AI Didn’t Invent Scams – It Industrialized Them
Why AI Misuse Scales

AI didn’t create fraud, influence ops, or intrusion. It compressed the labor curve. Across OpenAI, Anthropic, and Google threat reports, one pattern is consistent: AI is a workflow accelerant. It drafts, translates, profiles, scripts, and scales. Outcomes, however, are still driven by two choke points, distribution and access.
AI writes the script. Distribution and access pull the trigger.
For scams and influence operations, distribution is decisive. Paid ads, high-follower accounts, and rapid off-platform routing outperform “better writing.” Engagement tracks reach, not prose. For intrusion and extortion, access is decisive. Once credentials or footholds exist, agentic systems can accelerate recon, targeting, lateral movement, and pressure tactics at a speed that previously required teams. And this is the uncomfortable delta.
AI is no longer just polishing phishing emails. In documented cases, it has been used to assist multi-step intrusion workflows: mapping organizations, prioritizing data, shaping extortion messaging, and compressing operational cycles. The limiting factor is no longer attacker expertise. It’s access and process friction.
The reality check: what these reports actually admit
A) AI is rarely the whole stack, it is stitched into workflows.
Threat actors combine AI with websites, ad networks, messaging apps, fake accounts, and scammers with actual heartbeats. The model is a component, not the system.
B) Distribution is a force multiplier, not an afterthought.
Romance and task scams follow a clean funnel: paid social ads, keyword targeting, link-outs, Telegram migration, followed by extraction. Other campaigns use malicious ads or traffic steering into trusted hosting platforms where users are guided to execute commands themselves.
The pattern is hear is clear: content generation is cheap. Distribution infrastructure determines impact.
The clean mental model: Ping – Zing – Sting – Route
Ping: cold contact.
Zing: emotional trigger.
Sting: payment or extraction.
Route: move the victim off-platform fast, or get them to execute locally.
“Route” is the multiplier. Once communication leaves the platform or execution shifts to the user’s machine, detection drops and leverage rises.
What actually drives success (measurable levers)
Lever 1: Account reach + ad targeting > AI realism
The same AI-generated batch can produce wildly different engagement depending on follower count and ad precision. Reach beats prose.
Lever 2: Trust laundering through legitimate infrastructure.
Abuse of public share links, trusted domains, and mainstream services gives malicious workflows credibility. The infrastructure does the social proofing.
Lever 3: Speed and scale in recon and personalization.
LLMs accelerate OSINT synthesis, profile mapping, translation, and targeted lure generation. They reduce preparation time and increase speed to iterate.
Evidence discipline: what we cannot verify
Many revenue claims and operational impact metrics come from the attackers’ own inputs. They are directional, not definitive.
What is measurable: Funnels. Routing patterns. Platform moves. Infrastructure reuse.
What is narrative: Claimed profits. Claimed victim counts without independent validation.
If we want clarity, we must separate artifact from assertion.
So what actually fixes this?
Attack the distribution layer (scams and IO):
Stronger ad identity verification. Friction on rapid off-platform migration. Reputation scoring for trusted-host abuse and copy-paste execution patterns.
Attack the access layer (intrusion and extortion):
Phishing-resistant authentication. Device-bound credentials. Anomaly detection tuned to recon-to-exfiltration sequences. Shorten dwell time.
Attack the economics:
Cross-platform indicator sharing. Faster take-downs. Payment rail monitoring and making scale expensive again.
Address model misuse – but don’t over-index on it:
Telemetry, abuse classifiers, and rapid shutdowns matter. They are necessary, but hey are not sufficient.
We will not solve AI misuse by arguing about whether text “sounds AI-generated.” We solve it by controlling channels. We solve it by hardening identity. We solve it by instrumenting systems so misuse produces signals faster than it produces victims.
AI did not invent scams.
It industrialized them.
Primary Sources
OpenAI
Disrupting Malicious Uses of AI – October 2025
PDF: https://cdn.openai.com/threat-intelligence-reports/7d662b68-952f-4dfd-a2f2-fe55b041cc4a/disrupting-malicious-uses-of-ai-october-2025.pdf
Overview: https://openai.com/global-affairs/disrupting-malicious-uses-of-ai-october-2025/
Anthropic
Detecting and Countering Misuse of AI – August 2025
PDF: https://www-cdn.anthropic.com/b2a76c6f6992465c09a6f2fce282f6c0cea8c200.pdf
Overview: https://www.anthropic.com/news/detecting-countering-misuse-aug-2025
Google Threat Intelligence Group (GTIG)
Distillation, Experimentation, and Integration: AI for Adversarial Use – February 2026
Report: https://cloud.google.com/blog/topics/threat-intelligence/distillation-experimentation-integration-ai-adversarial-use
Original human-authored work with limited AI-assisted drafting and illustration.
© 2026 Borealis Traders of New England, LLC. All rights reserved. btne.net/media
Consulting: Need independent analysis or security support? See AI & Cybersecurity Consulting.
