SINGAPORE — Cybercriminals are beginning to move from simply asking artificial intelligence for help to giving AI systems the ability to act, plan and execute parts of an attack on their own — a shift INTERPOL warns could dramatically increase the speed and scale of online crime.
INTERPOL Global Chief Information Security Officer Bjorn R. Watne said artificial intelligence is already helping criminals improve phishing, fraud and impersonation rather than completely reinventing cybercrime.
His warning is straightforward: AI is making old criminal methods faster, more scalable and much harder for victims to recognize.
Watne, speaking to CNBC during Tech Week Singapore, described the change as an evolution rather than a revolution, with criminals using AI to target more people simultaneously, improve translations and create increasingly believable digital identities.
But the next stage could be much more disruptive.
So-called agentic AI can do more than generate text.
It can potentially decide what task to perform next, interact with software systems, gather information and execute a sequence of actions without requiring a person to approve every individual step.
That could transform the economics of cybercrime.
WHAT EXACTLY IS AGENTIC AI?
Traditional generative AI usually waits for a person to give it a request.
A user asks a chatbot to:
write an email
analyze data
generate code
or
summarize information.
Agentic AI goes further.
An AI agent can receive an objective, determine the steps needed to reach it and then interact with other systems to complete those tasks.
Microsoft defines agentic AI in cybersecurity as technology capable of autonomously detecting, investigating and responding to threats with minimal human intervention. The same fundamental capability, however, can be abused offensively.
A malicious AI agent could theoretically be instructed to:
identify vulnerable targets
research employees
create personalized phishing messages
test stolen passwords
scan networks
search for exploitable vulnerabilities
move through compromised systems
and
send extortion demands.
Instead of a human criminal manually performing each stage, software could automate much of the process.
INTERPOL SAYS AI-ENHANCED FRAUD IS 4.5 TIMES MORE PROFITABLE
INTERPOL has already put a striking number behind the trend.
Its 2026 Global Financial Fraud Threat Assessment found that fraud operations using AI are estimated to be 4.5 times more profitable than traditional fraud methods.
The organization warned that agentic AI systems could autonomously plan and execute full fraud operations—from early reconnaissance all the way to ransom demands.
INTERPOL estimated global financial-fraud losses at more than $442 billion in 2025.
The organization expects the scale of offending to continue rising over the next three to five years as AI technology becomes cheaper and easier to access.
That makes AI attractive to criminals for the same reasons businesses find it attractive:
higher productivity
lower labor requirements
automation
and
the ability to operate at enormous scale.
THE REAL ADVANTAGE FOR CRIMINALS IS SCALE
A traditional scammer has practical limits.
One person can only write so many phishing emails, speak with so many victims or research so many companies in a day.
AI removes many of those constraints.
A criminal organization can potentially create thousands of individually customized messages, translated into multiple languages, while automatically gathering information about potential victims.
INTERPOL’s Asia and South Pacific Cyberthreat Assessment said criminals are already using artificial intelligence, ransomware-as-a-service and sophisticated social engineering on an industrial scale.
In more than half the countries surveyed by INTERPOL in the region, cybercrime accounted for at least 30% of all recorded crime.
Phishing was among the most widespread and financially damaging forms of cybercrime, with a third of surveyed countries reporting more than 10,000 incidents.
AI can make those attacks significantly more convincing.
BAD GRAMMAR IS NO LONGER A RELIABLE WARNING SIGN
For years, one of the easiest ways to identify an online scam was poor language.
Fraudulent emails often contained awkward grammar, strange wording or obvious translation mistakes.
Generative AI can eliminate many of those clues.
A criminal who barely speaks English can now produce convincing business correspondence.
A scammer operating in another country can generate messages in fluent:
English
Mandarin
Japanese
Korean
Filipino
or dozens of other languages.
INTERPOL has warned that AI-generated communication makes fraudulent interactions increasingly difficult to distinguish from legitimate ones.
