Editorial explainer · official sourcesmedium
AI did not create the genius hacker: it industrialised the mediocre one
Two opposite and equally wrong stories circulate about AI and cybercrime: that it changes everything, and that it changes nothing. The data in ENISA's Threat Landscape 2025 tell a more precise reality. AI has not created a genius attacker capable of technical magic: it has made the average attacker faster, cheaper and more convincing, multiplying the volume of phishing and lowering the barrier to entry. The cultural consequence is counterintuitive: the defences that matter remain the ones we already had. An explainer on what really changes, minus the hype.
Two wrong stories
When people talk about artificial intelligence and cybercrime, they usually split into two exaggerations. The first: AI has created a new species of all-powerful hacker, against whom there is no defence. The second: it is all marketing, nothing has changed. ENISA's Threat Landscape 2025 — the annual report of the European cybersecurity agency, published in October 2025 and based on the analysis of 4,875 incidents between July 2024 and June 2025 — lets us replace opinion with data. And the picture that emerges is more precise than either caricature.
The figure that sums it all up: by early 2025, according to ENISA, AI-supported phishing accounted for more than 80% of the social-engineering activity observed globally. Not a niche activity of the most skilled: the dominant mode.
What really changes: volume, not genius
The most useful reading of the report is this: AI has not handed attackers technical tricks that were impossible before. It has removed friction. It has made it trivial to produce, in seconds and in any language, a grammatically perfect and contextually credible phishing email — goodbye to the translation errors that for years were the first warning sign. It has made it possible to generate lures at previously unthinkable volumes. ENISA documents the emergence of tools built for exactly this — names like WormGPT, EscapeGPT, FraudGPT — that automate the creation of deceptive messages, and even autonomous malicious AI systems and fake AI-tool websites used to distribute ransomware and tampered installers.
The right word, then, is not "genius" but "industrialisation." AI takes the mediocre attacker — the one who got the grammar wrong, who could not scale, who hit few targets at a time — and makes them fast, cheap and prolific. The threat has not become more intelligent: it has become more abundant and harder to tell apart by eye.
The frontier should also be flagged, with the caution it deserves. The first reports are circulating of criminal operations driven almost entirely by agents based on language models, able to run several phases of an attack with little human input. These are emerging cases, mostly reported by single pieces of research: they should be treated as signals of where the phenomenon is heading, not as an established state of affairs. Saying so is part of the job.
- 01Beforephishing with errors, hard to scale, easy to sniff out
- 02With AIperfect messages, in every language, at huge volumes
- 03The consequencenot smarter, but far more abundant
The cultural lesson
If the change is in volume and credibility, and not in some new technical magic, then the consequence is counterintuitive but liberating: the defences that work remain the ones we already had. Phishing-resistant multi-factor authentication still stops credential theft even if the email asking for them is beautifully written. The out-of-band verification of an unusual request — a phone call to the real colleague — dismantles the cloned voice just as it dismantled the misspelled email. Updates, backups, segmentation: none of these become less effective because the lure is more polished.
What changes, if anything, is the register of awareness. We can no longer teach people to spot phishing by its bad grammar, because there is none left. The message that holds in 2026 is different: it is not what the message looks like, it is what it asks you to do. An urgent request for credentials, for a payment, for a verification code deserves the same suspicion regardless of how well written it is. AI has perfected appearances; it has, for that very reason, made suspicion about substance more valuable than ever.