< Back to all clusters
[CRIME] · 2 sources

Cybercriminals exploit AI impersonation and URL shorteners in record phishing attacks

In 2025, 3.8 million phishing attacks were recorded, the highest level reported. Attackers are increasingly using legitimate URL‑shortening services such as bit.ly, t.co and is.gd to hide malicious links, allowing the messages to pass corporate email filters that whitelist these domains. The same techniques extend to QR‑code phishing, cloaking via paid ads that mimic popular software downloads, and the use of cloud storage platforms like GitHub or Dropbox to host payloads. A new vector involves generative‑AI interfaces that suggest malicious URLs without built‑in anti‑phishing protection.

A Kaspersky report covering January–April 2026 shows a five‑fold rise in malware attacks targeting small‑ and medium‑size enterprises, with more than 33 300 incidents blocked. Cyber‑crackers are impersonating public AI tools—42 % mimic ChatGPT, 24 % Claude and 20 % DeepSeek—to trick users into downloading trojans that steal data, encrypt files or destabilise systems. Attacks leveraging fake versions of communication apps such as Telegram, WhatsApp, Zoom and Microsoft Teams remain prevalent, with roughly 415 000 blocked attempts in the same period. Experts stress continuous employee training, verification of URLs and robust security solutions as essential defenses.