Leaders in the email security space have been seeing this for a while now [0], this is not new. The problem is the means to protect consumer mailboxes outside of Gmail, isn't cost effective since most people do not actually pay for their consumer mailbox and the impacts of compromised accounts do not actually impact the providers. It is going to be interesting to see how this plays out in the consumer space as the complexity of the problem continues to grow while the technology used to stop it stays in the early-2010s.
They don't even need to actually vibecode the emails. Some scam reached my gmail inbox for the french railway company advantage card at a "too low to believe" price. They just downloaded an original email, replaced content urls to their own host and all links to their scam page. Yes, all links even the socials lol. There's one link that was removed instead of replaced (but the text was still there): the unsubscribe notice. I didn't check the page but the email was well done since it just was an edited official one and if the page was equally made I'm sure at least some people got scammed there.
But is this something new? Wasn't using AI for scamming around for a long time?
Scammers started using LLMs to write fishing emails, then scammers started generating images, then they started using AI to vibe code it. Its just a natural progression.
From https://news.ycombinator.com/item?id=47435156, we can know that India has a ~70% positive view on AI. While scammers likely didn't fill out the survey, it shows the general view on AI from where most scammers work from and live.
> it shows the general view on AI from where most scammers work from and live.
Got any citation on that? From what I've seen, the vaat majority of scams are targeted at other Indians. The government runs a significant number of cyber awareness programs nowadays; don't think they appreciate scammers.
For years I’ve read people claim that the reason spam emails were low quality was to filter for idiots. If the spammers are now reaching for coding agents to clean up the presentation, it seems that theory was bunk.
That theory was always bunk. People just can't comprehend, that the average spammer really is that bad. So that theory was created to make sense of that.
Because of my work I investigated a lot of spam, and I discovered real life identities of senders in many cases (because of horrible or no exostent opsec). Most of them were either underage, lived in third world countries, or both.
Scams got sophisticated a while ago where they would exactly replicate things like password reset emails and such including a whole fake replica website that looks identical to the real one.
I saw someone fall for one recently where a scammer had created a fake announcement from an email sending company stating they were adding political messages to the bottom of your sent emails, and to log in to opt out. The look and feel of the email was pretty much perfect.
The sophistication of scam emails these days is a big part of the switch to Passkeys, just physically making it impossible to give your credentials to the scammer site.
Phishing too. At one point in my job I was involved with taking down phishing sites, and we would sometimes get a copy of the Phish kit code from the site owner. These were basically extremely poorly written PHP scripts that people would buy from a scam-enabler and deploy to some website. The sophistication was the lowest possible level at each step. But even if you find the perpetrator bragging about it on Facebook, they're in Nigeria (for example) and the local government doesn't care at all.
Remember that a large portion of the "real scam" is selling scamming techniques and systems to wanna-be scammers, some who never figure out how to replace the "insert viagra link here" text.
The (now possibly vibe-coded) email clients hiding link destinations and the real senders' addresses as well as making it very hard to see the actual message content including all headers don't help either. Scammers might get the visible body content very convincing, but one look at the Received: and From: headers is still a reliable way to discern.
That already exists, it's "voicemail". The scammers never leave a voice mail (idk why). If a real person is trying to reach you, they'll either leave a voice mail or text you after you don't pick up.
In my country, despite voicemail being available since the introduction of mobile phones decades ago, I am yet to hear of a single instance of anybody actually leaving a message.
But voicemail implies storing the audio somewhere, and that means cost.
And at least in my country one should explicitly enable voicemail. I never could make it work for some reason..
And as far as I can see, it is not widely used.
EDIT: Oh, I completely missed the fact that there can be a fake voicemail where the phone automatically answers and asks the caller to speak and record it and store the audio on the phone itself. Then the user can check such recorded messages later..
Did you mean something like that? I am really surprised that this is not common already...
Many spammers leave a prerecorded voicemail, they call quickly from 2 numbers so they can slide into your voicemail instantly without ringing more than once
definitely a big issue especially with all the big places now vibe coding and leaking all our damned data in plaintext. a lot of people are getting hit real hard now. its not a joke or overstatement.
