“TRUST STARTS & ENDS WITH THE TRUTH”
Matt is both the company founder and a nationally renowned private investigator. Matt is an intelligence specialist who excels in detecting and preventing the illegal interception of communications and in providing high-tech covert surveillance. Matt has years of hands on experience in the investigation industry and has developed a reputation for incorporating state of the art technology and innovative ideas to provide effective solutions for his clients. Matt also serves as Treasurer for the Executive Board of Directors of FALI, The Florida Association of Licensed Investigators.
AI-generated cyber attacks are cyber attacks in which artificial intelligence creates or operates part of the attack itself, including the phishing email, the cloned voice, the malware code, or the exploit. Instead of replacing hackers, AI speeds them up and lowers the skill required. The result is fraud and intrusion attempts that are faster, cheaper, and far harder to spot.
An AI-generated cyber attack is any attack where a machine learning model produced or ran a working piece of it. That piece might be the message that reached your inbox, the voice on the other end of your phone, the code that executed on your server, or the decision about what the attacker tries next.
It helps to separate artificial intelligence cyber attacks into two tracks, because they hurt you in completely different ways.
Attacks on people use AI to manufacture trust. A cloned voice, a fabricated video call, a flawless email in your CFO’s exact writing style. Nothing is hacked. Someone is simply convinced.
Attacks on systems use AI to write and rewrite code. Malware that changes its own signature, exploits built from a model reading source code, tooling that adapts mid-intrusion.
Most of the cases that come through our door sit on the first track. The money moves because a person believed something, not because a firewall failed.
AI is used at nearly every stage of an attack, from picking the target to writing the malware to running the intrusion. The table below maps what that looks like in practice.
| AI-Generated Cyber Attacks | What AI does |
|---|---|
| Reconnaissance | Builds org charts and identifies who has authority to approve payments |
| Lure creation | Writes personalized, error-free phishing in seconds, in any language |
| Impersonation | Clones a voice from a short audio sample, generates video and images |
| Code | Writes malware and rewrites it repeatedly to evade signature detection |
| Exploitation | Reads source code and surfaces logic flaws that scanners miss |
| Operation | Executes steps of the intrusion with limited human supervision |
The reconnaissance line is the one people underestimate. Cyber attacks using AI rarely start with code. They start with a model being asked who handles wire approvals at a specific company, and what that person’s writing style looks like.
They are happening, and the federal government now counts them separately. The FBI’s 2025 Internet Crime Report added artificial intelligence as a tracked descriptor for the first time, logging 22,364 AI-related complaints and $893,346,472 in reported losses.
For scale, IC3 received 1,008,597 complaints in 2025 totaling $20.877 billion, a 26 percent jump over the prior year.
One important caveat about that AI number. It reflects only the complaints where a victim or an analyst recognized AI involvement. The FBI notes in the same report that overall investment scam losses exceeded $8 billion while the AI-flagged portion sat at $632 million, which suggests most victims never learn what actually built the thing that fooled them. Treat $893 million as a floor.
The systems side has caught up faster than most people expect. In May 2026, Google Threat Intelligence Group reported the first zero-day exploit it believes was developed with AI, a two-factor authentication bypass that criminal actors planned to use in a mass exploitation event. The same research documented malware that calls a language model mid-operation to decide what to do on an infected device.
On the enterprise side, IBM’s 2026 X-Force Threat Intelligence Index recorded a 44 percent increase in attacks that began by exploiting public-facing applications, attributed in part to AI-assisted vulnerability discovery.
It looks ordinary. That is the entire problem. Here are three patterns we see repeatedly.
The voice on the phone. A grandparent gets a call. The voice is unmistakably their grandson, panicked, in some kind of legal trouble, asking them not to tell his parents. Roughly thirty seconds of audio scraped from a public video is enough to build that clone. IC3 recorded more than $5 million in losses to these distress scams in 2025.
The closing that goes wrong. A buyer is days from closing on a house. An email arrives in an existing thread, matching the tone and signature of the title company, with updated wiring instructions. The account belongs to a criminal. Real estate fraud accounted for $275 million in reported losses last year, and IC3’s own casework includes a Missouri senior who wired more than $1.3 million on exactly this pattern.
The vendor who is not your vendor. A business receives an invoice from a supplier it has paid for years, with a note about a bank change. Business email compromise remains the second most costly crime category in the country at $3,046,598,558 across 24,768 complaints, and 86 percent of that money moves by wire or ACH. The AI-flagged share was $30.2 million in reported losses.
When funds leave an account this way, the work is financial, not just technical. Our team handles that through tracing where the money actually went, following the wire trail through receiving accounts, money mules, and crypto conversion.
Everyone with money or access, which is a wider group than most people assume. The old assumption that attackers only pursue large enterprises stopped being true when generating a thousand tailored lures became nearly free.
Florida is a heavier target than most states. IC3 logged 71,843 complaints from Florida in 2025 with $1,596,138,595 in reported losses, third in the country behind California and Texas.
The groups we see most often:
For companies where a leaked conversation or a spoofed executive would be genuinely damaging, it is worth having someone audit how exposed your leadership communications are before an incident forces the question.
