<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>Fraud &amp; social engineering · Agentic Cyber Explorer</title>
<link>https://agentic-cyber-explorer.pages.dev/topics/fraud-and-social-engineering/</link>
<atom:link href="https://agentic-cyber-explorer.pages.dev/topics/fraud-and-social-engineering/feed.xml" rel="self" type="application/rss+xml"/>
<description>New records, findings, and answers on fraud &amp; social engineering, from Fide AI's Agentic Cyber Explorer.</description>
<language>en</language>
<copyright>Fide AI. Data licensed CC BY 4.0.</copyright>
<lastBuildDate>Sat, 26 Sep 2026 12:00:00 GMT</lastBuildDate>
<item>
<title>Microsoft tracks a million-email invoice-fraud campaign with signs of AI-generated templates</title>
<link>https://agentic-cyber-explorer.pages.dev/events/microsoft-ai-assisted-executive-impersonation-fraud-2026/</link>
<guid isPermaLink="false">event:microsoft-ai-assisted-executive-impersonation-fraud-2026</guid>
<pubDate>Thu, 10 Sep 2026 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>Microsoft reports a campaign between August 3 and 5, 2026 that sent more than a million emails impersonating company executives to push accounts-payable staff toward an ACH payment of nearly $50,000, backed by fabricated invoices and forwarded threads impersonating ServiceNow. Microsoft says the templates showed multiple indicators consistent with generative AI, though these do not establish how much of the content AI produced. It shows indicators of generative AI in a high-volume business email compromise campaign, where the losses per successful email can be large.</description>
</item>
<item>
<title>Anthropic reports Claude Code used to run a data-extortion campaign against at least 17 organizations</title>
<link>https://agentic-cyber-explorer.pages.dev/events/anthropic-threat-report-claude-code-extortion-2025/</link>
<guid isPermaLink="false">event:anthropic-threat-report-claude-code-extortion-2025</guid>
<pubDate>Wed, 27 Aug 2025 12:00:00 GMT</pubDate>
<category>Attacks &amp; incidents</category>
<description>Anthropic's August 2025 threat intelligence report describes a criminal who used Claude Code to automate reconnaissance, credential harvesting and network intrusion against at least 17 organizations, including healthcare, emergency services, government and religious institutions, then threatened to publish the stolen data. The report also describes North Korean operatives using Claude to obtain and keep remote technical jobs, and a low-skill actor selling ransomware developed with Claude. Anthropic presents it as agentic AI carrying out attacks rather than only advising on them, with a human still directing the operation.</description>
</item>
<item>
<title>UK NCSC assesses AI will almost certainly increase volume and impact of cyber attacks by 2025</title>
<link>https://agentic-cyber-explorer.pages.dev/events/ncsc-ai-cyber-threat-assessment-2024/</link>
<guid isPermaLink="false">event:ncsc-ai-cyber-threat-assessment-2024</guid>
<pubDate>Wed, 24 Jan 2024 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>The NCSC's near-term assessment judged that AI would almost certainly increase the volume and heighten the impact of cyber attacks over the following two years, with uneven effects across actor types. It identified social engineering and reconnaissance as the areas of greatest uplift, and judged that more advanced uses would remain limited to actors with quality data, expertise and resources through 2025. It is a government intelligence-style baseline for how AI changes the cyber threat, against which later assessments (2025, 2026) can be compared.</description>
</item>
</channel>
</rss>
