AI cybercrime in 2026: deepfakes, phishing and defence
The rules of the game have changed. AI cybercrime 2026 has completely transformed the digital security landscape: scams no longer depend on spelling mistakes or suspicious emails. We are now talking about automated, hyper-realistic and personalised attacks, capable of deceiving experienced professionals. The good news is that the same technologies that enable these sophisticated attacks also allow us to defend ourselves better than ever. In this article we analyse the main threats, how they work and what concrete measures you can implement to protect your organisation.
AI cybercrime 2026: the new threat landscape
This new criminal context is characterised by a professionalisation and a scale never seen before. Attackers are no longer isolated individuals: they are organisations with their own infrastructure, custom AI models and sophisticated “ransomware as a service” business models.
Automated large-scale attacks
Moreover, automation has democratised cybercrime. According to the ENISA Threat Landscape 2024 report, automated attacks with AI have increased significantly compared to the previous year. A single criminal organisation can launch thousands of personalised attacks simultaneously, something unthinkable just five years ago.
Personalisation and credibility
On the other hand, what used to give an attack away — grammatical errors, generic greetings, suspicious links — is no longer reliable. Language models generate perfectly written emails, adapted to the tone of the target company and in the recipient’s native language.
AI cybercrime 2026: deepfakes and identity impersonation
Deepfakes are one of the most worrying threats in the current landscape. The ability to generate hyper-realistic videos and audio of real people opens up a completely new attack vector.
The case of video-call fraud
For this reason, cases of multi-million fraud carried out through deepfake video calls have already been documented. A finance employee can receive an apparent video call from their CEO requesting an urgent transfer, with the voice and image perfectly replicated. It is one of the scenarios I address in my analysis of banking security against modern cybercrime. The pressure of timing (end of quarter, confidential operation) reduces the likelihood that the victim will verify the identity through other channels.
How to detect a deepfake
Although the technology is improving rapidly, there are still warning signs: irregular blinking, inconsistent lighting, imperfect lip-syncing on complex words. The best defence is procedural: establishing double-verification protocols for sensitive operations, regardless of who requests them and with what urgency.
AI cybercrime 2026: intelligent phishing and spear phishing
Undoubtedly, AI-powered phishing is the most frequent threat in this context. We are no longer talking about traditional mass phishing: we are talking about targeted attacks with a craftsman’s level of personalisation.
Automated spear phishing
Because of this, AI makes it possible to automatically analyse a person’s public profiles on LinkedIn, their social media posts and their contacts (a good reminder to review the management of your digital legacy) to generate phishing emails that mention real projects, colleagues’ names and recent events. The victim perceives the email as legitimate because it contains information that only someone from their environment could know.
Smishing and vishing
Moreover, phishing is no longer limited to email. Fraudulent SMS (smishing) and calls with AI-generated voices (vishing) are growing vectors. Staff training must cover all communication channels, not just corporate email.
AI cybercrime 2026: ransomware and supply chain attacks
On the other hand, AI-powered ransomware has evolved into an organised industry. Criminal groups operate with corporate structures, including technical support for victims who pay the ransom.
Double and triple extortion
Finally, the extortion model has evolved. Encrypting data is no longer enough: attackers also exfiltrate it and threaten to publish it if payment is not made. Some organisations go further, contacting the victim’s customers or partners directly to add pressure. The real cost of a ransomware attack far exceeds the ransom demanded.
Supply chain attacks
Attackers have discovered that compromising a small supplier gives access to its larger customers. For this reason, supply chain oversight is now a regulatory obligation under NIS2 and not just good practice.
AI cybercrime 2026: defence strategies
Defending against these threats requires combining technology, processes and organisational culture. None of the three dimensions is sufficient on its own.
Technical defence with AI
Defensive AI is as important as offensive AI. Detection and response platforms (EDR, XDR, SIEM with AI) analyse behaviour in real time and detect anomalies that would go unnoticed by a human analyst. Investing in these capabilities is no longer optional for organisations with critical assets.
Zero Trust and strong authentication
Moreover, the Zero Trust model starts from the principle that no access is trusted by default. Every request is verified, authenticated and authorised, regardless of whether it comes from inside or outside the corporate network. In this context, multi-factor authentication, preferably with hardware tokens or biometrics, is the most effective barrier against credential theft.
Training and security culture
On the other hand, technology is useless if people do not know how to use it. Periodic phishing simulations, continuous training and a culture where reporting an incident is not penalised are the foundations of an effective defence. The human link is not the weakest by nature: it is weak when it is not adequately invested in.
AI cybercrime 2026: incident response and compliance
Finally, prevention is essential but insufficient. Every organisation must assume that sooner or later it will suffer an incident and prepare its response capacity.
Response and communication plans
For this reason, having an incident response plan that is documented, tested and known by the management team is fundamental. Communication with customers, regulators and the media during a crisis requires prior preparation: improvising under pressure almost always worsens the reputational impact.
Regulatory compliance
Moreover, regulations such as NIS2 impose very strict incident notification deadlines (24 hours for the initial alert). Because of this, the compliance function must be integrated into the response plan by design, not added at the end. In conclusion, tackling AI cybercrime 2026 is not a purely technical question: it is an organisational, cultural and strategic challenge that requires leadership at the highest level. The organisations that understand it this way will be the ones that truly protect their digital future.
Beyond traditional cybercrime, there is another side: AI on defence. I wrote about that in how Claude Mythos detects threats.
AI cybercrime in 2026 is the use of generative artificial intelligence by digital criminals to automate and scale attacks: mass creation of deepfakes, hyper-personalised phishing, generation of adaptive malware and biometric identity impersonation. Open source models and “as-a-service” offerings on the dark web have democratised capabilities previously reserved for nation-states.
To detect deepfakes in video calls: request atypical movements (turning the head 90°, covering and uncovering the face), observe unnatural blinking, verify lip-sync on labial consonants (p, b, m), require confirmation via an alternative channel (a call to the corporate mobile) and deploy active biometric detection tools such as Microsoft Video Authenticator or Reality Defender on critical video-call platforms.
AI-powered BEC (Business Email Compromise) is the most dangerous. It combines public LinkedIn data, company registers and press releases to build hyper-personalised emails that imitate executives’ writing style. AI makes it possible to generate infinite variants that evade heuristic filters and, together with voice clones from synthetic audio, executes CEO fraud with success rates of over 35%.
Defence against AI cybercrime in 2026 requires Zero Trust architecture, phishing-resistant multi-factor authentication (FIDO2/passkeys), extended detection and response (XDR) with proprietary defensive AI models, continuous deepfake training for executives, network segmentation, privileged identity management (PAM) and periodic AI-assisted social engineering drills. NIS2 and DORA require these controls for regulated sectors.
In Spain and Europe, the response to AI cybercrime is governed by NIS2 (transposed in 2026 with reinforced obligations for essential and important entities), DORA (digital operational resilience in banking and insurance), the EU AI Act (with explicit prohibitions on malicious deepfakes and an obligation to label synthetic content) and the GDPR for identity impersonation. INCIBE coordinates incident response and CCN-CERT supports the public sector.
Do you have to apply this under DORA, NIS2 or ENS? Tell me about it.
Book 20 minutes