AI is changing the threat landscape, one model at a time. The pace at which the technology is evolving means activities that once took a skilled cybercriminal several hours or even days to achieve can now be done in a fraction of that time by someone with little or no prior knowledge. This matters, because it’s lowering the barrier to entry for cybercriminals. We’re seeing it with vulnerability exploitation. We’re seeing it with basic malware generation. And we’re seeing it with victim reconnaissance.

This should put even regular internet users on high alert. If attacks are getting cheaper and easier for fraudsters to carry out, everyone could be a target.

How AI is changing the game

There was a time when open-source intelligence gathering (OSINT) was something only used on high-profile and potentially high-value targets. That’s because it took skill and time to carry out. The term itself originates outside of the cyber world, referring to military and intelligence efforts to collect publicly available information which could be used to achieve strategic goals.

With the advent of the web, and more recently social media, these efforts have become a familiar part of the digital world, used by researchers and threat actors alike. But until AI came along, there was often still a major bottleneck. An adversary needed to spend time finding their targets’ public-facing accounts, interests, friends, family and colleagues. They might have to use dedicated tools or trawl through countless websites, accounts and posts, correlating and cross-checking information, working out relationships between individuals, and deciding what to use in an attack.

AI tools have largely removed that bottleneck by processing information at machine speed. They can find publicly available material from across the web, link it to their potential victims, and map relationships between them and others. It’s particularly good at hunting down unstructured information – especially images and videos. You don’t have to be an OSINT specialist any longer to do this kind of work.

Putting the pieces together at scale

This is troubling news for a variety of reasons. Fraudsters can now easily collect publicly available information on you to make social engineering more convincing and scams more scalable. Consider:

  • A phishing email designed to trick you into sharing your logins or clicking through and unwittingly installing malware. It would be much more convincing if it contained personal details such as your workplace or child’s school, a recent event you were at, or some contextually relevant news you’ve posted like a birthday or a recent holiday. All of that information may be in the public domain and easy to gather at scale.
  • A video or phone call impersonating your voice/face might be used to trick a loved one into believing you’re in danger. Scammers can use these deepfakes to ask for money in your “voice”, or to pretend that you have been kidnapped and need them to pay a ransom to ensure your safety. They might even use a deepfake of you to create an obscene video which they threaten to send to your contacts unless you pay up. This kind of sextortion scheme is becoming more commonplace. In the UK, hundreds of under-18s have reported being victimized this year.

Unfortunately, large language models (LLMs) are expert at piecing together the kind of information that fraudsters need to make their scams work. They can profile large numbers of potential victims in little time, collecting relevant pictures, videos, and info on personal interests, work, and family and friends that could be leveraged.

AI can also help to design the social engineering scripts used by fraudsters, enabling them to sound convincing over email/social media or other channels even if they’re non-native speakers. It offers an end-to-end fraud pipeline.

Trouble at work

It’s not just your personal life that malicious actors can trawl through in this way. The boundary between work and home has become increasingly blurred in recent years, especially as many of us work in a hybrid setup. We might use personal devices and home addresses for corporate activities. And of course, linking our professional and personal social media accounts is a simple task for AI.

All of which means that reconnaissance efforts can have an impact on your professional life. For example, fraudsters could use personal information to craft a social engineering attack designed to harvest your work credentials or information. Or they could target your colleagues when you’re on holiday, knowing that you may not be contactable to verify fraudulent details. This is a useful time to launch a business email compromise (BEC) attack.

Losing your personal information is one thing. But OSINT efforts which have a corporate dimension could potentially have a serious impact on your professional reputation and career.

What you can do about AI-powered OSINT

When it comes to AI-powered reconnaissance, there are things you can control and things you can’t. Once information about you is in the public domain, it can be extremely challenging to request its removal, especially as it may have been republished in other places. Old social media photos are easier to remove, but few of us have the time to trawl through our entire digital life to remove anything potentially useful to criminals.

It’s better therefore to focus on the things that are within your power to change. Consider the following:

  • Ensure your social profiles can’t be publicly accessed, to limit AI’s ability to find any information or images/videos contained within
  • Be judicious in what you share on social media; things like birth dates, children’s schools, holidays and similar events should be off limits
  • Be aware that photos may contain information in them that could be used to identify addresses, vehicle details etc
  • Avoid posting anything that may be used to link your personal and professional lives
  • Use multi-factor authentication and strong, unique passwords to add an extra layer of security on your accounts
  • Don’t accept friend/follower requests from anyone you don’t know. Or if you’re curious, approach them via a separate channel

AI is changing many facets of our lives for the better. But it comes with risks we’re only just waking up to. Caution is always the best policy. It pays to work under the assumption that anything you publish could be read by AI. Act accordingly, and encourage your friends and family to.