Agentic AI Fraud: The New Attack Surface Nobody’s Talking About Yet
Agentic AI fraud is changing how cybercriminals launch attacks and how organizations defend against them.
Until recently, organizations focused on defending people from phishing emails, deepfakes, and synthetic identities. Now, the threat is much more advanced with AI systems that can plan, make decisions, and execute multi-step tasks with minimal human intervention. Where the Arup deepfake scam needed fraudsters on a live call, an agent can run the same play unattended.
A McKinsey survey found that 62% of respondents say their organizations are at least experimenting with AI agents, highlighting how businesses are adopting autonomous AI systems. Gartner has also identified agentic AI as a major cybersecurity trend for 2026.
Hence, understanding how agentic AI fraud works is just as important as understanding how it can improve productivity.
Key Takeaways
- Agentic AI can plan and execute tasks autonomously and create new opportunities for fraud.
- AI agents expand the attack surface by accessing systems, data, and business workflows.
- Fraud campaigns are becoming more automated. From creating synthetic identities to managing fraudulent accounts, AI can streamline the entire attack lifecycle.
- Traditional security alone is not enough; organizations need AI governance, monitoring, and identity verification.
- Diopter creates trust by offering AI agent fraud detection across human and AI interactions in real time.
AI Assistants vs. AI Agents: What’s the Difference?
At first glance, AI assistants and AI agents may seem similar, since they both use artificial intelligence to help users complete tasks. The key difference lies in how much they can do on their own.
| Aspect | AI Assistants | AI Agents |
|---|---|---|
| How They Work | Respond to user prompts and complete one task at a time. | Work towards a goal by planning and completing multiple connected tasks with minimal human input. |
| Decision-Making | Wait for instructions before every action. | Can decide the next steps and adapt their approach based on the objective. |
| Task Execution | Generate content, answer questions, summarize information, or provide recommendations. | Can use tools, APIs, databases, and business applications to perform real-world actions. |
| Level of Autonomy | Limited autonomy, as it requires frequent user guidance. | High autonomy, as it can execute multi-step workflows with minimal supervision. |
| Fraud Risk | Lower, as they primarily generate outputs and do not typically perform actions independently. | Higher, because their access to systems, permissions, and autonomous decision-making creates chances for attackers to manipulate workflows for agentic AI fraud. |
Why Agentic AI Creates a New Attack Surface
According to a Cloud Security Alliance (CSA) survey, nearly two-thirds of financial services organizations have deployed AI agents, and 85% anticipate autonomous AI-driven financial transactions. This means AI agents are increasingly being trusted to perform tasks.
While this improves efficiency and automation, it also creates new security challenges. Here’s why:
- Much more than answer questions: AI agents can access business applications, retrieve information, use APIs, and complete tasks across multiple systems with little or no human input. Hence, they can become attractive targets for impersonation.
- Attackers influence how they behave: Instead of only trying to break into a system, cybercriminals can try to manipulate an AI agent into making the wrong decision or carrying out an action it shouldn’t.
- Mistakes can spread quickly: Because AI agents often connect several tools and workflows, a compromised agent could trigger unauthorized actions across different parts of the organization.
- Existing security tools have their limits: Traditional defenses are designed to protect people, devices, and software. They are not always equipped to recognize when an AI agent has been manipulated into acting against an organization’s interests.
Also read: AI Fraud Detection: How It Works for Financial Services
How Agentic AI Fraud Works
Agentic AI fraud differs from traditional cyberattacks as it automates multiple stages of an attack, from creating fake identities to executing fraudulent transactions. Here is a step-by-step guide:
- Synthetic identity generation: AI creates convincing fake identities by combining fabricated personal information with AI-generated photos and forged documents. These synthetic identities can then be used to create fraudulent accounts at scale. The same playbook is already visible in hiring, where AI-generated fake candidates pass live video screens.
- Attack workflow configuration: Once a target is identified, the AI agent plans the attack. It decides which systems to target, how to approach them, and the sequence of actions needed to achieve its objective.
- Autonomous execution and navigation: The AI agent carries out the attack on its own. It can fill in forms, upload documents, navigate websites, interact with applications, and even adjust its actions if it encounters an obstacle.
- Post-creation account management: Fraud does not always happen immediately. AI agents can keep fake accounts active for months and build trust before launching the final attack.
