This One AI Threat Will DOMINATE 90% of All Attacks by 2028 – Are You Ready?

You probably think you’re pretty savvy when it comes to online scams, right? We’ve all gotten those dodgy emails, the fake calls, maybe even a text trying to get us to click a suspicious link. But what if I told you that the game is about to change entirely, and the old rules of digital defense just won’t cut it anymore?

We’re staring down the barrel of a terrifying new era of cybercrime, one where artificial intelligence isn’t just assisting fraudsters; it’s running the show. Forget human error or clumsy phishing attempts. We’re talking about ‘agentic fraud,’ where AI systems operate autonomously, mimicking human behavior so perfectly that they can bypass even the most vigilant security protocols. A recent report from Incode Technologies painted a chilling picture: agentic fraud, which already accounted for a staggering 40% of all cyberattacks in early 2026, is projected to exceed 90% by 2028. That’s not a typo. Ninety percent! This isn’t just a trend; it’s an impending tsunami that will redefine how we think about cybersecurity and, critically, how to protect business from AI-driven fraud.

The numbers are already eye-watering. The FBI reported a colossal $20.9 billion in US cyber-enabled losses in 2025 alone. And if you think that’s bad, consider this: payments to AI scam-service vendors have skyrocketed by an astonishing 1,900% since 2021. This isn’t just about big corporations; small and medium-sized businesses (SMBs) are incredibly vulnerable, often lacking the resources of larger enterprises. So, if you run a business, big or small, you absolutely need to understand this threat and, more importantly, put concrete measures in place. This guide will walk you through actionable steps you can take right now to safeguard your operations.

1. Understand the Threat: The Rise of Agentic AI

First things first: what exactly is ‘agentic fraud’? It’s not just AI being used as a tool by a human criminal. This is about AI operating as an independent agent, performing complex tasks and making decisions without direct human oversight for each step. Imagine an AI that can craft incredibly convincing phishing emails tailored to your specific industry, mimic an executive’s voice perfectly to authorize fraudulent transfers, or even engage in a sustained conversation to extract sensitive information. These AI agents learn, adapt, and refine their tactics, making them incredibly difficult to detect with traditional methods. There’s a fuller look at the unseen force in cybersecurity.

The core problem is AI’s ability to perfectly mimic human behavior and voice patterns. Your current security might be good at spotting anomalies in IP addresses or unusual login times, but what happens when the ‘person’ logging in sounds exactly like your CEO, uses their typical phrasing, and even knows specific details about your business? That’s the power of agentic AI. It’s not just about fooling a system; it’s about fooling people at a fundamental level, making social engineering exponentially more effective. This shift requires a complete re-evaluation of how to protect business from AI-driven fraud.

2. Implement Advanced Identity Verification Solutions

If AI can perfectly mimic a human, then the only reliable defense is to verify that the human is, in fact, real. This is where advanced identity verification (IDV) comes into play. Traditional methods like password-based logins or even two-factor authentication (2FA) via SMS are increasingly vulnerable. AI can intercept codes, clone voices for phone verification, or even bypass knowledge-based authentication if it has enough data.

You need to move towards AI-native IDV solutions that use biometrics. This means things like liveness detection during video calls to ensure a real person is present, not a deepfake. It involves advanced facial recognition that can detect subtle inconsistencies that betray AI manipulation, or robust fingerprint and iris scans. For customer onboarding, for example, consider solutions that require a live video selfie scan against a government-issued ID, with algorithms specifically designed to spot AI-generated fakes or masks. This is a crucial step in how to protect business from AI-driven fraud. (See: FBI Cyber Crime Reports.) Related reading: an essential survival strategy.

3. Fortify Your Email and Communication Channels

Email remains a primary vector for fraud, and AI is making it terrifyingly effective. AI can write emails that are grammatically perfect, contextually relevant, and psychologically manipulative, often impersonating trusted individuals like suppliers, clients, or even internal executives. The days of easily spotting a phishing email by poor grammar are over.