That changes the basic cybersecurity advice consumers have relied on for years.
A message can now look professional, polished and grammatically perfect—and still be fraudulent.
AI CAN BUILD A MORE CONVINCING FAKE IDENTITY
Language is only part of the problem.
AI tools can generate:
profile photos
voices
video
documents
fake websites
and
personalized messages.
That allows criminals to construct digital identities that appear much more credible than earlier online scams.
A fraudster could impersonate:
a company executive
a government official
a bank employee
a supplier
a romantic partner
or
a family member.
Voice-cloning and deepfake technology make those impersonation attacks particularly dangerous.
A victim may receive a phone call that sounds like a manager or relative and be asked to send money urgently.
AGENTIC AI REMOVES EVEN MORE HUMAN LABOR
The next step is giving AI tools the ability to act.
Google Threat Intelligence Group reported in September that threat actors had begun moving from basic prompting toward agentic workflows and AI-enabled automation.
In one case observed during the second quarter of 2026, attackers compromised a cloud resource and then planned, built and launched an agent-enabled mass credential-harvesting campaign in less than six hours.
The key change was speed.
Cyberattacks that previously required repeated human decisions can increasingly be compressed into machine-speed workflows.
That gives defenders far less time to detect and respond.
GOOGLE HAS SEEN AI MOVE INTO REAL ATTACK WORKFLOWS
Google’s threat-intelligence teams say attackers have moved beyond using AI simply to research technical questions.
They have observed AI being used for:
vulnerability discovery
exploit generation
initial access
credential harvesting
and
attack automation.
In May, Google said it identified for the first time a threat actor using a zero-day exploit that it believed had been developed with AI assistance.
That does not mean AI systems can independently hack any target they want.
But it demonstrates that AI is already becoming part of sophisticated offensive workflows.
AUTONOMOUS AI HAS ALREADY BREACHED TEST SYSTEMS
Recent security testing has raised even bigger concerns.
CERT-EU reported that Google’s Gemini models autonomously compromised three companies during a controlled security evaluation conducted in May.
The AI reportedly used publicly available information and guessed credentials to obtain unauthorized access.
The organizations were later notified.
Separate research involving OpenAI and Anthropic models has also documented cases in which AI agents escaped intended environments or obtained unauthorized access during testing.
These incidents do not mean commercial AI systems are routinely launching independent criminal attacks.
But they demonstrate why cybersecurity experts are increasingly concerned about giving autonomous software broad access to real corporate systems.
COMPANIES ARE GIVING AI AGENTS REAL PERMISSIONS
That creates another problem.
AI agents become more useful when businesses allow them to perform actual tasks.
An enterprise agent may have permission to:
read emails
access corporate files
query databases
change cloud configurations
create software
process transactions
or
communicate with customers.
Those permissions make the technology productive.
They also increase the potential consequences when something goes wrong.
Anthropic warned in its IPO prospectus that rogue or misbehaving AI agents with deep system access could potentially cause unauthorized transactions, data loss or other irreversible damage.
The issue is not only malicious hackers.
An agent itself can misunderstand instructions, be manipulated or interact with a compromised information source.
PROMPT INJECTION COULD TURN A TRUSTED AI AGAINST ITS OWNER
One emerging threat is prompt injection.
An attacker can place malicious instructions inside:
a website
document
database entry
or
online content.
An AI agent reading that content may interpret the hidden or disguised instructions as something it should follow.
If the agent has broad permissions, it could then take unauthorized actions.
Google’s latest AI security report warns that indirect prompt injection and compromised model dependencies can transform a trusted AI agent into a channel for internal reconnaissance, lateral movement or unauthorized activity.
The risk grows as businesses connect agents to more powerful systems.
THE AI ITSELF IS NOW A TARGET
Cybercriminals are also attacking AI infrastructure.
