SendTech Times
Analysis
SYSTEMS SHIFT:

AI Reprices Cybercrime Risk Around Phishing And Deepfakes

Newsroom brief

A Forbes contributor analysis by Dr. Jonathan Reichental, republished by Yahoo Finance, says generative AI is reducing the cost and skill needed for phishing and social-engineering attacks. The piece frames AI cyber risk as an operating-control problem for payment approvals, access requests, employee training, simulations, defensive tools and board-level governance.

Verified against source materialEdited by SendTech Times Cybersecurity DeskSource: Forbes
AI Reprices Cybercrime Risk Around Phishing And Deepfakes
Image source: Forbes

A Forbes contributor analysis by Dr. Jonathan Reichental, republished by Yahoo Finance, says artificial intelligence is changing cybercrime less by inventing new attacks than by making old ones cheaper, faster and harder for companies to verify.

The argument is economic as much as technical.

The analysis describes cybercrime as a risk-management problem already projected to cost $14 trillion in 2028, while phishing and social-engineering attacks each cost an enterprise about $4 million per breach.

Generative AI changes that calculation because attackers can automate research, targeting and message production while preserving the credibility that once required skilled human operators.

The Cost Curve Moves First

The strongest evidence is the gap between ordinary phishing and AI-assisted deception.

An academic study cited in the analysis found AI-automated phishing emails performed at the level of human experts and reached a 54 percent click-through rate, compared with 12 percent for generic phishing emails.

That changes the attacker's calculation.

If the marginal cost of a convincing spear-phishing email falls, more campaigns can be built around specific employees, real projects, payment workflows and internal language.

The risk is not only that fraudulent emails look better.

It is that the production cost of believable fraud falls while the possible return remains high.

Spear phishing shows the point clearly.

Messages once requiring manual research can now be personalized at scale, with AI helping gather information, identify targets and shape a request around a company's normal processes.

That makes the attack surface broader than the inbox.

The economics are the warning.

Old Warning Signs Lose Value

Traditional awareness training has often taught employees to spot poor spelling, awkward grammar, odd formatting and generic wording.

The analysis warns that AI weakens those signals by producing cleaner messages and by giving attackers a way to mimic organizational context.

A finance employee, for example, may receive a request that appears to come from a senior executive, refers to a real project and asks for payment to a bank account.

The attack type is not new, but AI can make the request feel routine enough to pass through a busy approval chain.

That shifts phishing from an email-filter problem into a business-process problem.

The question for companies is no longer only whether a message looks suspicious.

It is whether payment approvals, data-access requests and executive instructions have verification paths strong enough to withstand a believable message.

Deepfakes Extend The Same Risk

The Hong Kong deepfake case cited by Reichental shows the same cost shift moving beyond text.

The cited case involved an employee who joined a video conference, believed the call included company executives and transferred $25 million before learning the participants were AI-generated impersonations.

The case illustrates how trust can become part of the attack surface.

A convincing executive impersonation can move the target from system access to the decision process around payment approval.

Voice, video and chat channels can all become routes into the same payment or access workflow.

For security leaders, that means awareness training alone is too narrow.

Employees still need training, but the higher-value control is a second path for confirming high-consequence actions before money moves, credentials change or sensitive data is released.

The Response Is Operational

The five recommendations point toward a broader operating model.

Training needs to reflect AI-driven phishing and social engineering.

Payment, data-access and workflow approvals need to be tested against more realistic deception attempts.

Incident-response exercises should include AI-powered scenarios rather than only conventional breach playbooks.

The recommendations also call for defensive tools designed for AI-enabled attacks, including updated secure email gateways and malicious-traffic controls.

But the governance recommendation is the more important signal: AI cyber risk needs to sit inside risk management, digital trust and innovation oversight, not only inside the security team.

The public record still has limits.

The analysis does not provide a company-by-company benchmark for AI-driven losses, and the cited phishing study sample is not identified in the text available to readers.

Exposure will vary by sector, approval design and employee access patterns.

The analysis does not provide a sector-by-sector loss benchmark for AI-generated phishing or deepfake attempts.

Until that data is clearer, the practical question is how quickly businesses can add verification controls around payment, data-access and executive-approval workflows.

Share this article
inXf

Related articles

More
Check Point CEO Warns AI Is Compressing Cyber Defence Timelines
Cybersecurity

Check Point CEO Warns AI Is Compressing Cyber Defence Timelines

Frontier Enterprise interviewed Check Point CEO Nadav Zafrir on how AI is accelerating phishing, vulnerability exploitation and remediation demands while pushing security teams toward CTEM, AI firewalls and open-platform consolidation.

APAC Cybersecurity Spending Turns Toward Identity Risk
Cybersecurity

APAC Cybersecurity Spending Turns Toward Identity Risk

Identity governance is moving into the center of APAC security planning as session theft, AI-enabled impersonation and uneven regional maturity weaken older perimeter-heavy defenses.

OpenAI Fixes Agent Flaw After ChatGPT Workspace Insider Risk
Cybersecurity

OpenAI Fixes Agent Flaw After ChatGPT Workspace Insider Risk

SecurityWeek reported that OpenAI fixed the AgentForger flaw in ChatGPT Workspace Agents after Zenity Labs showed how a phishing link could create a hidden autonomous agent with access to already-authorised connectors.

Kratos Takedown Leaves Microsoft 365 Session-Theft Risk Unfinished
Cybersecurity

Kratos Takedown Leaves Microsoft 365 Session-Theft Risk Unfinished

German and US law enforcement took more than 200 Kratos phishing-kit servers offline, but investigators still tie the service to roughly 1,800 customers and session-theft attacks against Microsoft 365.