Beyond traditional spam filters, invest in advanced email security solutions that leverage AI themselves to detect subtle patterns indicative of agentic fraud. Look for tools that can analyze sender behavior, email content for unusual requests, and even cross-reference against known scamming patterns. Implement strict internal protocols: verify any unusual payment requests or changes in banking details through a secondary, out-of-band channel – a direct phone call to a known number, not just replying to the email. Educate your team relentlessly about these sophisticated AI-driven phishing attempts.

4. Leverage AI for Your Own Defense: AI-Native Security

Fighting fire with fire isn’t just a cliché; it’s a necessity in the age of agentic fraud. Since AI is driving the attacks, AI must also be at the forefront of your defense. This means shifting from reactive, rule-based security systems to proactive, AI-native defense mechanisms. These systems can analyze vast amounts of data in real-time, identify anomalous behaviors that human eyes would miss, and predict potential threats before they fully materialize.

Think about AI-powered intrusion detection systems that monitor network traffic for patterns of AI agent activity, or behavioral analytics tools that learn the normal operational patterns of your employees and systems, flagging anything that deviates. These tools can spot a deepfaked voice during a phone transaction or an AI-generated text interacting with your chatbots in ways that betray its non-human origin. This strategic pivot is fundamental to how to protect business from AI-driven fraud effectively.

5. Strengthen Employee Training and Awareness

Even with the most advanced technology, your employees are often the weakest link. But in the context of AI-driven fraud, ‘weakness’ isn’t about carelessness; it’s about being outmatched by sophisticated impersonations. Traditional security awareness training needs a serious upgrade. It’s no longer enough to warn about suspicious links; you need to teach about deepfake audio, video impersonations, and the psychological tactics AI can employ.

Conduct regular, realistic simulations of AI-driven phishing, vishing (voice phishing), and smishing (SMS phishing) attacks. Teach employees to question everything, especially urgent requests or those that circumvent normal protocols. Emphasize multi-channel verification for sensitive transactions. For example, if a supplier emails you with new bank details, train your staff to call that supplier on a known, verified number (not one provided in the email) to confirm the change. Human skepticism, combined with robust protocols, remains a critical layer of defense. We covered a game-changing cybersecurity statistic in more detail.

6. Implement Robust Fraud Detection and Prevention Platforms

For businesses handling transactions, especially those in financial services or e-commerce, a comprehensive fraud detection and prevention platform is non-negotiable. These platforms increasingly integrate AI and machine learning to analyze transaction data, user behavior, and device fingerprints to identify fraudulent activity in real-time. They can spot patterns that indicate account takeover, synthetic identity fraud, or other sophisticated scams driven by AI. (See: CDC Cybersecurity Resources.)

Look for solutions that offer adaptive risk scoring, meaning they continuously learn and adjust their risk assessments based on new data and evolving threat landscapes. These platforms can identify when an AI agent is attempting to make multiple small purchases, test stolen credit card numbers, or manipulate loyalty programs. Integrating such a platform is a powerful way to enhance how to protect business from AI-driven fraud at the transactional level.

7. Secure Your APIs and Digital Touchpoints

Many businesses rely on Application Programming Interfaces (APIs) to connect different systems, exchange data, and enable digital services. These digital touchpoints are prime targets for AI-driven attacks. AI agents can relentlessly probe APIs for vulnerabilities, attempt to inject malicious code, or exploit misconfigurations to gain unauthorized access or extract data.

It’s crucial to implement strong API security measures. This includes robust authentication and authorization protocols, rate limiting to prevent brute-force attacks, and continuous monitoring for unusual API call patterns. Regularly audit your APIs for vulnerabilities and ensure they are patched promptly. Think about using API gateways that provide an additional layer of security, filtering requests and protecting your backend systems from direct exposure to potential AI attacks.