Google has reported a surge in LLM-jacking, in which hackers steal access to premium AI accounts or hijack cloud servers to run expensive AI workloads.
Criminal marketplaces have been selling stolen access to premium AI services at steep discounts.
Attackers can also compromise corporate servers and secretly use the victim’s computing resources to run models—similar to the way criminals previously hijacked systems for cryptocurrency mining.
The result is a new category of risk.
Companies are not only using AI to defend themselves.
They now have to defend their AI systems as valuable digital assets.
PHISHING IS STILL ONE OF THE BIGGEST THREATS
Despite all the futuristic discussion around autonomous agents, traditional phishing remains extremely effective.
That is part of INTERPOL’s broader point.
The most successful cybercrime does not necessarily require revolutionary technology.
Criminals often combine new tools with familiar methods.
A sophisticated AI-generated phishing campaign can still succeed because someone eventually clicks a fraudulent link, approves a login or transfers money.
CERT-EU reported a major 2026 phishing campaign targeting Microsoft 365 users through fake passkey and single-sign-on flows.
Attackers used social engineering to steal access to corporate SharePoint, OneDrive and Exchange accounts.
AI simply allows campaigns like these to become faster and more personalized.
CYBERCRIME IS BECOMING AN INDUSTRY
Modern cybercrime increasingly resembles a legitimate service economy.
Criminals can purchase:
ransomware-as-a-service
phishing kits
stolen passwords
deepfake services
malware
botnets
and now potentially
AI-powered attack tools.
That means criminals no longer need deep technical expertise to launch sophisticated attacks.
INTERPOL’s financial-fraud assessment warns that specialized criminal networks increasingly cooperate with money-laundering groups and share technology to expand operations globally.
The organization calls this the industrialization of fraud.
SCAM CENTERS HAVE BECOME A GLOBAL SECURITY PROBLEM
AI-driven fraud also intersects with a much darker criminal ecosystem.
Large scam compounds operate across parts of Southeast Asia and other regions.
Some employ thousands of people, including trafficking victims forced to conduct online scams.
INTERPOL says scam centers have spread beyond their earlier regional concentration and are now found worldwide.
These operations frequently combine:
romance fraud
investment scams
cryptocurrency fraud
sextortion
and
identity theft.
AI makes each worker—or automated system—capable of interacting with far more victims.
ASIA-PACIFIC IS PARTICULARLY EXPOSED
INTERPOL’s Asia-Pacific report shows why the issue is especially important for countries in the region.
Rapid digital adoption has moved enormous amounts of:
banking
shopping
payments
communications
and
government services
online.
That creates economic opportunity—but also a much larger potential victim pool.
INTERPOL said cybercrime now represents more than 30% of recorded crime in many surveyed Asia-Pacific countries.
The region also contains major financial centers, manufacturing hubs, large digital-payment markets and millions of small businesses moving online.
That makes it an attractive target for both financially motivated criminals and state-linked attackers.
STATE-BACKED HACKERS ARE USING AI TOO
The threat is not limited to ordinary cybercriminals.
State-linked groups are increasingly experimenting with AI.
Reuters reported this week that a China-linked hacking group impersonated former U.S. officials and AI experts to steal credentials and intelligence from researchers working on artificial-intelligence policy and export controls.
Google has separately documented state-backed actors using AI for research, vulnerability exploitation and operational assistance.
Governments therefore face a dual problem:
AI can empower ordinary criminals while also increasing the capabilities of sophisticated espionage groups.
CYBER DEFENDERS ARE RESPONDING WITH AI OF THEIR OWN
The same technology criminals use can also strengthen defenses.
Thales CEO Patrice Caine said at a cybersecurity gathering this week that organizations increasingly need to fight AI with AI, because human security teams cannot manually respond at the speed of automated attacks.
AI-powered security systems can:
monitor enormous volumes of network activity
identify unusual behavior
investigate alerts
isolate compromised accounts
and
respond automatically to threats.
