When AI Writes the Bait: How LLMs Are Fueling a New Wave of Phishing
Attackers are using large language models to craft hyper-personalized lures and automate fraud at scale. Defenders must move beyond rules and retrain risk models.
Attackers are using large language models to craft hyper-personalized lures and automate fraud at scale. Defenders must move beyond rules and retrain risk models.

Illustration by IMF Alpha editorial · Reviewed by Pedro Marini
A new breed of social engineering has arrived. Large language models are no longer lab curiosities; they have become practical tools for crafting highly targeted phishing, automating scam campaigns, and making sophisticated fraud accessible to people with little technical skill.
Security teams have seen waves of innovation before — mass-email spam, fileless malware — but this feels different. AI can mimic tone, pull context from public sources, and spin believable narratives in seconds. The outcome is not simply more phishing; it's phishing that sounds right, every time.
Why this matters now
The defender's dilemma
Static rules, blocklists, signature filters — they still catch yesterday's attacks. But fluent, context-aware text slips through. Defenders are also using AI to spot anomalies, which creates an arms race: prompts get tuned, evasions get iterated. In practice, though, the contest is messier than headlines suggest. Models help, but they also introduce new failure modes and fresh blind spots.
Practical steps for security leaders
A few counterpoints worth noting
What investors and boards should watch
The takeaway
AI has altered the economics of deception: language craft and adaptive workflows scale cheaply now. That does not leave defenders powerless. It does mean priorities must shift — strengthen identity, assume compromise, and lean on behavior-based detection. Expect the next major breach to begin with social manipulation, and only later become technical.
Pedro Marini

From fraud models to credit scoring, financial firms increasingly prefer synthetic customer data to train AI — a pragmatic fix that raises fresh privacy and accuracy questions.

From Wall Street simulations to synthetic patient charts, U.S. firms are using fake data to train serious AI — and investors, compliance teams, and regulators are taking note.

Local models, smarter silicon, and privacy demand are driving a shift from remote AI to the handset. Here’s who wins, who loses, and why it matters now.