Not sure whether what you received was real or synthetic?
That question usually has an answer, and it is usually still sitting inside the file. We examine the video, audio, or message directly and tell you what we find.
See how an AI threat investigation works
Confidential. No obligation.
You often cannot tell from content alone, which is why the reliable checks are behavioral rather than technical. Watch for these:
Here is the honest part. Consumer detection tools perform reasonably well on clean recorded audio and poorly on a live compressed phone call, which is the exact situation where you need them. Do not build your safety around a detector.
Forensic verification is different work. We run frame-by-frame video inspection, audio waveform and cadence analysis, and metadata and file history review, then compare the suspect file against verified recordings of the real person. If you need to verify whether a recording was synthetically generated, that is a lab question with a documented answer, not a judgment call.
Move on the money first, then the evidence. The order matters more than most people realize.
Within the first hour. Call your bank’s fraud line and request a recall. Do not email. Speed is the single biggest factor in recovery. IC3’s Recovery Asset Team initiated 3,900 fund-freeze actions in 2025 and froze $679 million of $1.16 billion in attempted theft, a 58 percent success rate, and nearly all of that depended on early reporting.
Within 24 hours. File at ic3.gov with full transaction details. For business losses above roughly $50,000, contact your local FBI field office directly and ask about the Financial Fraud Kill Chain.
Before anyone touches the devices. Do not wipe, reset, or reinstall. Do not delete the messages, and do not confront the sender in a way that prompts them to scrub the trail. Preserve original files rather than screenshots where you can, because the metadata is often the case. Court-admissible forensic imaging has to happen before the evidence degrades, and it degrades quickly.
If you are on the other side of this, meaning the digital evidence is being pointed at you, that is a separate discipline. We support attorneys and clients defending against a cybercrime allegation by testing how the evidence was collected and whether it says what the other side claims.
Build verification into the process instead of relying on people to spot a fake. Every AI cybersecurity threat above depends on someone acting without confirming through a second channel. Close that and most of the attacks fail.
Controls that hold up:
For businesses that want to know where the actual gaps are rather than guessing, a full assessment covering systems, policies, and staff training is what our cybersecurity consultants do.
What is an AI-generated cyber attack?
An AI-generated cyber attack is an attack where artificial intelligence produced or operated part of it, such as writing the phishing email, cloning a voice, generating malware, or discovering the vulnerability being exploited. AI does not replace the attacker. It removes the skill and time barriers that used to limit them.
Can AI create malware on its own?
Partly. Google Threat Intelligence Group has documented malware families that use AI-generated decoy code to hide their function and one Android backdoor that queries a language model during operation to decide what to do next. Human operators still direct the campaign, but the code writing is increasingly automated.
How do hackers use AI to steal money?
Mostly through impersonation. AI writes convincing emails from executives and vendors, clones voices for emergency calls, and generates fake investment platforms. The FBI logged $893 million in AI-related losses in 2025, with the largest share tied to investment fraud and business email compromise.
Can you detect an AI-generated voice on a phone call?
Not reliably in real time. Detection tools perform well on clean recorded audio and much worse on live compressed calls. The dependable method is to hang up and call the person back on a number you already have, then have any recording examined forensically afterward.
Are AI-generated cyber attacks illegal?
Yes, when they cause a recognized harm. Fraud, wire fraud, identity theft, and extortion statutes all apply regardless of whether AI built the tool. The synthetic media itself sits in a more complicated legal space, which we cover in detail in our guide to where the law currently stands on synthetic media.
What should a business do first after an AI-enabled wire fraud?
Call the bank’s fraud line within the first hour and request a recall, then file at ic3.gov with full transaction details the same day. Preserve every email header and device untouched. Recovery odds fall sharply once funds move past the first receiving account.
AI-generated cyber attacks are attacks where artificial intelligence builds or runs part of the operation, from the phishing email to the cloned voice to the malware itself. They split into two tracks: deception aimed at people, and code aimed at systems. The FBI recorded 22,364 AI-related complaints and $893 million in losses in 2025, its first year tracking the category, and the real figure is almost certainly higher because most victims never learn AI was involved. Detection tools are unreliable on live calls, so verification through a second channel is the defense that actually works. If money has already moved, the first hour matters more than everything that follows.
If money moved, or a fake recording is being used against you, the window for tracing it is measured in days.
Southern Recon Agency traces stolen funds, verifies whether media was synthetically generated, and documents findings your attorney can take to court. We will tell you what is realistically recoverable and what your options are.
Request a confidential case review
Call (844) 307-7771. Every case is handled confidentially by a licensed Florida investigator.
Matt Aubin, CDFE, is the founder of Southern Recon Agency, a Florida-licensed private investigation firm (License A1400197) specializing in AI threat investigations, digital forensics, and technical surveillance countermeasures. He is a Certified Digital Forensics Examiner and serves as Treasurer on the Executive Board of Directors of the Florida Association of Licensed Investigators. Southern Recon Agency serves clients throughout Orlando, Tampa, Sarasota, and Osceola County.
This article is for general information and is not legal advice. For guidance on a specific situation, consult a licensed attorney in your state.