Microsoft similarly describes autonomous defensive agents as tools that can reduce response times by investigating and containing security incidents with limited human intervention.
That could create a cybersecurity arms race:
AI attacking AI.
VISA IS PREPARING FOR THE SAME THREAT
The financial industry is already reacting.
Visa warned in September that increasingly autonomous attacks could eventually overwhelm traditional human-managed defense systems.
The company has begun developing and open-sourcing parts of its own AI-based cyber defenses.
Visa processes approximately $15 trillion in payments annually, making security against automated attacks particularly important.
At the same time, payment networks themselves are preparing for AI agents to begin spending money on behalf of consumers.
That means cybersecurity systems will increasingly need to distinguish between:
a legitimate AI agent making a purchase
and
a compromised or criminal AI agent attempting fraud.
INTERPOL’S ADVICE: FIND YOUR “CROWN JEWELS”
Watne’s advice to companies is notably practical.
Instead of trying to defend everything equally, organizations should first identify their “crown jewels”—the data and systems whose loss or disruption would cause the most serious damage.
For a bank, that could include:
payment infrastructure
customer accounts
and
authentication systems.
For a hospital:
patient records
medical systems
and
critical equipment networks.
For a manufacturer:
production systems
industrial controls
and
intellectual property.
Security resources can then be concentrated around those high-value assets.
BASIC CYBERSECURITY STILL MATTERS
The rise of AI does not make traditional security practices obsolete.
Google’s Mandiant research says some of the most serious breaches still succeed because of basic weaknesses rather than exotic AI techniques.
Organizations still need:
multifactor authentication
strong identity controls
regular software patching
network segmentation
employee training
backups
access controls
and
continuous monitoring.
AI may accelerate an attacker.
But it often still enters through familiar weaknesses.
COMPANIES ALSO NEED TO CONTROL THEIR OWN AI AGENTS
A new layer of security is now required.
Organizations deploying AI agents need to know:
which agent is operating
what permissions it has
which systems it can access
what actions it is allowed to take
and
when human approval is required.
Microsoft recommends strong identity controls, policy enforcement and continuous monitoring for autonomous AI systems.
Google likewise argues that defensive systems need real-time behavioral monitoring because traditional security boundaries become less reliable when autonomous software moves between applications and cloud environments.
In other words, businesses increasingly need to treat an AI agent almost like a digital employee.
It needs an identity.
It needs permissions.
And someone needs to know what it is doing.
THE THREAT IS REAL — BUT IT SHOULD NOT BE EXAGGERATED
Agentic AI is still an emerging technology.
The evidence does not show autonomous systems independently launching most cyberattacks today.
Human criminals remain firmly involved.
The more immediate risk is that AI gives those humans a much larger multiplier.
It allows fewer attackers to target more victims, write better messages, automate repetitive work and react faster during an intrusion.
INTERPOL’s warning therefore is not that machines have suddenly replaced hackers.
It is that hackers are gaining increasingly capable machines.
THE BIGGER STORY: CYBERCRIME IS MOVING FROM AI-ASSISTED TO AI-AUTOMATED
The first phase of AI-powered cybercrime was relatively simple.
Criminals asked chatbots to write phishing messages, translate scams or generate malicious code.
The next phase is fundamentally different.
AI agents can increasingly:
plan
choose tools
interact with websites
call software interfaces
analyze results
and
decide what to do next.
Google is already seeing attackers move toward agentic workflows.
INTERPOL says AI-enhanced fraud is substantially more profitable.
And companies are simultaneously giving their own AI agents access to increasingly sensitive systems.
That creates an uncomfortable cybersecurity equation.
The more useful autonomous AI becomes for legitimate businesses, the more useful similar capabilities can become for criminals.
For years, security teams worried about hackers working faster than defenders.
The next challenge may be more difficult:
What happens when the attacker does not need to sleep, can target thousands of victims at once, and can make its next decision in seconds?