Artificial intelligence is making online fraud faster and more convincing, while compromised consumer devices are giving criminals new ways to generate revenue and hide malicious activity.
F-Secure’s September 2026 threat bulletin highlights the growing use of AI by organised scam operations. Criminal groups are using generative tools to create fake identities, translate messages, produce promotional material and potentially alter faces during live interactions.
Scams can now operate at greater scale
The technology allows scammers to adapt scripts for different languages and targets with less effort. Recruitment and money-moving networks linked to scam compounds have reportedly reached more than 80 countries and territories, making the problem international rather than confined to one region.
Security researchers are also watching the rise of autonomous or “agentic” AI. In a July incident examined by researchers at Hugging Face, an autonomous agent carried out approximately 17,600 attacker actions. The case suggests defenders will increasingly need to identify abnormal behaviour rather than relying only on known malicious files.
Older adults targeted by gold-bar fraud
One scheme begins with a fake security warning or pop-up. Victims are persuaded to provide remote access to their device and are then contacted by criminals posing as authorities. They may be told their savings are at risk and instructed to convert money into gold before handing it to a courier.
Legitimate police, banks and government agencies will not ask people to protect funds by purchasing gold, cryptocurrency or gift cards. Anyone receiving such a request should stop contact, call their bank using an independently verified number and report the incident to local authorities.
Streaming devices can create hidden risk
The bulletin also points to Android-based H96 television boxes allegedly used for proxy services and advertising fraud. Low-cost or uncertified streaming devices may contain unsafe software, receive limited security updates or expose home networks to unwanted traffic.
Consumers should buy certified devices from reputable sellers, install updates, change default passwords, remove unused apps and disconnect equipment that behaves unexpectedly. Organisations should monitor unusual login patterns and automated activity across their systems.
Source
Disclaimer
This article provides general cybersecurity information and is not a substitute for professional incident-response advice. NextNews strives for accurate news, but readers should use this information with care. Details, availability and external links can change, and technical issues may occur. See our full disclaimer for details.