While artificial intelligence is supercharging digital scams and cybercrime, it's also becoming a powerful weapon to protect potential victims. Governments have long struggled to curb online crime due to jurisdictional limits, leading to innovative approaches like using automation to overwhelm scammers. Now, AI is turning these experimental tactics into serious tools in the battle against cyber threats.
Companies like Apate, named after the Greek goddess of deception, are developing systems that redirect phone scammers to AI bots. These bots are designed to prolong conversations, keeping scammers occupied while gathering intelligence on their methods. Apate's CEO, Dali Kaafar, explained, "What we really like to think is that we’re building the perfect victims for scammers." He added that every minute a scammer spends talking to a bot is a minute saved for potentially thousands of other people they might have targeted.
Apate's platform, utilized by banks and supported by telecom companies, boasts around 350,000 bots. These bots not only answer scam calls but also engage in scam chat groups and respond to text messages. The objective is to frustrate scammers and extract valuable information, such as scam URLs, money mule accounts, and bank details. To date, the company has collected over 250,000 pieces of intel on fraudsters in real-time.
To enhance realism, Apate's bots are equipped with diverse personalities, language skills, and profiles. Kaafar noted, "Sometimes [the bots] do have WhatsApp, sometimes they don’t. Sometimes they pick up the phone, sometimes they just actually hang up on the scammer saying, ‘I'll come back to you later.'" Kernel Panic tested a demo version, finding the AI's persona convincingly skeptical yet open enough to prolong scam attempts. Even when two users collaborated to trick the AI, dubbed "Lucy" with her financial advisor "Mickey," they failed to convince it to invest in a cryptocurrency scheme after six minutes of effort.
Despite these advancements, scam calls and texts remain prevalent, with cybercriminals initiating billions of communications annually. While traditional methods like scambaiting have had some deterrent effect, law enforcement and research efforts haven't halted the overall expansion of digital scamming. However, AI is poised to usher in a new era of anti-scam efforts. Enhanced intelligence sharing among law enforcement, tech companies, and financial institutions, potentially aided by AI-driven analysis, is crucial. Additionally, disruptive tactics exploiting cybercriminals' psychological vulnerabilities, such as trolling ransomware attackers, are gaining traction.
Honeypots, a long-standing defense strategy where fake virtual machines attract and trap hackers, are also evolving. Security researchers are increasingly integrating Large Language Models (LLMs) into honeypots to make them more convincing. Research indicates that LLM-powered honeypots can keep AI-driven attackers engaged significantly longer and are perceived as more legitimate by these sophisticated agents, offering a distinct advantage to defenders.