AI-assisted reconnaissance: Why everyone could be a viable target for fraud
AI is lowering the barrier to entry for cybercriminals by automating open-source intelligence (OSINT) gathering, enabling more sophisticated and scalable fraud schemes. AI tools can quickly analyze publicly available information – including images, videos, and personal details – to craft highly convincing phishing emails, deepfake impersonations, and social engineering attacks. This poses a significant risk to both individuals and organizations, particularly as the line between personal and professional lives blurs.
AI is fundamentally changing the threat landscape, one model at a time. The pace of technological advancement means that activities once requiring significant skill and time from a cybercriminal can now be accomplished in a fraction of that time by someone with limited experience. This is lowering the barrier to entry for cybercriminals. This trend is particularly evident in the realm of open-source intelligence (OSINT) gathering.
Historically, OSINT – collecting publicly available information – was a specialized skill, primarily used by military and intelligence agencies. It involved significant time and effort to find relevant information, correlate data, and determine how to use it strategically. With the advent of the web and social media, OSINT became a familiar tool for researchers and threat actors alike. However, until AI came along, there was often a major bottleneck. An adversary needed to spend considerable time finding their targets’ public-facing accounts, interests, friends, family, and colleagues. They might have to use dedicated tools or trawl through countless websites and accounts, correlating and cross-checking information, and deciding how to use it in an attack.
AI tools have largely removed that bottleneck by processing information at machine speed. They can find publicly available material from across the web, link it to their potential victims, and map relationships between them and others. It’s particularly good at hunting down unstructured information – especially images and videos. You don’t have to be an OSINT specialist any longer to do this kind of work.
Putting the pieces together at scale is now possible, and this has serious implications. Fraudsters can now easily collect publicly available information on you to make social engineering more convincing and scams more scalable. Consider:
- A phishing email designed to trick you into sharing your logins or clicking through and unwittingly installing malware. It would be much more convincing if it contained personal details such as your workplace or child’s school, a recent event you were at, or some contextually relevant news you’ve posted like a birthday or a recent holiday. All of that information may be in the public domain and easy to gather at scale.
- A video or phone call impersonating your voice/face might be used to trick a loved one into believing you’re in danger. Scammers can use these deepfakes to ask for money in your “voice”, or to pretend that you have been kidnapped and need them to pay a ransom to ensure your safety. They might even use a deepfake of you to create an obscene video which they threaten to send to your contacts unless you pay up. This kind of sextortion scheme is becoming more commonplace. In the UK, hundreds of under-18s have reported being victimized this year.
Large language models (LLMs) are expert at piecing together the kind of information that fraudsters need to make their scams work. They can profile large numbers of potential victims in little time, collecting relevant pictures, videos, and info on personal interests, work, and family and friends that could be leveraged.
AI can also help to design the social engineering scripts used by fraudsters, enabling them to sound convincing over email/social media or other channels even if they’re non-native speakers. It offers an end-to-end fraud pipeline.
Trouble at work is also a concern. The boundary between work and home has become increasingly blurred in recent years, especially as many of us work in a hybrid setup. We might use personal devices and home addresses for corporate activities. And of course, linking our professional and personal social media accounts is a simple task for AI.
All of which means that reconnaissance efforts can have an impact on your professional life. For example, fraudsters could use personal information to craft a social engineering attack designed to harvest your work credentials or information. Or they could target your colleagues when you’re on holiday, knowing that you may not be contactable to verify fraudulent details. This is a useful time to launch a business email compromise (BEC) attack.
Losing your personal information is one thing. But OSINT efforts which have a corporate dimension could potentially have a serious impact on your professional reputation and career.
What you can do about AI-powered OSINT is limited, but not impossible. Once information about you is in the public domain, it can be extremely challenging to request its removal, especially as it may have been republished in other places. Old social media photos are easier to remove, but few of us have the time to trawl through our entire digital life to remove anything potentially useful to criminals.
It’s better therefore to focus on the things that are within your power to change. Consider the following:
- Ensure your social profiles can’t be publicly accessed, to limit AI’s ability to find any information or images/videos contained within
- Be judicious in what you share on social media; things like birth dates, children’s schools, holidays and similar events should be off limits
- Be aware that photos may contain information in them that could be used to identify addresses, vehicle details etc
- Avoid posting anything that may be used to link your personal and professional lives
- Use multi-factor authentication and strong, unique passwords to add an extra layer of security on your accounts
- Don’t accept friend/follower requests from anyone you don’t know. Or if you’re curious, approach them via a separate channel
AI is changing many facets of our lives for the better. But it comes with risks we’re only just waking up to. Caution is always the best policy. It pays to work under the assumption that anything you publish could be read by AI. Act accordingly, and encourage your friends and family to.