Tuesday, October 6, 2026 Breach Index $4.5B lost to breaches in 2026 · 104 breaches made public
How-To GuideCybersecurityDefenses Explained

How to Prevent AI Cyber Attacks? – The Curious Lab

how to prevent ai cyber attacks

How to Prevent AI Cyber Attacks? A Simple Guide for Everyone

An AI cyber attack doesn’t look like a robot breaking into your computer.

It looks like your boss on a video call. It sounds like your son on the phone, crying and asking for money. It reads like a perfectly written email from your bank. Note that none of these need the attacker to break anything. They only need you to believe what you see and hear.

This is what makes AI attacks so different. For years, we told people to look for spelling mistakes, a strange voice or a blurry photo. AI has removed most of those signs. So the old checks don’t work anymore, and we need new ones.

In this post, we will see what an AI cyber attack is, the main types, how much money people are losing to them, how to prevent them at home and at work, which tools help, and what to do if you have already been tricked.

No technical background is needed to understand this. We have written it for the common person, with basic technical details added along the way for cybersecurity enthusiasts.

What is an AI cyber attack?

An AI cyber attack is any attack where artificial intelligence does part of the work.

Most people picture only one kind. In reality, there are two.

  • Attacks made with AI: the attacker uses AI as a tool to trick you. A cloned voice, a fake video, a well-written scam message or malware that changes its own code.
  • Attacks on your AI: the attacker tricks the AI tools that you use, such as a chatbot, an AI browser or an AI assistant that can read your email. The AI then works for the attacker instead of you.

In the first kind, AI is the attacker’s weapon. In the second kind, your own AI assistant becomes the attacker’s helper.

how to prevent ai cyber attacks

Two kinds of AI cyber attacks. In one, AI is the weapon. In the other, your own AI tool is the target.

Note that the goal hasn’t changed. The attacker still wants your money, your passwords or access to your company. AI only changes how convincing the trick looks and how many people the attacker can reach at once.

Why are AI attacks harder to spot?

Basically, AI removes the clues that used to give scams away.

The writing is now perfect. In December 2024, the FBI warned that criminals use AI to fix the spelling and grammar mistakes that used to be warning signs of fraud. They also use it to translate scams into any language. So a message from an attacker in another country can now read like it was written by your colleague.

The voice and face can be copied. Voice cloning means using AI to create a copy of a real person’s voice from a short recording. A deepfake is a fake video, image or voice made with AI that shows a real person doing or saying something they never did. In a peer-reviewed study from UC Berkeley, listeners correctly identified an AI-cloned voice only about 61% of the time, which is not much better than a coin toss.

The messages work better. Microsoft’s 2025 Digital Defense Report found that phishing emails made with AI got a 54% click rate, compared with about 12% for ordinary phishing. That is roughly 4.5 times more effective.

It costs the attacker almost nothing. One attacker with AI can write thousands of personal messages, in many languages, in the time it once took to write ten.

how to prevent ai cyber attacks

The old warning signs are fading. The new warning sign is the request itself.

So, checking whether a message looks real is no longer enough, because almost everything can look real now. The useful check is what the message is asking you to do. We come back to this in the protection section.

Types of AI cyber attacks:

We group AI attacks into four families: fake voices and faces, AI-written tricks, attacks on your AI tools, and AI-powered hacking.

how to prevent ai cyber attacks

Four families of AI attacks. The first two target you. The last two target your tools and your computer.

Family 1 — Fake voices and faces

Family emergency calls: A call or voice message from someone who sounds exactly like your child, parent or partner. They say they are in trouble, in an accident or under arrest, and they need money right now. The FBI lists short cloned audio clips of a family member in an emergency as one of the ways criminals use AI.

Fake bosses on video calls: The attacker pretends to be a senior manager on a video call and asks for an urgent payment. This is exactly what happened at the engineering company Arup in 2024, which we tell as a real story near the end of this post.

Fake officials: In May 2025, the FBI warned that attackers were sending AI-generated voice messages that pretended to come from senior US officials. In September 2026, it warned that scammers now use AI to appear as police and government officials on video calls. Between January 2025 and July 2026, the FBI received nearly 61,000 complaints about law enforcement and government impersonation, with losses of more than $1.6 billion.

Fake celebrities and experts: AI-made videos of famous people “recommending” an investment or a trading app. The FBI warned about this in 2024, and investment fraud is where most AI-related money is lost.

Family 2 — AI-written tricks

Perfect phishing: Emails and texts that are well written, personal and in your language. AI can also read your public profiles and mention your real job, your real colleagues or a real event you attended.

