INTERPOL: AI is increasing the speed and scale of cyber threats
INTERPOL reports that artificial intelligence is accelerating and scaling existing cyber threats like scams and fraud. The organization urges companies to identify their most critical assets.

INTERPOL has warned that artificial intelligence (AI) is significantly increasing the speed and scale of cyber threats. According to the international law enforcement organization, AI is not revolutionizing criminal activity but rather enhancing existing methods such as scams and fraud. Björn R. Watne, INTERPOL's global chief information security officer, stated that AI enables criminals to target multiple victims simultaneously, and improved translation capabilities and digital identities are making it harder to distinguish fraudulent interactions from genuine ones.
Watne emphasized that AI is primarily increasing the "speed and scale" of existing criminal techniques. He advised companies to prioritize identifying their most critical assets and use threat intelligence to tailor their defenses. Businesses should determine which assets are vital to their operations and who might be interested in stealing or disrupting them. Threat intelligence can then be used to understand adversaries' tactics and technologies and adapt defense mechanisms accordingly.
Furthermore, Watne expressed concern regarding agentic AI, which has the capability to perform actions on behalf of users. He cautioned that mistakes in this context could lead to real-world consequences, particularly in the physical domain, beyond just incorrect information. The increasing deployment of AI in devices like cars and self-driving vehicles heightens risks as AI systems begin to perform actions autonomously. Watne also noted the relatively high trust humans place in technology, which can exacerbate risks when systems act independently.
Watne observed that in many industries, companies have not yet fully realized that "everyone is an IT company today." While cyber risks are rising on corporate risk registers, cybersecurity has not yet fully integrated into the boardroom discussions of many organizations. Instead of merely implementing basic security measures, companies should develop targeted strategies that reflect the nature of the threats they face, whether from opportunistic criminals or advanced threat actors.