Democratized cybercrime: a new lower bar for hackers and higher stakes for security


Phishing has long been a staple of cybercrime, historically betrayed by clumsy spelling, suspicious URLs and poor formatting. Today, however, the rules have changed. What once required technical knowledge, time, and effort can now be executed with frightening ease by virtually anyone.
Thanks to generative AI, automation, and easy access to malicious toolkits, the barrier to entry for cybercrime is fast collapsing. Phishing emails are now convincingly written, well branded, and often hyperpersonalized. Deepfake audio and video tools make it possible to impersonate trusted individuals in real time.
Even entry level attackers can now deploy high quality campaigns that look and sound legitimate. Ironically, a spelling error might be the only clue that a message was created by a real human, rather than an AI.
Meanwhile, across the business world the stakes for defenders are rising fast. As multichannel attacks grow in scale and sophistication, even experienced employees are falling victim. In this new landscape, the cost of inaction isn’t just a data breach- it’s operational disruption, financial loss, and lasting reputational damage. Let’s unpack how advancements in technologies such as AI expands the talent pool for threat actors.
Senior Principal Solutions Consultant at OpenText Cybersecurity.
Social engineering made scalable
Phishing may be evolving but it still hinges on the same psychological tricks: urgency, trust, and fear. But where scams were once generic and mass distributed, AI now allows attackers to tailor them at scale. The result? A surge in spearphishing – targeted messages crafted with context to deceive specific individuals.
According to the OpenText 2025 Cybersecurity Threat Report, November 2024 saw the highest rate of spearphishing to date, making up 56.56% of all phishing activity. Attackers no longer have to choose between volume and precision- they can get the best of both worlds. And with users increasingly conditioned to trust branded platforms, phishing emails delivered via Google Docs or Amazon AWS (“living off the land” techniques) are slipping past defenses unchecked.
This democratization of tools means that cybercrime no longer requires deep expertise- just access to the right AI tools and a few stolen credentials. That’s a worrying trend for businesses who rely on traditional training to build user awareness. Keeping pace means continuously updating training to reflect emerging tactics, particularly those that blend email, SMS, voice and video across channels.
AI and automation, cybercrime’s force multiplier
The rise of generative AI has redefined the phishing threat. Not only are messages more convincing, but campaigns are faster to build, harder to detect, and significantly more dangerous. Deepfakes, once the domain of state actors, are now available to anyone with an internet connection.
This sharp rise in attack sophistication is mirrored in infection trends. In 2024, malware infections on business PCs jumped yet again from 1.86% to 2.39%- the steepest increase since 2020. And it’s not just the first hit that hurts: 43% of affected business endpoints were reinfected within the year. For consumers, the number is even higher, at 56%.
Attackers are increasingly using .zip files as a delivery mechanism, now the most popular format for malware laden attachments, making up 53% of the total. Their perceived legitimacy, combined with password protection (often provided in the email), creates a perfect storm of trust and risk.
AI isn’t just raising the quality of phishing, it’s removing the learning curve. That’s what makes today’s threat environment fundamentally different from even two years ago.
To counter this, organizations must fight fire with fire: deploy AI-enabled security tools that learn and adapt as quickly as attackers’ methods evolve.
From inbox to checkout
Phishing is no longer confined to email inboxes. Attackers have expanded into ecommerce, financial platforms, and cryptocurrency ecosystems – anywhere users engage digitally and make decisions quickly.
During busy shopping periods, scammers launch fake order confirmations and spoofed storefronts to steal payment details. Fraudulent investment schemes targeting decentralized finance and crypto wallets are also on the rise, often engineered with the same social engineering techniques seen in traditional phishing.
The OpenText report notes that phishing attacks are becoming more opportunistic, with over 235 million malware emails quarantined in 2024. Zip attachments dominate due to their effectiveness in bypassing user skepticism, and their ability to mask malicious content under the guise of security. This shift underscores a critical point: phishing is no longer just about access – it’s about fraud, financial theft, and long-term compromise. The digital trust model that underpins modern commerce is being weaponized.
Cybersecurity strategies must now span customer journeys, supply chains, and transaction flows, not just internal email systems.
Going forward
Phishing has evolved into a democratized, AI powered weapon, used by threat actors of all skill levels to exploit human trust and unlock IT infrastructure. The tools are widely available, the learning curve is shrinking, and the consequences of even one successful attack are growing.
This new era demands a new mindset. Defensive efforts must shift from reactive to proactive, combining real time threat detection with intelligent automation and continuous user education. Our data shows that companies using layered defenses, such as endpoint and DNS protection, experience 19.4% fewer infections than those relying on endpoint security alone.
In short, cyber resilience is no longer a mere competitive advantage – it’s imperative for survival.
Business leaders must act now. Audit your digital defenses, modernize your detection tools, and raise cyber awareness and response readiness at every level. Because when attackers can operate with minimal effort, organizations must respond with maximum intent.
We list the best online cybersecurity course.
This article was produced as part of TechRadarPro’s Expert Insights channel where we feature the best and brightest minds in the technology industry today. The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/news/submit-your-story-to-techradar-pro
Phishing has long been a staple of cybercrime, historically betrayed by clumsy spelling, suspicious URLs and poor formatting. Today, however, the rules have changed. What once required technical knowledge, time, and effort can now be executed with frightening ease by virtually anyone. Thanks to generative AI, automation, and easy access…
Recent Posts
- Democratized cybercrime: a new lower bar for hackers and higher stakes for security
- I tried a super-bright 83-inch OLED TV and now projectors are ruined for me
- Redwood Materials is giving old EV batteries a second life as microgrids
- Meta says it’s winning the talent war with OpenAI
- Google is rolling out its AI-powered ‘Ask Photos’ search again – and it has a speed boost
Archives
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010