AI is supercharging cybercrime’s new ‘fifth wave,’ Group-IB warns

March 22, 20262 min read2 sources
Share:
AI is supercharging cybercrime’s new ‘fifth wave,’ Group-IB warns

Cybercrime is entering a new “fifth wave” driven by weaponized AI, according to new research highlighted by Group-IB. The threat intelligence firm says criminals are using generative AI, deepfakes and automation to scale phishing, business email compromise, impersonation fraud and other social engineering attacks faster and more convincingly than before.

Reported by Infosecurity Magazine, Group-IB’s warning centers on how AI is changing criminal operations rather than introducing a single new exploit or malware family. Large language models can help attackers draft polished phishing emails, localize scams into multiple languages, imitate executive writing styles and automate parts of reconnaissance. Deepfake audio and video add another layer, making voice calls and video meetings less reliable for identity checks.

The shift matters because many organizations still depend on familiar signals such as writing style, caller voice or video presence to verify urgent requests. Group-IB’s framing suggests those trust cues are weakening as AI tools become cheaper and easier to use. That lowers the barrier for less-skilled criminals while helping established fraud groups run larger and more targeted campaigns.

The broader industry has been tracking the same pattern. The FBI’s Internet Crime Complaint Center has repeatedly flagged business email compromise as one of the costliest cybercrime categories, and AI is expected to improve the realism and speed of those scams. Recent deepfake-enabled fraud cases, including a widely reported Hong Kong incident involving a fake executive video call, have shown how synthetic media can be used to push fraudulent payments through internal workflows.

For defenders, the immediate risk is higher success rates for existing scams, not necessarily a surge in novel software vulnerabilities. Security teams are being pushed to strengthen out-of-band verification for payments, tighten help desk identity checks and train staff to treat voice and video as potentially spoofable. For remote workers and travelers, using a trusted VPN can help protect connections, but it will not stop impersonation-driven fraud on its own.

Group-IB’s “fifth wave” label may be its own taxonomy, but the underlying message is clear: AI is making cybercrime more scalable, more believable and harder to spot with human judgment alone.

Share:

// SOURCES

// RELATED

Three Microsoft Defender zero-days actively exploited; two still unpatched

Security firm Huntress warns of active exploitation of three Microsoft Defender zero-days, codenamed BlueHammer, RedSun, and UnDefend. Two remain unpa

6 min readApr 18

London healthcare faces months of disruption after ransomware attack on key supplier

A major ransomware attack on pathology provider Synnovis has caused severe, ongoing disruption to London hospitals, highlighting critical supply chain

6 min readApr 18

Most 'AI SOCs' are just faster triage, and that's not enough

Many AI security tools only speed up alert analysis, failing to reduce analyst workload. Experts argue real gains require AI that automates response a

2 min readApr 17

ZionSiphon malware designed to sabotage water treatment systems

A new proof-of-concept malware, ZionSiphon, demonstrates how attackers can sabotage water treatment plants by manipulating industrial control systems.

2 min readApr 17