I've noticed a gigantic uptick in text messages and phone calls where people try to bypass the call screening. It may get to the point where I'll only want to see comms from people in an allowlist.
My standard response in such cases is “Hello unknown number, who are you and why should I not immediately hang up?”.
The response “Am I speaking to…” gets cut off with “Nope, you answer my questions first”. If they _must_ speak to Mr [MySurname] I claim to be my PA and that they aren't talking to him(me) without convincing me they aren't a junk call first. If I have a few minutes to spare, it can be quite an entertaining little game keeping them on the line so they can't be conning someone more vulnerable. Unfortunately must junk calls these days are either initially automated or the humans are wise to people like me being a waste of their time so they hang up cutting that fun short.
I solved this by renting small office that has reception and they handle deliveries. They are not far and so if I get something I get a text and then I collect when is convenient for me. I really hate waiting for couriers to ring, so it's a massive stress relief.
This is hardly new, and it goes far beyond spam emails. Most of the content produced and consumed on the internet is now done by machines. A human may or may not benefit from directing a machine to do this, and the ways they do are often highly opaque, with several layers of indirection. It doesn't take a genius to see that this is ushering in a new era of scams and spam.
"AI" companies are responsible for this mess. They should be held accountable for digging us out of it.
This is interesting but I am not surprised. People got used to spammers putting in zero effort because it's a game of scale for them. Well now zero effort still gets them all the way there when it comes to looking convincing.
That LLMs are enabling more use cases to hurt us than help us is too obvious to deny. But too many people think they're going to be the ones getting rich from it so they pretend it's not the case.
[0] https://siliconangle.com/2023/12/19/new-report-warns-rise-ai...
Scammers started using LLMs to write fishing emails, then scammers started generating images, then they started using AI to vibe code it. Its just a natural progression.
From https://news.ycombinator.com/item?id=47435156, we can know that India has a ~70% positive view on AI. While scammers likely didn't fill out the survey, it shows the general view on AI from where most scammers work from and live.
Got any citation on that? From what I've seen, the vaat majority of scams are targeted at other Indians. The government runs a significant number of cyber awareness programs nowadays; don't think they appreciate scammers.
Because of my work I investigated a lot of spam, and I discovered real life identities of senders in many cases (because of horrible or no exostent opsec). Most of them were either underage, lived in third world countries, or both.
I saw someone fall for one recently where a scammer had created a fake announcement from an email sending company stating they were adding political messages to the bottom of your sent emails, and to log in to opt out. The look and feel of the email was pretty much perfect.
"Click link" ? I think not. Gonna log in myself in a new window and try to navigate to the same thing on my own.
LLMs are interesting for phishing as they allow personalisation. Spam is no longer, well exactly the Monty Python meaning.
Even if it's not the only they can do.
If someone calls from an unknown number, they get some sort of captcha to prove that they are a human, or they matter is important.
For example, the message should say that, if you are geniune, then please call again after 1 minute..
In my country, despite voicemail being available since the introduction of mobile phones decades ago, I am yet to hear of a single instance of anybody actually leaving a message.
And at least in my country one should explicitly enable voicemail. I never could make it work for some reason..
And as far as I can see, it is not widely used.
EDIT: Oh, I completely missed the fact that there can be a fake voicemail where the phone automatically answers and asks the caller to speak and record it and store the audio on the phone itself. Then the user can check such recorded messages later..
Did you mean something like that? I am really surprised that this is not common already...
The tricky part for scammers is there is no good answer here, if you claim to be a plumber and the victim hasn't booked a plumber, they won't answer.
The response “Am I speaking to…” gets cut off with “Nope, you answer my questions first”. If they _must_ speak to Mr [MySurname] I claim to be my PA and that they aren't talking to him(me) without convincing me they aren't a junk call first. If I have a few minutes to spare, it can be quite an entertaining little game keeping them on the line so they can't be conning someone more vulnerable. Unfortunately must junk calls these days are either initially automated or the humans are wise to people like me being a waste of their time so they hang up cutting that fun short.
"AI" companies are responsible for this mess. They should be held accountable for digging us out of it.