AI-driven cybercrime escalates with higher engagement and new attack vectors in 2025

Artificial intelligence is revolutionising cybercrime, with AI-powered phishing and vishing campaigns achieving unprecedented success rates and expanding beyond email to target voice and identity systems, prompting a shift in defensive strategies.

Artificial intelligence is changing cybercrime faster than many defenders can adapt. Security vendor Brightside says AI-assisted phishing campaigns now produce far higher engagement than older scams, with click-through rates rising from about 12% in traditional phishing to 54% in simulated AI-driven attacks. Brightside also says 82.6% of phishing attempts now involve AI in some part of the chain, underscoring how quickly the technology is being absorbed into criminal workflows.

The shift is most visible in email, but it is not confined to inboxes. Brightside says voice phishing, or vishing, has grown sharply, with attacks up 442% between the first and second halves of 2024 and deepfake-enabled vishing rising even faster in early 2025. Its simulator product is built around that threat, allowing security teams to mimic executive voices, test social engineering tactics and stage combined email-and-voice attacks against employees.

What makes AI especially useful to attackers is not only scale but also plausibility. Microsoft’s 2025 report, as cited by security researchers, found that AI-generated phishing messages can match or exceed the performance of human-written scams because they are grammatically clean, tailored from scraped personal or organisational data and calibrated to sound urgent and authoritative. The result is a form of social engineering that is harder for staff to spot and harder for conventional spam filters to catch.

The threat is also moving beyond email. Industry analysis from Nomad Solutions says phishing is increasingly targeting identity systems, help desks and voice channels, where one convincing interaction can expose an entire software stack. That evolution matters because the attacker no longer needs to break through every layer of defence. In many cases, one successful conversation is enough to open the door.

Researchers have also warned that the risk extends to the tools companies are adopting internally. A Trend Micro survey cited in the source material found that cybersecurity professionals are most worried about fraud, deepfakes, prompt injection, model poisoning and jailbreaking, with cloud environments and remote devices among the hardest areas to secure. Prompt injection, in particular, can trick an AI system into following malicious instructions hidden inside content it reads, turning a helpful assistant into an unwitting participant.

The same pattern applies to autonomous agents, which are increasingly being wired into email, calendars, support systems and software development pipelines. The concern is simple: once an AI has access to sensitive tools and data, it may act efficiently without exercising judgment. According to the source material, OpenAI has said fully defending against prompt injection in AI browsers may not be feasible, which is why many security experts now argue for restricting an AI’s permissions to the minimum necessary.

For defenders, the response is becoming more automated as well. Microsoft has launched Project Perception, which uses clusters of specialised agents for penetration testing, investigation, integration and remediation. But the most practical advice remains basic: turn on multi-factor authentication wherever possible and reduce the permissions granted to any AI agent or assistant connected to important accounts. In a security environment reshaped by AI, that kind of restraint may prove more valuable than any promise of intelligent automation.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.