AI Is Getting Really Good at Messing With Cybercriminals

Staff
By Staff 10 Min Read

Welcome to Kernel Panic!, the weekly newsletter where Lily Hay Newman and Matt Burgess take you inside the strange and fast-moving world of privacy and digital security. If you’ve ever felt like the internet is a place where scams are not just lurking but actively hunting, this is the newsletter for you. Each week, they unpack the latest threats, vulnerabilities, and defenses, trying to make sense of a landscape that often feels chaotic. And right now, that landscape is being reshaped by artificial intelligence in ways that are equal parts terrifying and hopeful. On one hand, AI is supercharging scamming and cybercrime, giving criminals the ability to craft convincing phishing messages, mimic voices, and automate their attacks at staggering scale. On the other hand, the same technology is being recruited into the fight to protect potential victims. Governments have consistently struggled with the global crisis of online crime, largely because cybercriminals operate across borders, hiding behind anonymity and legal loopholes. But now, innovative efforts are emerging that use automation to fight back in unexpected ways—like spamming the spammers, wasting their time, and gathering intelligence on their operations. It’s a new kind of arms race, and it’s happening faster than most of us realize.

For the last two years, an Australian company called Apate has been building a system that turns the tables on phone scammers. The name comes from Apate,the Greek goddess of deception, which feels perfectly apt for a tool designed to deceive the deceivers. Apate’s approach is beautifully simple in concept: divert scammers onto calls with AI bots that are trained to keep conversations going as long as possible, without ever actually falling for the scam. “What we really like to think is that we’re building the perfect victims for scammers,” Dali Kaafar,the founder and CEO of Apate, tells Kernel Panic. These AI “victims” are designed to be just gullible enough to keep a scammer interested, but never quite ready to hand over money or personal details. The point is not to have a real conversation—it’s to burn the scammer’s time and resources. “A minute that a scammer is talking to a bot or an agent is a minute where you’re probably saving hundreds, if not thousands of possible people being reached out to by that exact same scammer,” Kaafar explains. Because scammers often use automated dialing systems that blast call after call, every minute theyspend locked in conversation with an AI is a minute they’re not spending harassing real people. It’s a guerrilla warfare tactic, and it’s surprisingly effective.

The scale of Apate’s operation is impressive. Kaafar says the platform, which is used by banks and supported by telecom companies, has around 350,000 bots active at any given time. These bots don’t just answer phone calls; they also infiltrate online scam chat groups and respond to text messages, all with the same dual purpose: frustrating scammers while collecting intelligence from them. So far, the company has gathered more than 250,000 pieces of real-time information about fraudsters, ranging from scam URLs to money mule accounts and bank details. This isn’t just a passive defense; it’s an active intelligence-gathering mission. Every time a scammer tries to convince an AI bot to “invest” in a fake cryptocurrency or share their “bank details,” the bot is quietly noting the tactics, identifiers, and infrastructure behind the operation. That information can then be used to block scams before they reach vulnerable people, take down fraudulent accounts,or warn potential victims. The bots themselves are designed to be as human as possible, with different personalities, language skills, and profiles. Some are elderly retirees, some are busy young professionals, some are skeptical but curious. Kaafar says the goal is to make it hard for scammers to detect that they’re dealing with an AI. Like real people, “sometimes [the bots] do have WhatsApp, sometimes they don’t. Sometimes they pick up the phone, sometimes they just actually hang up on the scammer saying, ‘I’ll come back to you later,'” he says. This unpredictability is key—scammers are trained to look for perfect patience or robotic compliance, so Apate makes sure its botshave human flaws, interruptions, and excuses.

But the big question is: are they actually convincing? Kernel Panic decided to test the tool using a demo version where you, the user, get to play the role of the scammer and talk to one of Apate’s AI “victims.” It’s a strange experience, to be honest. You’re suddenly in the driver’s seat, trying to craft the perfect fraudulent pitch, but facing a person (or bot) who is not making it easy. The personas are designed to express a healthy amount of skepticism but leave enough openings for you to continue trying to win them over. They ask questions, they hesitate, they say things like “Hmm, that sounds a bit risky, doesn’t it?” or “My son told me never to give out my details over the phone.” But then they’ll add, “But I do like the sound of that investment… can you tell me more?” And just like that, you feel a flicker of hope. You press on, thinking you’re finally getting somewhere—only for them to get distracted, or express confusion, or say “I’ll need to check with my husband first.” It is intensely frustrating, and that’s exactly the point. As a scammer, you’re left dangling, investing more and more time into a dead end. The demo makes you feel, visceral level, how these bots work: they’re not just a brick wall; they’re a soft, quicksand-like trap that keeps you engaged, hopeful, and ultimately empty-handed.

The implications of this approach are huge. For years, governments have been stuck in a reactive mode, trying to arrest individual scammers or shut down call centers, but the sheer volume and international nature of cybercrime has made that nearly impossible. Apate offers a different kind of solution: instead of chasing criminals, why not drown them in useless conversations? It’s a kind of digital counterinsurgency, where every bot is a soldier in a war of attrition. Banks are particularly interested,because they’re the ones who end up reimbursing victims of fraud, and telecom companies can help route suspected scam calls to Apate’s system before they reach real customers. This collaborative approach is still experimental, but it’s already produced meaningful results. The 250,000 intelligence points collected in real-time aren’t just statistics; they’re actionable data that can help dismantle scam networks, identify new money mule schemes, and track the evolution of fraud techniques. And because AI models can learn and adapt, these bots are only going to get more effective at mimicking humans, spotting scam tactics, and wasting scammers’ time.

But there’s something deeper here that feels worth holding onto. In a world where artificial intelligence often seems like a force for chaos—deepfakes, automated phishing, voice cloning—it’s genuinely refreshing to see AI being used to shield people, especially the most vulnerable, from harm. Apate’s bots are not going to end cybercrime overnight, and scammers will inevitably adapt, possibly even finding ways to use AI themselves to detect bots. But for now, the idea of “building the perfect victims” has a certain poetic justice to it. The scammers, who have spent years perfecting the art of deception, are now being deceived by machines designed to mirror our own humanity back at us. The frustration we felt in the demo is exactly what real scammers feel every day when they encounter one of these bots: the sinking realization that all their effort, all their cleverness, is being swallowed by avoid, digital void that is learning from them even as it wastes their time. That’s a small, satisfying victory in the ongoing war of the digital age. And it’s a reminder that, even as technology gets more dangerous, it can also get more protective. We just need to make sure we keep building tools that tilt the scales toward the humanswho need them most.

Share This Article
Leave a Comment

Leave a Reply

Your email address will not be published. Required fields are marked *