AI Turns the Scammer Trap Back on Cybercriminals

AI is giving cybercriminals sharper tools, but security teams are turning the same technology against them. A new wave of AI systems is moving beyond experiments and into active defenses that waste scammers’ time, collect intelligence, and expose how modern fraud works.
That fight matters because scammers initiate billions of messages and calls each year, while AI-powered scams are becoming harder to spot. The attacks reach victims through social media platforms, text messages, emails, voice cloning, and phone calls, creating a relentless stream of opportunities for fraud.
AI Bots Are Becoming the Perfect Scam Targets
Apate, an Australian company, has spent the last two years building a system that diverts phone scammers into calls with AI bots. The platform now has around 350,000 bots, each designed to keep fraudsters engaged instead of allowing them to reach human victims.
Dali Kaafar, CEO of Apate, describes the strategy with a striking goal: “What we really like to think is that we’re building the perfect victims for scammers.”
The system does more than consume a scammer’s time. Apate has collected more than 250,000 pieces of information about fraudsters in real-time, turning conversations with its bots into a stream of intelligence about cybercrime.
That approach shows how AI platforms are turning experiments into real tools in the fight against cybercrime. Instead of waiting for every suspicious call to reach a potential victim, defensive systems can create a controlled interaction that keeps the scammer talking and captures information about the operation.
AI Is Fueling a Faster, Harder-to-Spot Fraud Machine
The danger runs in the opposite direction too. Cybersecurity experts warn that artificial intelligence is making fraud nearly impossible to detect, giving scammers more sophisticated tools, hyper-personalized approaches, and relentless pitches that can operate at a scale humans cannot match.
Chester Wisniewski, a cybersecurity specialist at Sophos, describes the impact in direct terms: “With AI powering these scams, it’s just like rocket fuel, making them faster and more sophisticated.”
Scammers can impersonate company CEOs, members of financial institutions, or charitable foundations, drawing victims into interactions that feel familiar and trustworthy. Deepfakes use AI-enhanced digital images, video, or audio to impersonate trusted figures, widening the gap between what looks real and what is real.
Deepfake campaigns have included a CEO calling an employee to request wire transfers. Grandparent scams can use a deepfaked phone call that claims a grandchild is in trouble. These schemes connect advanced AI tools to urgent requests, pushing victims toward a decision before they stop to question the exchange.
Open source honeypot providers have also incorporated large language models into their systems. These honeypots give security efforts another way to observe scam activity, while AI helps create interactions that can hold a fraudster’s attention.
But the threat extends beyond calls and messages. Wisniewski said, “They are just breaking in and stealing databases. Hundreds of millions of records are stolen every week from hacked websites where many of us have shopped or done business with.”
The Human Pause Could Still Break the Attack
Adam Evans, senior vice-president and chief information security officer at RBC, points to the economic engine behind the surge. “The software platforms they use to orchestrate scams are becoming cheaper. They can cast a wider net and automate a lot of the things that they would typically need a human to do, which means they can operate 24-7, 365 days a year.”
Cheaper platforms let scammers reach more people, automate more tasks, and maintain pressure without stopping. AI is making scams faster and more sophisticated, while stolen records give criminals information that can support more convincing contact.
Evans also identifies a moment where victims can disrupt the process: “When I talk to people who have been compromised or who clicked on a suspicious link, they generally had a gut feeling that something wasn’t right, but they didn’t pause and take a breath and look at it in a critical way.”
That pause now matters against messages, calls, emails, social media contact, voice clones, and deepfakes. A familiar voice or trusted identity no longer proves that the person on the other side is genuine.
The technology race is moving in both directions. Scammers are using AI to sharpen fraud, while Apate and open source honeypot providers are using AI systems to engage, observe, and collect information from cybercriminals. The next stage of cybersecurity will depend on which side turns that momentum into the stronger defense.
Based on