Chatbot scammers: In romance and investment scams, the person chatting with you for weeks may be partly or fully an AI. It never gets tired, never makes mistakes and can talk to hundreds of victims at the same time.

Fake job candidates: Some people now use deepfake video and AI-written CVs to get remote jobs under a false identity, then use that access to steal data. Gartner predicts that by 2028, one in four job candidate profiles worldwide will be fake.

Family 3 — Attacks on your AI tools

This family is the newest, and it affects anyone who uses an AI assistant.

Prompt injection: An instruction is something you tell the AI to do. In prompt injection, the attacker hides their own instructions inside a web page, an email or a document. When your AI tool reads that content, it may follow the attacker’s hidden instructions instead of yours. The hidden text can even be white text on a white background, so you never see it.

This becomes dangerous when the AI can take action. An AI agent is an AI tool that can act for you, such as an AI browser that can click, fill in forms, read your email or make purchases. Security researchers have shown that hidden instructions on a web page could make an AI browser fetch login codes from the user’s email when the user simply asked it to “summarize this page.”

Note that this is not a small bug that will be fixed next week. In December 2025, the UK’s National Cyber Security Centre (NCSC) warned that prompt injection may never be fully fixed, because AI models don’t truly separate information from instructions. In May 2026, the cybersecurity agencies of the US, UK, Australia, Canada and New Zealand published joint guidance telling organizations to assume that AI agents may behave unexpectedly.

how to prevent ai cyber attacks

Prompt injection. You see a normal page. Your AI assistant also reads the hidden instructions.

Poisoned AI answers: Attackers also try to get their fake websites and fake software into the answers that AI chatbots give. We covered this in our post on what is baiting in cybersecurity.

Family 4 — AI-powered hacking and malware

This family mostly targets companies, but it affects everyone in the end.

Malware that rewrites itself: In November 2025, Google’s Threat Intelligence Group reported the first malware families that ask an AI model for help while they are running. One of them, called PROMPTFLUX, asks Google’s Gemini to rewrite its own code so that antivirus tools find it harder to recognize. Google said it was still in testing. Another, PROMPTSTEAL, was used by a Russian state group in real attacks to generate commands on the fly.

AI doing most of the hacking: In November 2025, Anthropic reported that a group it assessed as Chinese state-sponsored had tricked its AI tool, Claude Code, into carrying out a large part of a hacking campaign against about 30 organizations. According to Anthropic, the AI did 80 to 90% of the work, and a small number of the attacks succeeded. The AI also made mistakes and sometimes made things up, so humans still had to step in.

Basically, AI is making hacking faster and cheaper. It is not yet doing everything on its own, but it is moving in that direction.

How much money are AI attacks costing?

For the first time in its 25-year history, the FBI’s Internet Crime Complaint Center (IC3) counted AI-related crime separately in its 2025 report. It received 22,364 complaints that involved AI, with losses of about $893 million.

how to prevent ai cyber attacks

US losses in 2025 from complaints that involved AI, by type of crime. Source: FBI IC3 2025 report.

Most of that money, about $632 million, was lost to investment fraud, where fake experts, fake celebrity videos and AI chat partners push people into fake trading platforms. Business email compromise added about $30 million. This is when attackers pose as a manager or supplier and ask for a payment, sometimes with a cloned voice to “confirm” it.

Note that the real number is much higher. The FBI only counts AI when the victim reports that AI was involved, and most victims never find out. A cloned voice that sounded perfect is, by definition, a voice the victim didn’t notice.

How to prevent AI cyber attacks: the steps that matter most

Here is the most important idea in this post.

AI can copy a face, a voice and a writing style. It can’t copy a phone number you already have, a word only your family knows, or a rule you have already agreed on.

So, instead of trying to spot the fake, we make the fake useless. Every step below follows this idea.

Step 1 — Verify through a channel you already trust

When a call, message or video asks for money, a code or access, stop and contact the person yourself using contact details you already had before the message arrived.

  • Hang up, then call back on the number saved in your phone, printed on your bank card or listed on the official website.
  • Don’t use the number, link or email address given in the message itself.
  • If it was a video call from your “boss,” send them a separate message on your normal work chat, or call their usual number.

The FBI gives the same advice: hang up, look up the official contact details yourself, and call that number directly.

This works because the attacker controls only one channel: the one they contacted you on. When you switch to a channel you already trust, the attack breaks.

how to prevent ai cyber attacks

Verify through a channel you already trust. The attacker controls one line, not all of them.

