Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ai-enabled-threat-activityphishing-campaign-intelligencebusiness-email-compromisecritical-infrastructure-threat

AI Use by Threat Actors Expands Phishing and Lowers Barriers to Cybercrime

Updated 3mo agoFirst seen Mar 20, 20264 sources

Security reporting and industry research indicate that generative AI is becoming embedded in offensive cyber operations, especially in phishing and other lower-skill attack workflows. Kaseya reported that AI-generated phishing became the default in 2025, citing widespread use of AI in phishing and BEC, higher click-through rates, and improved message quality that removes traditional warning signs such as poor grammar and repetitive templates. Bridewell's survey of UK critical national infrastructure organizations similarly found that AI-related cyber risk has become a top concern, with respondents linking it to more scalable phishing, BEC, and malware activity while also reporting broad exposure to cyber incidents and operational disruption.

An SC Media commentary pushed the trend further, arguing that AI is also reducing the expertise required for more advanced intrusions by describing a reported campaign against Mexican government entities in which an attacker allegedly used multiple chatbots for planning and troubleshooting during a prolonged data theft operation. That account is presented as opinion rather than a formal incident disclosure, but it aligns with the broader pattern that LLMs are lowering the barrier to entry for cybercrime and making attacks harder to detect because defenders must increasingly assess intent and context rather than rely on legacy indicators alone.

Share:
AI Use by Threat Actors Expands Phishing and Lowers Barriers to Cybercrime
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Mar 19, 20263mo ago

Bridewell reports attacks hit 93% of UK critical infrastructure

Bridewell's Cyber Security in CNI Report 2026 found that 93% of UK critical national infrastructure organizations experienced cyber attacks in the previous year. It also said AI-related cyber risk had become a top concern for the first time, with phishing and BEC remaining the most common attack vectors.

Kaseya says AI-generated phishing became the default in 2025

Kaseya's 2026 email security research concluded that AI-generated phishing became the baseline for cybercriminal operations in 2025. The report cited industry data saying 83% of phishing emails contained some AI-generated content and 40% of BEC attacks used generative AI.

Jan 26, 20265mo ago

Automotive sector warning highlights rising AI-driven cyber risk

A January 2026 report highlighted that cyber risk in the automotive sector was accelerating due to the raised threat posed by AI tools. The warning reflected growing concern that AI was increasing attacker capability across industry verticals.

Jan 25, 20265mo ago

Attacker exfiltrates 150 GB of Mexican government data

During the campaign that started in late December 2025, the threat actor ultimately exfiltrated about 150 GB of data, including records tied to 195 million taxpayers. Reporting said the attacker used more than 1,000 prompts and also consulted ChatGPT for help with lateral movement, credential use, and reducing detection risk.

Dec 25, 20256mo ago

AI-assisted campaign begins against Mexican government entities

In late December 2025, an unknown actor began a month-long intrusion campaign targeting multiple Mexican government entities using Anthropic's Claude Code and other AI tools. The operation showed how generative AI could help a relatively low-skill attacker carry out more advanced offensive activity.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

5 LINKEDOpen in app
Organizations
5 linked
Trend MicroInternational Business MachinesKaseyaGoogleINKY
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.