10 AI Cybersecurity Risks and How to Help Prevent Them

Given the evolving AI landscape, learn how to spot deepfakes, secure systems against vulnerabilities and more.

Key Takeaways

  • Artificial intelligence (AI) helps cybercriminals launch faster, more sophisticated attacks using tactics such as deepfakes, personalized scams and malicious bots.
  • AI-powered threats can appear across calls, messages, websites, search results, smart devices, and chatbots.
  • Simple precautions, including independently verifying communications, updating devices and using strong passwords, can help reduce your risk.
  • Cybersecurity professionals also use AI to detect suspicious activity, identify vulnerabilities and respond to threats more quickly.
  • If you believe you encountered a scam or that your account is compromised, contact your Morgan Stanley Financial Advisor or the Morgan Stanley Service Center immediately.

AI scams can make familiar fraud schemes feel more personal—and more convincing. Imagine your phone rings and the caller ID shows your daughter’s name. You answer and hear her crying, “I need help.” A man demands money for her safe release. After you send it, you call your daughter directly. She’s safe and confused. A scammer spoofed her caller ID and used AI to clone her voice. Understanding how these scams work can help you spot the warning signs.

n/a

Wealth Management

Countering Scams in the Age of AI

AI is a powerful tool for criminals, but it’s also being used to detect threats and fight back. Staying skeptical and building smart habits can help keep you stay one step ahead of the bad guys.

What Are AI Scams?

AI scams are fraud schemes that use artificial intelligence to create believable content, impersonate trusted people or organizations and automate malicious activity.

Bad actors primarily leverage two types of AI:

 

  • Generative AI, which can create realistic emails, text messages, voice recordings, images and videos that make their outreach more personal, polished and believable.
  • Agentic AI, which can take actions more autonomously, such as testing vulnerabilities or carrying out steps in a cyberattack with less human direction.

 

As a result, cybercriminals can launch more attacks in less time—and often achieve greater success. AI-related complaints cost Americans nearly $893 million in 2025, according to the FBI.¹

How Can AI Strengthen Cybersecurity?

With appropriate governance and oversight, AI can help cybersecurity teams:

 

  • Find and prioritize vulnerabilities before attackers exploit them
  • Analyze large data sets to detect patterns that may signal an attack 
  • Flag suspicious emails, links, attachments and sender behavior

 

While AI can improve security, strong personal safeguards remain essential. Here are 10 ways cybercriminals are leveraging AI and tips to help protect yourself.

What Are 10 Ways Cybercriminals Leverage AI?

  1. 1
    Deepfakes

    A deepfake is an AI-generated or altered audio, video or image that falsely depicts a person or event. Criminals may use deepfakes to steal money and credentials or manipulate your actions.

  2. 2
    System Vulnerabilities

    AI can help hackers find security gaps in outdated software, devices or systems and exploit them to access accounts, steal information or install malware.

  3. 3
    Rogue AI

    Rogue AI refers to an agentic AI tool that no longer behaves as expected. If the agent is poorly controlled or compromised, it may expose sensitive information, give unsafe recommendations or act without authorization.

  4. 4
    Social Engineering Schemes

    Scammers use AI to research targets and create credible, personalized messages that pressure you to share sensitive information, send money, click links or download attachments.

  5. 5
    Malicious Bots

    Attackers use AI-powered bots to flood websites or systems with traffic, slowing then down or taking them offline while evading detection.

  6. 6
    Password Hacking

    Cybercriminals use AI to quickly guess passwords by testing common or leaked passwords and familiar patterns.

  1. 7
    AI-Powered Investment Scams

    Cybercriminals leverage AI to create fake websites and social media profiles promoting low-risk, high-return investments. Once their target makes an “investment” (traditional or crypto), the fraudsters disappear with the funds.

  2. 8
    Fraudulent AI-Generated Results

    Attackers may manipulate AI chatbots and assistants to recommend fake services, share malicious links or provide instructions that could put personal information or devices at risk.

  3. 9
    Poisoned Search Results

    Attackers may push fake websites higher in search results or use lookalike web addresses to appear legitimate in an attempt to steal credentials, payment or data.

  4. 10
    Smart Technology (IoT)

    Smart devices—also called Internet of Things (IoT) devices—include connected technology like cameras, doorbells, thermostats and wearables. Cybercriminals may use AI to find devices with weak passwords, outdated software or unsecured settings. Once the device is compromised, they can monitor activity, steal information or try to reach other connected accounts.

     

    AI-powered threats can appear across many channels—from emails, texts and calls to social media, search results, smart devices and AI agents—and here’s how to protect yourself.

How Can You Prevent AI Cyberattacks?

Consider the following steps to help reduce your risk:

 

  • Create a family safe word you can use to confirm a trusted family member’s identity—and use it before discussing money or sensitive information.
  • Watch for deepfake cues on a call or Facetime, and hang up immediately if something feels off. Red flags can include unusual requests, memory lapses, robotic tone, lip movement out of sync, visual glitches, etc.
  • Follow basic cybersecurity hygiene including keeping devices up to date, using strong, unique passwords and enabling multi-factor authentication (MFA) for accounts tied to money or sensitive data. See more in our Cybersecurity Checklist.
  • Verify caller ID independently if you receive a suspicious call. Hang up and call the person or organization back using a trusted number from the official website—never a number that was provided to you by the caller. 
  • Don’t share personal or account information, including passwords, one-time codes, Social Security number or bank details in response to unsolicited calls or messages.
  • Be skeptical of urgency and pressure by treating “act now,” “keep this confidential” or “emergency payment” requests as red flags.
  • Only engage with links you trust and avoid clicking links from unexpected messages, search results and chatbot outputs.
  • Be cautious with investment pitches on social media and seek professional advice before transferring funds.
  • Add a trusted contact to your account as an additional layer of protection. Your Morgan Stanley Financial Advisor will only contact your trusted contact if they have concerns about your account but are unable to reach you. 

How Can I Report a Concern?

If you entered sensitive information on a fraudulent site, shared credentials with a scammer or believe an account was compromised, contact your Morgan Stanley Financial Advisor or the Morgan Stanley Service Center immediately at: 888-454-3965   

Report an Online Security Concern

Contact us immediately at 888-454-3965 if you:

• Believe you may be the victim of fraud or identity theft
• Suspect your phone or email have been compromised
• Notice suspicious account activity
• Receive a questionable email or text that appears to be from Morgan Stanley

We’re open 24/7 to help you. For international clients, please contact your Morgan Stanley Client Representative immediately to report any online fraud or security concerns.