Step 2 — Set a family code word

Agree on a secret word or phrase with your family. If someone calls in an emergency and asks for money, ask for the code word. A cloned voice won’t know it.

The FBI recommends this in its warning about AI fraud. A few tips make it work better.

  • Choose something that is not on social media, so not a pet’s name or a street name.
  • Tell older family members and children too, because they are often the target.
  • Never say the code word first. The caller must say it.

Step 3 — Look at the request, not the messenger

The face may be perfect and the voice may be exact. But the request usually gives the attack away.

In our post on baiting, we saw that almost every scam ends with one of three requests: install this app, enter this code, or send this payment. AI attacks are the same. Stop and verify whenever a message asks you to do any of these.

  • Send money, especially by bank transfer, gift cards, crypto or a “safe account.”
  • Share a code or password, such as a one-time code, a PIN or a login.
  • Install something or give access, such as a remote access app, a “security update” or a new account.

Then look for pressure. The FBI says impersonators often use an urgent or aggressive tone, keep the victim on the phone for the whole time, and tell them not to talk to family, the bank or the police. Secrecy is the biggest warning sign of all. A real emergency doesn’t stop you from calling someone else.

how to prevent ai cyber attacks

Three requests to always verify, and the pressure signs that come with them.

Step 4 — Share less of your voice and face publicly

To clone a voice, an attacker needs a recording of it. To make a deepfake, they need pictures and videos.

The FBI advises people to limit online content of their image and voice where possible, make social media accounts private, and limit followers to people they know. This doesn’t mean disappearing from the internet. It means thinking twice before posting long videos of yourself talking, or before answering an unknown caller with a long chat.

Step 5 — Use passkeys and phishing-resistant sign-in

AI makes fake login pages and fake messages more convincing, so your passwords are more likely to be stolen. The answer is to make a stolen password useless.

  • Turn on two-step verification for your email, bank and social media, starting with email.
  • Use passkeys wherever they are offered. A passkey lets you sign in with your fingerprint, face or device PIN, and it only works on the real website. So even a perfect fake page can’t steal it.
  • Use a password manager. It won’t fill in your password on a fake website, because the web address doesn’t match.

Microsoft says phishing-resistant multi-factor authentication can block more than 99% of identity-based attacks. We explained how to set all of this up in our post on how to protect your home computer.

Step 6 — Use AI assistants and AI browsers carefully

AI tools are useful, and you don’t need to stop using them. But an AI that can take action for you deserves the same care as a person you give your keys to.

  • Give AI agents only the access they need. Don’t connect an AI assistant to your email, bank or payment accounts unless the task really needs it.
  • Read before you confirm. If an AI tool asks you to approve a payment, a sent email or a download, check what it is about to do.
  • Be careful when an AI tool reads content you don’t trust, such as unknown websites, unexpected emails or files from strangers, especially while it is signed in to your accounts.
  • Check links and downloads that an AI gives you against the official website before you use them.
  • Don’t paste passwords, card numbers or private documents into a chatbot unless you are sure how that tool stores your data.

Step 7 — Keep the basics strong

AI-powered malware still needs a way in, and the old basics still close most of those doors.

  • Keep automatic updates on, so known security holes are fixed.
  • Keep your antivirus on. Because some new malware rewrites its own code, tools that watch what a program does, not only what its file looks like, matter more than before. Microsoft Defender, built into Windows, does both.
  • Download software only from official sources.
  • Back up your files, and keep one copy unplugged or in the cloud with older versions saved.

For organizations

AI attacks hit companies hardest where one person can approve something big. These steps remove that single point of failure.

  • Make the payment rule stronger than any voice. No payment, change of bank details or urgent transfer is approved because of a call, video or email alone. It needs a call-back to a known number and a second person’s approval.
  • Agree on verification phrases for finance teams and senior managers, the same way families use a code word.
  • Verify new hires properly. Check identity documents, and hold at least one live interview in person or with strong identity checks for remote roles.
  • Treat AI agents like new employees. Give them the least access they need, log what they do, and require a human to approve sensitive actions such as payments or sending data outside.
  • Use behavior-based security tools such as EDR (Endpoint Detection and Response) on every computer. EDR watches how programs behave, which helps against malware that changes its own code.
  • Train people with real examples. Show staff what a cloned voice and a deepfake call look like, and make it normal, even praised, to hang up and call back.
  • how to prevent ai cyber attacks

Five layers of protection. Each one catches what the last one missed.

