KONCYBER

AI & Cybercrime

AI Didn't Invent Cybercrime. It Just Got Better at the Job.

August 6, 2026

Every few months, a new AI capability makes headlines, and right behind it comes the same panic: this changes everything. I've investigated cybercrime long enough to know better than to take that claim at face value. I want to walk through why I think the framing is wrong, and where I think the real risk is actually sitting.

Old crime, new sophistication

When I look at what AI-enabled cybercrime is doing today, I don't see a new category of offense. I see the same offenses I responded to as an investigator - phishing, fraud, impersonation, disruption - carried out with better tools. The intent hasn't changed. The victim's experience hasn't fundamentally changed. What's changed is scale, speed, and how convincing the attempt is now.

That distinction matters more than it sounds like it should, because it changes what you should actually be doing about it. If AI-enabled crime were a genuinely new category, you'd need genuinely new defenses. It isn't, so you don't - you need better versions of the defenses you already know work, applied with more discipline.

Where AI actually changes the picture

Impersonation gets cheaper and better. Convincing a person that a voice, a video, or a message is real used to take skill and time. AI collapses both. That doesn't create a new crime - impersonation and social engineering are old - but it lowers the bar for who can pull it off convincingly, and raises the bar for what "looks legitimate" now has to clear.

Phishing gets tailored, at scale. The clumsy, typo-riddled phishing email is disappearing. AI can now write something that reads like it came from someone who actually knows you, in volume. Sophistication and scale used to be a trade-off for an attacker. AI removes that trade-off.

Malware adapts mid-attack. Rather than following a fixed script, AI-assisted malware can adjust its behaviour based on what it encounters, which makes detection harder and response slower, because you're no longer defending against a known, static pattern.

None of these are new crimes. They're the same crimes, with the friction removed.

Where I actually get concerned

The AI capability sitting in front of us right now is not, on its own, the part that worries me most. What worries me is what happens when AI stops being the whole story, when it's paired with computing power and infrastructure that removes the remaining constraints on scale and concealment. That combination is where I think the real step-change sits, not in whichever headline is loudest this month.

I'd rather organizations spend their attention preparing for that trajectory than reacting to the news cycle.

What this means for you, right now

Cybercrime, AI-enabled or not, still follows the path of least resistance. It goes after whoever and whatever is easiest to compromise. That hasn't changed, and it's the most useful thing to hold onto while everything else around it does.

Practically, that means the fundamentals still carry the most weight: strong, unique credentials; a workforce that's actually trained to pause before acting on urgency; verification steps for anything involving money or access, especially when the request "sounds exactly like" someone you trust; and an incident response plan that assumes the attempt will eventually be sophisticated enough to get past a first line of defence.

The closing thought

AI is not going away, and neither is its use by people who mean you harm. But panic is not a strategy, and neither is assuming today's threat is the ceiling. The organizations that come out ahead won't be the ones who reacted hardest to this month's AI headline - they'll be the ones who kept doing the fundamentals well, and stayed honest about where the real risk is actually heading next.

Get the next issue