Skip to content

10 AI cybersecurity risks and how to help prevent them

09/23/26

Summary: Given the evolving AI landscape, learn how to spot deepfakes, secure systems against vulnerabilities and more.   

Woman with screen images behind her

Key takeaways:

  • Artificial intelligence (AI) helps cybercriminals launch faster, more sophisticated attacks using tactics such as deepfakes, personalized scams and malicious bots.
  • AI-powered threats can appear across calls, messages, websites, search results, smart devices and chatbots.
  • Simple precautions, including independently verifying communications, updating devices and using strong passwords, can help reduce your risk.
  • Cybersecurity professionals also use AI to detect suspicious activity, identify vulnerabilities and respond to threats more quickly.
  • If you believe you encountered a scam or that your account is compromised, contact E*TRADE immediately.

AI scams can make familiar fraud schemes feel more personal—and more convincing. Imagine your phone rings and the caller ID shows your daughter’s name. You answer and hear her crying, “I need help.” A man demands money for her safe release. After you send it, you call your daughter directly. She’s safe and confused. A scammer spoofed her caller ID and used AI to clone her voice. Understanding how these scams work can help you spot the warning signs.

What are AI scams?

AI scams are fraud schemes that use artificial intelligence to create believable content, impersonate trusted people or organizations and automate malicious activity.

Bad actors primarily leverage two types of AI:

  • Generative AI, which can create realistic emails, text messages, voice recordings, images and videos that make their outreach more personal, polished and believable.
  • Agentic AI, which can take actions more autonomously, such as testing vulnerabilities or carrying out steps in a cyberattack with less human direction.

As a result, cybercriminals can launch more attacks in less time—and often achieve greater success. AI-related complaints cost Americans nearly $893 million in 2025, according to the FBI.¹

How can AI strengthen cybersecurity?

With appropriate governance and oversight, AI can help cybersecurity teams:

  • Find and prioritize vulnerabilities before attackers exploit them
  • Analyze large data sets to detect patterns that may signal an attack  
  • Flag suspicious emails, links, attachments and sender behavior

While AI can improve security, strong personal safeguards remain essential. Here are 10 ways cybercriminals are leveraging AI and tips to help protect yourself.

What are 10 ways cybercriminals leverage AI?

1. Deepfakes

A deepfake is an AI-generated or altered audio, video or image that falsely depicts a person or event. Criminals may use deepfakes to steal money and credentials or manipulate your actions.

2. System vulnerabilities

AI can help hackers find security gaps in outdated software, devices or systems and exploit them to access accounts, steal information or install malware.

3. Rogue AI

Rogue AI refers to an agentic AI tool that no longer behaves as expected. If the agent is poorly controlled or compromised, it may expose sensitive information, give unsafe recommendations or act without authorization.

4. Social engineering schemes

Scammers use AI to research targets and create credible, personalized messages that pressure you to share sensitive information, send money, click links or download attachments.

5. Malicious bots

Attackers use AI-powered bots to flood websites or systems with traffic, slowing them down or taking them offline while evading detection.

6. Password hacking

Cybercriminals use AI to quickly guess passwords by testing common or leaked passwords and familiar patterns.

7. AI-Powered investment scams

Cybercriminals leverage AI to create fake websites and social media profiles promoting low-risk, high-return investments. Once their target makes an “investment” (traditional or crypto), the fraudsters disappear with the funds.

8. Fraudulent AI-generated results

Attackers may manipulate AI chatbots and assistants to recommend fake services, share malicious links or provide instructions that could put personal information or devices at risk.

9. Poisoned search results

Attackers may push fake websites higher in search results or use lookalike web addresses to appear legitimate in an attempt to steal credentials, payment or data.

10. Smart technology (IoT)

Smart devices—also called Internet of Things (IoT) devices—include connected technology like cameras, doorbells, thermostats and wearables. Cybercriminals may use AI to find devices with weak passwords, outdated software or unsecured settings. Once the device is compromised, they can monitor activity, steal information or try to reach other connected accounts.

AI-powered threats can appear across many channels—from emails, texts and calls to social media, search results, smart devices and AI agents—and here’s how to protect yourself.

How can you prevent AI cyberattacks?

Consider the following steps to help reduce your risk:

  • Create a family safe word you can use to confirm a trusted family member’s identity—and use it before discussing money or sensitive information.
  • Watch for deepfake cues on a call or FaceTime, and hang up immediately if something feels off. Red flags can include unusual requests, memory lapses, robotic tone, lip movement out of sync, visual glitches, etc.
  • Follow basic cybersecurity hygiene including keeping devices up to date, using strong, unique passwords and enabling multi-factor authentication (MFA) for accounts tied to money or sensitive data.
  • Verify caller ID independently if you receive a suspicious call. Hang up and call the person or organization back using a trusted number from the official website—never a number that was provided to you by the caller.
  • Don’t share personal or account information, including passwords, one-time codes, Social Security numbers or bank details in response to unsolicited calls or messages.
  • Be skeptical of urgency and pressure by treating “act now,” “keep this confidential” or “emergency payment” requests as red flags.
  • Only engage with links you trust and avoid clicking links from unexpected messages, search results and chatbot outputs.
  • Be cautious with investment pitches on social media and seek professional advice before transferring funds.
  • Add a trusted contact to your account as an additional layer of protection. E*TRADE will only contact your trusted contact if they have concerns about your account but are unable to reach you. 

How can I report a concern?

As always, it’s a good idea to regularly visit our Security Center for updates regarding AI and our latest cybersecurity tips. By staying secure, it makes it easier for all of us to enjoy the conveniences and other enhancements in our daily lives made possible by AI. To report a concern, contact E*TRADE at 800-387-2331.

1  FBI National Press Office, Cryptocurrency and AI Scams Bilk Americans of Billions: FBI Releases Annual Internet Crime Complain Report, published April 6, 2026,  https://www.fbi.gov/news/press-releases/cryptocurrency-and-ai-scams-bilk-americans-of-billions

 

CRC# 5919530 09/2026

How can E*TRADE from Morgan Stanley help?

Cybersecurity

Consider investing in companies that help safeguard data and computer systems.

Artificial intelligence

Find investing opportunities in this growing field of technology.

E*TRADE’s Security Center

Your account security is important to us. In addition to the ways your assets are protected, the E*TRADE Customer Protection Guarantee means you’re not liable for unauthorized third-party use of your account through no fault of your own, and we’ll never sell your personal information.1

 

Report a security concern

Contact us immediately at 800-387-2331 if you:

  • Believe you are a victim of identity theft or fraud
  • Suspect your phone or email have been compromised
  • Notice suspicious account activity
  • Receive a questionable email that looks like it is from E*TRADE or one of our affiliated companies
  • Accessed E*TRADE through a search result or link and believe the website may not have been etrade.com, or you may have accessed your account through a lookalike website

To report a website vulnerability, please go to Responsible Disclosure.

What to read next...

Fraudsters are scamming to take advantage of the popularity of digital currency. Learn how to detect cryptocurrency scams and help protect your assets.

Learn how to help protect you or your loved ones from common elder abuse scams.

Looking to expand your financial knowledge?