers making purchases after the holiday season. Many of these attacks involved infostealer malware, a category of malicious software designed to harvest login credentials, session information and personal data stored on infected devices. Infostealers have become particularly valuable to cybercriminals because account access can often be monetised more easily than traditional ransomware attacks.

Phishing remains one of the most effective attack methods available to cybercriminals. In relation to tjis, according to the report, more than 4.4 million phishing attempts were blocked during the first half of 2026. Interestingly, the research found that 99 percent of phishing attacks impersonate just 300 brands, demonstrating how criminals rely heavily on familiar and trusted organisations.

This concentration reflects an important aspect of modern phishing campaigns. Attackers increasingly focus on brands that users interact with regularly, making fraudulent messages appear more believable. Guidance from the NCSC consistently emphasises verifying communications through official channels rather than relying solely on emails, text messages or links received unexpectedly.

One of the more concerning findings involves session cookies. The report identified 94 billion cookies exposed online between 1 January and 26 May 2026. Of these, approximately 1.2 billion were active session cookies. Session cookies play a critical role in maintaining authenticated user sessions. When stolen, they can sometimes allow attackers to access accounts without needing passwords and, in some circumstances, even bypass multi-factor authentication protections.

Security researchers have increasingly highlighted session hijacking as a growing concern because it exploits authenticated sessions rather than login credentials themselves. Organisations such as the OWASP Foundation have long classified session management weaknesses among the most significant application security risks.

Another notable finding concerns the amount of personal information circulating within criminal ecosystems. According to NordVPN’s analysis, more than 47 percent of exchanged compromised data contains both physical addresses and full names. This information allows criminals to construct comprehensive victim profiles by combining digital and real-world data.

The report also identified 8.4 million compromised accounts within a 90-day period through NordVPN’s dark web monitoring systems. These figures reinforce the value of monitoring exposed credentials and ensuring passwords are unique across multiple services. The report also highlights the continuing evolution of fraud beyond traditional online channels.

Between launch and 16 June 2026, NordVPN blocked almost 29,000 scam calls and warned more than 525,000 users about spam calls. As AI voice synthesis technology improves, security experts increasingly expect telephone fraud to become more convincing. Technologies capable of generating realistic speech patterns, accents and conversational responses may soon make it far harder to distinguish legitimate callers from fraudulent ones.



AI-powered fraud is becoming personal: How cybercriminals are exploiting trust at unprecedented scale

#AIpowered #fraud #personal #cybercriminals #exploiting #trust #unprecedented #scale

Leave a Reply

Your email address will not be published. Required fields are marked *