Overview of The new era of AI-powered cybercrime
This NPR Shortwave episode examines how AI is reshaping cybercrime and cybersecurity. Hosts Regina Barber and Emily Kwong explain that cyberattacks are becoming easier to launch, harder to detect, and more global in scope, while defenders struggle with a growing skills gap and increasingly sophisticated threats. The episode also highlights how cybersecurity is not just a technical issue, but a human one: training, skepticism, and critical thinking are becoming essential for everyone, from kids to corporate security teams.
Key Takeaways
-
Cybercrime is surging
- The FBI’s Internet Crime Complaint Center reportedly received over 1 million cybercrime complaints in 2025, a record high.
- Attacks are increasingly common, varied, and harder for ordinary users to recognize.
-
AI is making attacks more effective
- Cybercriminals can use AI to:
- write more convincing phishing emails,
- translate scams into fluent foreign languages,
- generate deepfake voice/video calls,
- and identify vulnerabilities in software code.
- This lowers the barrier to entry for criminals and increases the scale of attacks.
- Cybercriminals can use AI to:
-
Defenders are under pressure
- Security teams must now deal with attacks that are faster, more automated, and more convincing.
- AI tools can help defenders spot vulnerabilities, but the same tools can also be used by attackers.
Cybersecurity Basics Explained
The CIA Triad
The episode introduces the core cybersecurity framework known as the CIA triad:
- Confidentiality — only authorized people can access sensitive data
- Integrity — data cannot be altered or corrupted without permission
- Availability — systems and data must be accessible when needed
A ransomware attack is used as a clear example of what happens when availability is destroyed.
Example: Ransomware in Healthcare
- The episode cites the 2016 Hollywood Presbyterian Medical Center ransomware incident.
- The hospital was locked out of its systems for two weeks and paid hackers in Bitcoin to regain access.
- This illustrates how cybercrime can directly threaten care, not just data.
Who the Cybercriminals Are
- Cybercriminals are described as loosely organized networks operating globally.
- They target:
- individuals,
- businesses,
- and supply chains.
- Some hackers work on behalf of governments; these are known as nation-state actors.
- The episode mentions countries including North Korea, Iran, China, and Russia.
- It references Fancy Bear, the Russian military intelligence-linked group associated with election interference.
How AI Is Changing the Game
Better Phishing and Social Engineering
AI helps criminals create:
- more polished scam messages,
- better-targeted manipulation,
- and emails that feel personalized and trustworthy.
Deepfakes and Synthetic Media
- AI-generated voice and video can make fake requests seem legitimate.
- This increases the risk of fraud, impersonation, and credential theft.
Vulnerability Discovery
- Some AI models can help find bugs in code faster than humans.
- That is useful for cybersecurity teams, but dangerous if adversaries use the same tools.
Policy Response
- The episode notes a June executive order from the Trump administration aimed at mitigating AI-related cyber threats.
- It would require certain AI models to be submitted for government review before release.
The Human Side of Cyber Defense
Training People to Be Skeptical
The episode emphasizes that cybersecurity is as much about behavior and judgment as it is about software.
- Charlene Cooper of Cyber.org works on cybersecurity education for K–12 students.
- She encourages parents and teachers to talk with kids about:
- not sharing personal information online,
- being cautious in games and chat platforms like Roblox,
- and verifying identities before trusting someone online.
Teaching Future Cyber Defenders
- Ashley Podorodsky of Dakota State University helped create CybHer, a cybersecurity program and summer camp.
- Students learn practical skills like password cracking to understand how attackers think.
- The goal is not to create hackers, but to build awareness and strong security habits.
Workforce Gap and Next Steps
- The U.S. reportedly has more than 500,000 unfilled cybersecurity jobs.
- The episode argues that the field needs more people trained in:
- critical thinking,
- problem-solving,
- and digital skepticism.
- A major theme is that cybersecurity should be accessible to curious students, not just those who already see themselves as math-and-science experts.
Notable Insight
“Cybersecurity is not an all-tech field. It’s really a critical thinking field.”
That idea captures the episode’s main message: AI is accelerating cybercrime, but the best defense still depends on people who can think carefully, verify information, and adapt quickly.
Resources Mentioned
- Cyber.org — cybersecurity education for students and educators
- CybHer — cybersecurity summer camp and training program
Bottom Line
AI is supercharging cybercrime by making scams more convincing, attacks more scalable, and defenses more complicated. But the episode closes on a hopeful note: with better education, stronger training, and more people entering cybersecurity, defenders can still adapt faster than attackers.
