Scams

10 Examples of AI-Powered Cyber Attacks and AI Breaches Every Business Should Know in 2026

The FBI’s Internet Crime Report records a sharp rise in AI-enabled fraud and scams.

AI is changing cyber risk as fast as it is changing business productivity.

The same tools that help teams work faster are also giving attackers new ways to automate phishing, manipulate assistants, expose data, and scale attacks on a level not seen before.

Firebrand survey on UK businesses and AI-powered cyber attacks reveals that 8% of respondents estimate their cyber risk has risen by 10 to 49% due to AI-powered threats, and 17% believe it has gone up by 50 to 99%.

In the US, the FBI’s 2025 Internet Crime Report recorded a sharp rise in AI-enabled fraud and scams. These cases included AI-assisted impersonation, more convincing phishing, and other forms of digital deception that were enabled or amplified by artificial intelligence.

The reported impact was substantial: more than 22,000 complaints and over $893 million in losses.

So what are the new types of AI threats emerging? Here are some examples of AI-powered attacks, as well as incidents where hackers used flaws in AI apps and other systems.

Anthropic Claude-assisted cybercrime spree

In one of the clearest examples of AI being used directly for criminal activity, a hacker reportedly used Claude to help identify targets, automate intrusion steps, and draft extortion demands. Rather than inventing a new attack method, the criminal used AI to make an existing one faster, cheaper, and more scalable.

From their own report, they mentioned that at least 17 companies were targeted. This case matters because it shows how AI can lower the barrier to entry for attackers and increase the volume of harm they can inflict in a short period.

Grok chat exposure

Grok chat conversations were reportedly exposed through public indexing, allowing private prompts and content to surface in search results. In effect, material that users may have assumed was private became far more visible than intended.

The reported impact was up to 370,000 private chat links appearing in search results. Even when there is no direct financial loss, this kind of exposure can create serious privacy, reputation, and trust issues for users and the platform alike.

The 25-million-dollar deepfake heist

Arup, a British multinational design and engineering company behind world-famous buildings such as the Sydney Opera House, became the target of a deepfake scam that led to one of its Hong Kong employees paying out $25 million to fraudsters.

The scammers used deepfake voice and images using AI to trick the employees into remitting money during a deepfaked conference call. This case just goes to show how important employee training and upskilling is, especially when there is already a huge cybersecurity skills gap.

Recreation of a spear phishing email. AI has improved spear phishing techniques and is getting more difficult to detect.

Medicare scammed using AI voices and hacking

AI-powered cyber crime is not limited to corporate email fraud or exposed chat platforms. The healthcare sector is also under pressure. For example, the New York Post reported on Medicare fraud, describing how international criminal networks used fake AI voices, hacked data and remote digital tactics to steal from the US system without even setting foot in the country.

What makes this case especially striking is the scale. Public reporting linked the wider Medicare fraud crackdown to $14.6 billion in intended losses, while the US Justice Department said advanced analytics helped stop roughly $4.45 billion in fraudulent payments before they were made.

OpenAI staff targeted by spear phishing malware

OpenAI reported that a suspected China-based threat actor, known as SweetSpecter, sent spear-phishing emails to staff using malicious ZIP files disguised as legitimate messages.

The attackers reportedly used the emails to deliver Windows malware called SugarGh0st RAT, which could have allowed them to take control of infected machines, steal data, and capture screenshots.

The attack was unsuccessful because OpenAI’s internal security controls blocked the emails before they reached employee inboxes. Even so, the incident is a strong reminder that AI companies themselves are now high-value targets, and that phishing remains one of the most effective ways to try to breach even the most security-conscious organisations.

AI-related employment fraud

AI has also been used in employment scams, including voice spoofing and synthetic identity tactics aimed at job seekers. These scams exploit trust, urgency, and the promise of legitimate opportunities, which makes them especially difficult for victims to identify quickly.

