Cybercrime Southeast Europe Newsletter No. 117
When a Scam Looks Like a Familiar Brand – AI Is Changing the Way Cybercriminals Approach Victims
Online scams no longer have to arrive from a suspicious email address, contain poorly written messages or direct users to an obviously questionable website.
New research by Kaspersky, conducted in Serbia and 11 other countries, highlights a growing problem: cybercriminals are using artificial intelligence to imitate the identities of well-known companies and organisations, creating the impression that users are communicating with an entity they already trust.
According to data published for Serbia, brand impersonation accounts for 33.2% of reported scams on communication platforms, while 38.4% of scams begin through WhatsApp, 32% through Facebook and 27.2% through SMS/iMessage.
Trust becomes part of the scam
A particular danger of this type of fraud is that victims are no longer necessarily dealing with an unknown company or individual attempting to gain their trust.
Fraudsters may impersonate banks, delivery companies, telecommunications providers, well-known retailers, employers, streaming services and even charitable organisations.
By using a familiar name, logo, communication style and visual identity, a fraudulent message or website may initially appear almost identical to a legitimate one.
Artificial intelligence makes it easier to produce convincing text, advertisements and other content. As a result, traditional warning signs – such as poor grammar or obviously unprofessional design – are no longer sufficient.
When victims are repeatedly asked to pay more
The research also highlights a pattern particularly familiar in investment and other financial fraud.
One respondent from Serbia described being repeatedly asked to provide additional money in order to supposedly receive a payout.
This pattern should be treated as a serious warning sign.
After an initial payment, further demands may follow – for an additional fee, tax, verification payment, account activation or another purported requirement that must be satisfied before the funds can be released.
The fact that a user has already transferred money does not mean that making an additional payment will enable a withdrawal.
A familiar name is not proof of authenticity
The development of these scams also changes the way online communication should be verified.
It is no longer enough simply to ask: “Does this look legitimate?”
The more important question is: “Can I independently verify who is actually contacting me?”
If a message contains a link or requests a payment, banking details, passwords or other sensitive information, it is safer not to rely on the contact details or link contained in that message.
Instead, users should independently visit the organisation’s official website and verify the request through contact information published there.
Particular caution is required when the message also creates a sense of urgency – for example, by claiming that an account will be blocked, money will be lost or an opportunity will disappear unless the user acts immediately.
Technology used by legitimate companies to improve communication with customers can also be used to create highly convincing fraudulent communications.
For this reason, a familiar name, professional-looking website or convincing message is no longer sufficient evidence that the communication actually originates from the company whose identity is being used.
Anyone who has already transferred money or provided information should preserve messages, emails, links, screenshots, payment records and any other information that may later help establish how the communication and transaction took place.
DefendMe Global