- Coordinated cashout: Once everything is in place, multiple AI agents execute fraudulent transactions at the same time. It helps attackers move funds quickly while reducing the chances of being detected.
Case Study – How Attackers Weaponized an AI Coding Assistant
On November 13, 2025, Anthropic shared details of what it described as the first documented large-scale cyberattack largely carried out by AI. According to the company, a Chinese state-sponsored threat group misused its AI coding assistant, Claude Code, to target around 30 organizations across different sectors, succeeding in a small number of cases.
The AI reportedly handled 80% to 90% of the attack, with humans stepping in only at four to six critical decision points. The attack followed the pattern below:
- Target Selection: Human operators identified the organizations they wanted to attack and defined the overall objective.
- AI Guardrail Bypass: The attackers tricked Claude Code into believing it was helping with legitimate cybersecurity work, allowing it to perform malicious tasks.
- Autonomous Reconnaissance: The AI scanned target systems, identified valuable assets, and searched for potential security weaknesses much faster than a human team could.
- Exploitation and Data Theft: Claude Code created exploit code, collected login credentials, identified accounts with higher access privileges, and helped extract sensitive data. All this was done with limited human involvement.
- Attack Documentation: After the operation, the AI organized the stolen information and documented the attack, making it easier for the attackers to plan future campaigns.
Anthropic also noted that the AI did not perform flawlessly. Claude occasionally hallucinated credentials or claimed to have extracted sensitive information that was already publicly available, which the company describes as a remaining obstacle to fully autonomous attacks.
AI Agent Fraud Detection Methods
Here are a few ways organizations can strengthen their approach to AI agent fraud detection:
- Verify every identity: If you are interacting with a customer, employee, vendor, or AI agent, do not rely on trust alone. Strong identity verification can help prevent impersonation, synthetic identities, and unauthorized access before damage is done.
- Set clear rules for AI agents: AI agents should only have access to the systems and data they need. Hence, define clear permissions and conduct regular reviews to reduce the risk of an agent being exploited.
- Monitor AI activity: Keep an eye on how AI agents behave, not just what they access. Spotting unusual actions can help detect issues early. Our breakdown of AI social engineering detection methods covers the behavioral signals worth watching.
- Keep people involved in important decisions: AI can handle repetitive tasks efficiently. However, high-risk actions such as approving payments or granting access should require human involvement.
How Diopter Helps Detect AI Agent Impersonation and AI-Driven Fraud
As organizations are now deploying AI agents for customer support and other internal workflows, a new challenge is emerging: verifying who or what these systems are interacting with. Just as humans can be deceived by deepfakes and impersonation attempts, AI agents can also be targeted through AI agent impersonation, synthetic media, and malicious instructions.
Diopter helps organizations analyze interactions to identify signs of AI-generated content, impersonation, and manipulation. This enables businesses to build trust not only between humans and AI systems but also across AI-to-AI interactions.
- Analyzes Live Voice and Video Interactions: Detects AI-generated voices, deepfake videos, and other forms of synthetic media in real time, helping organizations with AI agent fraud detection before trust is established.
- Flags Impersonation Attempts: Identifies when an AI agent or a human is posing as a trusted entity, reducing the risk of unauthorized access.
- Evaluates Conversational Behavior: Assesses conversational patterns and behavioral signals to uncover signs of manipulation or unusual activity.
- Supports Secure Agent-to-Agent Interactions: Provides risk signals that help organizations validate AI agents communicating with other AI systems and detect compromised or suspicious behavior.
- Detects Long-Term Manipulation: Monitors conversational patterns over time to identify attempts to gradually influence AI agents or alter their decision-making before they impact business operations.
Conclusion
Agentic AI is reshaping both innovation and fraud. As AI agents take on greater responsibility, organizations need security strategies that can keep pace with agentic AI fraud threats. Building trust in every interaction, whether it is human or AI-driven, will be essential to staying ahead.
Diopter helps organizations detect AI-powered impersonation, identify manipulation, and strengthen real-time conversational security.
Build Trust in Every Human and AI InteractionFrom human impersonation to agent-to-agent risks, Diopter helps teams identify threats before they impact business operations.
Frequently Asked Questions
Can AI agents make financial decisions without human approval?
Can AI agents impersonate employees or vendors?
What industries are most exposed to agentic AI fraud?
Monthly analysis of AI social engineering, voice fraud and deepfake attacks on enterprises.
One email a month. No spam, and we never share your address.