8. Regularly Audit and Update Your Security Infrastructure

The threat landscape is evolving at an unprecedented pace, thanks to AI. What was cutting-edge security last year might be obsolete next year. Therefore, regular audits and updates of your entire security infrastructure are paramount. This isn’t a ‘set it and forget it’ situation.

Schedule quarterly or even monthly security assessments. This includes penetration testing to identify weaknesses, vulnerability scanning, and reviewing access controls. Ensure all software, operating systems, and applications are kept up-to-date with the latest security patches. Many breaches occur because organizations fail to patch known vulnerabilities. In the context of AI-driven fraud, an unpatched system is an open invitation for an autonomous agent to exploit. For more on this, see how to identify deepfake scams.

9. Develop a Robust Incident Response Plan

Even with the best defenses, a breach is always a possibility. The question isn’t *if* it will happen, but *when*. Having a well-defined and regularly practiced incident response plan is crucial. This plan should detail the steps to take immediately after a suspected or confirmed security incident, especially one involving AI-driven fraud. (See: New York Times on AI and Cybersecurity.)

Your plan should cover detection, containment, eradication, recovery, and post-incident analysis. Who needs to be notified? What systems need to be isolated? How will data be restored? How will you communicate with customers and stakeholders? Practicing this plan through tabletop exercises can help ensure your team knows exactly what to do under pressure, minimizing damage and recovery time. This preparedness is an often-overlooked aspect of how to protect business from AI-driven fraud.

10. Collaborate and Stay Informed

No business is an island, especially when facing a global, AI-driven threat. Staying informed about the latest tactics, techniques, and procedures (TTPs) used by AI fraudsters is essential. Join industry-specific cybersecurity forums, subscribe to threat intelligence feeds, and participate in information-sharing groups.

Collaborate with cybersecurity experts, even if it’s just for consulting services. They can provide insights into emerging threats and help you tailor your defenses. The cybersecurity community is constantly working to understand and counter these new AI-driven attacks. By staying connected and informed, you can leverage collective knowledge to bolster your own defenses against this rapidly evolving form of fraud.

The rise of agentic fraud is not just another cybersecurity challenge; it’s a fundamental shift in the landscape of digital security. With AI projected to dominate over 90% of all attacks by 2028, businesses simply can’t afford to stick to old playbooks. The time to act, to implement advanced identity verification, AI-native defenses, and robust employee training, is now. Your business’s future literally depends on it.

Frequently Asked Questions

What is agentic fraud in cybersecurity?

Agentic fraud refers to a new form of cybercrime where artificial intelligence operates autonomously, mimicking human behavior to execute scams. Unlike traditional fraud, where humans are involved, agentic fraud involves AI systems that can bypass security protocols effectively, making it a significant threat to businesses.

How much will AI-driven fraud increase by 2028?

According to recent projections, AI-driven fraud is expected to exceed 90% of all cyberattacks by 2028. This alarming increase highlights the need for businesses to adapt their cybersecurity measures to combat this emerging threat.

What are the impacts of AI on small businesses?

Small and medium-sized businesses (SMBs) are particularly vulnerable to AI-driven fraud due to limited resources for cybersecurity. The rise of agentic fraud poses a significant risk, making it crucial for SMBs to implement robust security measures to protect against these sophisticated attacks.

How can businesses protect themselves from AI scams?

Businesses can protect themselves from AI scams by understanding the nature of agentic fraud, investing in advanced cybersecurity solutions, training employees on recognizing threats, and implementing strict security protocols to safeguard their operations against AI-driven attacks.

What are the financial losses from cybercrime in recent years?

In 2025, the FBI reported $20.9 billion in U.S. cyber-enabled losses. This figure underscores the severity of cybercrime and the increasing financial impact on businesses, highlighting the urgent need for enhanced cybersecurity measures.

Agree or disagree? Drop a comment and tell us what you think.

Choose your Reaction!