Fake Calendar Invites Push Malware Past Email Defenses
Cybersecurity

Fake Calendar Invites Push Malware Past Email Defenses

Sublime Security tracked sharp month-over-month growth in ICS phishing, where malicious calendar invitations exploit default settings in Outlook, Gmail and Apple Mail.

AI Attack Speed Puts Identity Governance At Center Of APAC Security
Cybersecurity

AI Attack Speed Puts Identity Governance At Center Of APAC Security

Frontier Enterprise analysis says AI-assisted attacks are compressing response windows, pushing zero trust, privileged-access controls and non-human identity governance into operational security.

WindRelay And SpyNote Pair Drives Android Phone Fraud Workflow
Cybersecurity

WindRelay And SpyNote Pair Drives Android Phone Fraud Workflow

BleepingComputer reported that Group-IB investigated a WindRelay and SpyNote Android malware combination that used social engineering, remote device access and NFC relay fraud to move from a phone call to financial theft.

OpenAI Widens Cyber AI Access Through Vetted Security Partners
Cybersecurity

OpenAI Widens Cyber AI Access Through Vetted Security Partners

OpenAI is giving approved security vendors and services firms access to cyber AI models while keeping Astra under tighter review for potential misuse risk.

Keep Reading

More Stories

Latest
Ethereum Testnet Update Targets 200 Million-Gas BlocksCrypto/Web3Oct 6, 2026Ethereum Testnet Update Targets 200 Million-Gas BlocksEthereum developers released Prysm 7.2.1 so the Sepolia trial of Glamsterdam can test 200 million-gas blocks, more than three times the prior 60 million setting, before any main-network change.Kepler Targets 2027 Production for HBM Replacement MemoryCloud & Data CentersOct 6, 2026Kepler Targets 2027 Production for HBM Replacement MemoryEE Times reports that Kepler Computing is preparing 3D ferroelectric memory for 2027 production, promising higher capacity and bandwidth per watt while limiting reliance on advanced-node lithography.Yokogawa Opens Singapore Hub For Industrial Cyber ResilienceCapital & PolicyOct 6, 2026Yokogawa Opens Singapore Hub For Industrial Cyber ResilienceYokogawa Engineering Asia has launched a Singapore center focused on OT cyber resilience, training, response planning and recovery coordination for Southeast Asia, Oceania and Taiwan.ClickFix Attack Uses Browser Cache To Hide Malware PayloadCybersecurityOct 6, 2026ClickFix Attack Uses Browser Cache To Hide Malware PayloadMicrosoft Threat Intelligence traced a ClickFix cache-smuggling method that preloads malware into browser caches, then uses file size checks and a pasted Run command to launch later credential-theft stages.VOA Tests Six-Month Startup Buildout Before Funding DecisionsFintech & Digital PaymentsOct 6, 2026VOA Tests Six-Month Startup Buildout Before Funding DecisionsTechCabal’s interview with VOA Venture Partners founder Victoria Olayide Adesanya describes a six-month build programme that lets the firm work inside African financial-infrastructure startups before deciding whether to invest.Bitcoin Holds $86,000 As Dollar Index Hits 18-Month HighCrypto/Web3Oct 6, 2026Bitcoin Holds $86,000 As Dollar Index Hits 18-Month HighCoinDesk reported that bitcoin stayed near $86,000 while the U.S. Dollar Index reached about 102.5, with U.S. rate expectations and European political risks strengthening the dollar backdrop.Google Freezes OSS Bug Bounty Reports After AI Submission FloodCybersecurityOct 6, 2026Google Freezes OSS Bug Bounty Reports After AI Submission FloodGoogle has stopped accepting new product vulnerability reports in its OSS VRP after invalid automated submissions swamped reviewers, while older reports and some Cloud VRP routes remain open.Fleuret AI Raises €4M For Continuous AI Pentesting PlatformCybersecurityOct 6, 2026Fleuret AI Raises €4M For Continuous AI Pentesting PlatformTech.eu reported that French startup Fleuret AI raised €4 million in pre-seed funding to develop an agentic-AI platform that turns penetration testing into a continuous security process.GFT Analysis Says AI Documentation Can Cut Maintenance Work 30%Fintech & Digital PaymentsOct 6, 2026GFT Analysis Says AI Documentation Can Cut Maintenance Work 30%A GFT Technologies analysis says AI-linked software documentation can cut maintenance effort and speed developer onboarding when knowledge assets stay synchronized with code changes.Schneider Electric Lines Up $22.6 Billion PTC DealAIOct 5, 2026Schneider Electric Lines Up $22.6 Billion PTC DealSchneider Electric plans to buy PTC in a cash transaction valuing the US engineering software provider’s equity at about $22.6 billion, adding product-lifecycle software to its industrial AI push.Aggarwal Pledges Ola Electric Stake To Fund ₹1,000 Cr Rights IssueCapital & PolicyOct 5, 2026Aggarwal Pledges Ola Electric Stake To Fund ₹1,000 Cr Rights IssueOla Electric founder Bhavish Aggarwal pledged 20 Cr shares to finance his participation in a rights issue that forms part of a larger ₹1,500 Cr fundraising plan.Natrona Schools AI Review Puts Student Privacy Ahead Of Classroom Tool UseAIOct 5, 2026Natrona Schools AI Review Puts Student Privacy Ahead Of Classroom Tool UseNatrona County trustees questioned whether teacher AI tools expose student data, even as existing district rules already ban unauthorized generative AI use by students.