Unfortunately, with job losses at a high in the UK, Ireland, and the US, some of these scams also exploit the vulnerability of job seekers by giving them tasks. A UK-based writer from The Guardian in the UK called these “task scams” where one will be asked to perform small, online tasks in exchange for fees. The jobseeker would then be asked to pay to access their fees. The RTE in Ireland also did an investigative report on this matter. In their investigation, the AI scammers even used real company names in their scams, which could tarnish brand reputation.

In the US, the reported impact was nearly $13 million in losses, according to the earlier-mentioned FBI report. This kind of fraud is important because it shows that AI-driven crime is not limited to corporate environments — it is also affecting individuals at scale.

A recreation of a fake job scam generated by AI and being sent to jobseekers.

McDonald’s AI hiring bot data exposure

A Wired investigation reported that McDonald’s AI hiring system, McHire, built with Paradox.ai, exposed the personal data of applicants due to basic security flaws. Researchers were able to access an administrative account using the password 123456 and then reach applicant chat data through an insecure internal API.

This could have exposed the details of up to 64 million applicants, including names, email addresses, phone numbers, physical addresses, shift preferences, and chat logs. Paradox.ai said the vulnerability was fixed quickly after disclosure, but this case is a strong example of how AI-powered hiring tools can create massive privacy risks when fundamental security controls are weak.

AI government “spies”

According to Anthropic, they disrupted what they described as the first reported AI-orchestrated cyber espionage campaign, allegedly linked to a Chinese state-sponsored group. The attackers are said to have used Claude to automate much of the operation, rather than relying solely on human operators.

The reported campaign targeted around 30 organisations across technology, finance, chemicals, and government, and Anthropic said the AI carried out about 80% to 90% of the operational work. That included reconnaissance, vulnerability discovery, credential harvesting, lateral movement, and data extraction, with humans mainly stepping in for planning and approval at key stages.

AI image app leaks millions of user files

An Android app called Video AI Art Generator & Maker left a large cloud storage bucket publicly exposed, allowing researchers to access user-uploaded content without authentication.

The app promised AI-powered photo and video makeovers, but instead exposed a huge volume of private media because of a basic cloud security mistake.

Researchers said more than 1.5 million user images and over 385,000 user-uploaded videos were exposed, alongside millions of AI-generated files, bringing the total to about 8.27 million media files and more than 12 terabytes of data.

AI plush toy exposed children’s private chats

An AI plush toy from Bondu reportedly left a web console exposed, allowing anyone with a Gmail account to access around 50,000 private chat transcripts between children and their toys. The data included names, birth dates, family details, preferences, and other intimate conversations, making the issue especially sensitive because it involved children’s personal information.

The impact was serious from a privacy and safeguarding perspective, even though the company said it took the console offline quickly and relaunched it with stronger authentication. The case is a strong reminder that AI toys are not just consumer gadgets. They are also data-collecting systems, and if access controls are weak, they can expose highly personal information at scale.

How can businesses prepare for AI-powered attacks?

AI-powered cyber risk is here, and it is already causing real damage. Attackers are using AI to scale fraud, impersonation, phishing, and data theft, while weaknesses in AI systems are exposing sensitive information at extraordinary volume.

For business leaders, the response cannot be passive. AI systems need tighter controls, better monitoring, and stronger user awareness, but those measures only work when teams know how to use them properly. 

Companies across all industries need people who can spot AI-enabled threats early and act quickly before a small issue becomes a serious incident.

Why training matters most

Technology alone will not close the gap. If staff, especially those on cyber security teams, do not understand how AI-enabled attacks work, what warning signs to look for, or how threat actors exploit trust, then even the best security tools can be bypassed, misconfigured, or underused.

That is why cyber security training is a core business safeguard. Training strengthens judgement. It also improves response times and gives teams the confidence to handle AI-driven threats before they escalate into reputational damage or financial loss.

Firebrand Training helps organisations build the practical skills needed to defend against modern cyber threats, including AI-driven attacks.

For businesses that want to improve resilience and prepare their teams for the realities of today’s threat landscape, the Firebrand Advantage offers a fast, focused route to capability.

Contact us for a free assessment