Tools that help protect you from AI attacks

No single tool can stop AI attacks, because many of them target your trust, not your computer. But the right tools take away much of the attacker’s advantage. Most of the tools below are free.

What it protects Tool Why it helps against AI attacks
Your passwords Bitwarden, Google Password Manager, Apple Passwords, 1Password Won’t fill in your password on a fake site, however real the site looks
Your sign-in Passkeys, Google Authenticator, Microsoft Authenticator A stolen password alone is no longer enough
Your device Microsoft Defender (Windows Security), XProtect and Gatekeeper on Mac Built in and free; Defender also watches how programs behave, not only what their files look like
Your browser Google Safe Browsing, Microsoft Defender SmartScreen, uBlock Origin Warns about known fake sites and removes many fake download ads
Your phone line Your phone’s built-in spam call filter and your mobile company’s scam blocking Reduces scam calls before they reach you
Your family A secret code word Free, and a cloned voice can’t guess it
Your company EDR tools, payment call-back rule, two-person approval Stops one convincing call from moving money

The Curious Lab also offers free tools that help with the basics:

A note on deepfake detector apps: many apps claim to tell a real voice or video from a fake one. Detection is improving, but researchers have found that audio detectors lose much of their accuracy on real phone calls and compressed recordings. So use them as an extra hint, never as proof. The call-back and the code word are still more reliable.

What to do if you think an AI attack tricked you:

Don’t panic, and don’t keep it to yourself. The faster you act, the less damage the attacker can do.

  1. Stop all contact with the attacker. Hang up, end the video call and don’t reply to messages.
  2. Call your bank straight away if you sent money or shared card details. Use the number on your card. Banks can sometimes stop or recall a payment if you act fast.
  3. Change your important passwords from a clean device, starting with your email. Choose “sign out of all devices” wherever you can, and turn on two-step verification.
  4. If you installed something or gave remote access, disconnect from the internet and follow the steps in our post on how to protect your home computer.
  5. Warn the person who was impersonated, so they can warn others.
  6. At work, tell your IT or security team straight away, even if you are not sure anything happened.
  7. Report it. In the US, report at ic3.gov and mention that AI or a cloned voice was involved. We listed where to report in the UK, India, Australia, Canada and Singapore in our post on baiting.

Note that falling for an AI attack has nothing to do with being foolish. These attacks are designed to beat human eyes and ears. Reporting helps the police and banks warn the next person.

A real story: the video call where everyone was fake

In January 2024, an employee in the Hong Kong office of Arup, a British engineering company, received an email that seemed to come from the company’s UK-based chief financial officer. It asked for a secret transaction.

The employee was suspicious at first and thought it might be phishing. Then he joined a video call. On the call were the chief financial officer and several colleagues he recognized. They looked and sounded real, so his doubt went away.

Following the instructions from the call, he made 15 transfers to five bank accounts in Hong Kong, a total of HK$200 million, about US$25 million. The fraud was only discovered when he later checked with the company’s head office.

Every other person on that call was a deepfake. Hong Kong officials later said the police believed the video had been made from public online clips of the real people, so there was no real conversation at all. Arup confirmed in May 2024 that fake voices and images had been used.

No computer was hacked and no password was stolen. The whole attack depended on one thing: a payment that could be approved because a familiar face asked for it. A call-back to the chief financial officer’s known number, or a rule that large payments need a second approval, would have stopped it.

Final thoughts

AI hasn’t invented new crimes. It has made old tricks look and sound real. A fake boss, a fake relative, a fake official and a fake website are all old ideas. AI only removed the spelling mistakes, the strange voices and the blurry photos that used to give them away.

So the defense has to move from spotting fakes to checking requests. Verify through a channel you already trust. Set a family code word. Treat any request for money, codes or access as a reason to pause. Use passkeys, keep your devices updated, and give AI tools only the access they need.

Note that you don’t need to do everything today. Start with two steps: agree on a code word with your family, and make it a habit to hang up and call back before you pay anyone. Those two steps alone defeat most voice and video tricks.

If you are new to cybersecurity, start with our guide on how cyberattacks work.

Stay safe, stay alert!

Related posts from The Curious Lab

 

Found this useful? Save it for later or send it to someone who needs it.

Written by

Chief Editor

See all 11 articles

Up next

How to protect your home computer? – The Curious Lab

How to Protect Your Home Computer? A Simple Guide for Everyone Protecting your home computer doesn’t mean becoming a computer expert. Most attacks on home computers…

Keep reading · 20 min read

Join the discussion

Your email won't be published.