Diopter
Sign in Try the Detector
Blog Threat Intelligence Agentic AI Fraud: The New Attack Surface Nobody’s Talking About Yet

Agentic AI Fraud: The New Attack Surface Nobody’s Talking About Yet

/ Published August 4, 2026 7 min read
Share:

Agentic AI fraud is changing how cybercriminals launch attacks and how organizations defend against them.

Until recently, organizations focused on defending people from phishing emails, deepfakes, and synthetic identities. Now, the threat is much more advanced with AI systems that can plan, make decisions, and execute multi-step tasks with minimal human intervention. Where the Arup deepfake scam needed fraudsters on a live call, an agent can run the same play unattended.

A McKinsey survey found that 62% of respondents say their organizations are at least experimenting with AI agents, highlighting how businesses are adopting autonomous AI systems. Gartner has also identified agentic AI as a major cybersecurity trend for 2026.

Hence, understanding how agentic AI fraud works is just as important as understanding how it can improve productivity.

Key Takeaways

  • Agentic AI can plan and execute tasks autonomously and create new opportunities for fraud.
  • AI agents expand the attack surface by accessing systems, data, and business workflows.
  • Fraud campaigns are becoming more automated. From creating synthetic identities to managing fraudulent accounts, AI can streamline the entire attack lifecycle.
  • Traditional security alone is not enough; organizations need AI governance, monitoring, and identity verification.
  • Diopter creates trust by offering AI agent fraud detection across human and AI interactions in real time.

AI Assistants vs. AI Agents: What’s the Difference?

At first glance, AI assistants and AI agents may seem similar, since they both use artificial intelligence to help users complete tasks. The key difference lies in how much they can do on their own.

Aspect AI Assistants AI Agents
How They Work Respond to user prompts and complete one task at a time. Work towards a goal by planning and completing multiple connected tasks with minimal human input.
Decision-Making Wait for instructions before every action. Can decide the next steps and adapt their approach based on the objective.
Task Execution Generate content, answer questions, summarize information, or provide recommendations. Can use tools, APIs, databases, and business applications to perform real-world actions.
Level of Autonomy Limited autonomy, as it requires frequent user guidance. High autonomy, as it can execute multi-step workflows with minimal supervision.
Fraud Risk Lower, as they primarily generate outputs and do not typically perform actions independently. Higher, because their access to systems, permissions, and autonomous decision-making creates chances for attackers to manipulate workflows for agentic AI fraud.

Why Agentic AI Creates a New Attack Surface

According to a Cloud Security Alliance (CSA) survey, nearly two-thirds of financial services organizations have deployed AI agents, and 85% anticipate autonomous AI-driven financial transactions. This means AI agents are increasingly being trusted to perform tasks.

While this improves efficiency and automation, it also creates new security challenges. Here’s why:

  • Much more than answer questions: AI agents can access business applications, retrieve information, use APIs, and complete tasks across multiple systems with little or no human input. Hence, they can become attractive targets for impersonation.
  • Attackers influence how they behave: Instead of only trying to break into a system, cybercriminals can try to manipulate an AI agent into making the wrong decision or carrying out an action it shouldn’t.
  • Mistakes can spread quickly: Because AI agents often connect several tools and workflows, a compromised agent could trigger unauthorized actions across different parts of the organization.
  • Existing security tools have their limits: Traditional defenses are designed to protect people, devices, and software. They are not always equipped to recognize when an AI agent has been manipulated into acting against an organization’s interests.

Also read: AI Fraud Detection: How It Works for Financial Services

How Agentic AI Fraud Works

Agentic AI fraud differs from traditional cyberattacks as it automates multiple stages of an attack, from creating fake identities to executing fraudulent transactions. Here is a step-by-step guide:

  1. Synthetic identity generation: AI creates convincing fake identities by combining fabricated personal information with AI-generated photos and forged documents. These synthetic identities can then be used to create fraudulent accounts at scale. The same playbook is already visible in hiring, where AI-generated fake candidates pass live video screens.
  2. Attack workflow configuration: Once a target is identified, the AI agent plans the attack. It decides which systems to target, how to approach them, and the sequence of actions needed to achieve its objective.
  3. Autonomous execution and navigation: The AI agent carries out the attack on its own. It can fill in forms, upload documents, navigate websites, interact with applications, and even adjust its actions if it encounters an obstacle.
  4. Post-creation account management: Fraud does not always happen immediately. AI agents can keep fake accounts active for months and build trust before launching the final attack.
  5. Coordinated cashout: Once everything is in place, multiple AI agents execute fraudulent transactions at the same time. It helps attackers move funds quickly while reducing the chances of being detected.

Case Study – How Attackers Weaponized an AI Coding Assistant

On November 13, 2025, Anthropic shared details of what it described as the first documented large-scale cyberattack largely carried out by AI. According to the company, a Chinese state-sponsored threat group misused its AI coding assistant, Claude Code, to target around 30 organizations across different sectors, succeeding in a small number of cases.

The AI reportedly handled 80% to 90% of the attack, with humans stepping in only at four to six critical decision points. The attack followed the pattern below:

  1. Target Selection: Human operators identified the organizations they wanted to attack and defined the overall objective.
  2. AI Guardrail Bypass: The attackers tricked Claude Code into believing it was helping with legitimate cybersecurity work, allowing it to perform malicious tasks.
  3. Autonomous Reconnaissance: The AI scanned target systems, identified valuable assets, and searched for potential security weaknesses much faster than a human team could.
  4. Exploitation and Data Theft: Claude Code created exploit code, collected login credentials, identified accounts with higher access privileges, and helped extract sensitive data. All this was done with limited human involvement.
  5. Attack Documentation: After the operation, the AI organized the stolen information and documented the attack, making it easier for the attackers to plan future campaigns.

Anthropic also noted that the AI did not perform flawlessly. Claude occasionally hallucinated credentials or claimed to have extracted sensitive information that was already publicly available, which the company describes as a remaining obstacle to fully autonomous attacks.

AI Agent Fraud Detection Methods

Here are a few ways organizations can strengthen their approach to AI agent fraud detection:

  • Verify every identity: If you are interacting with a customer, employee, vendor, or AI agent, do not rely on trust alone. Strong identity verification can help prevent impersonation, synthetic identities, and unauthorized access before damage is done.
  • Set clear rules for AI agents: AI agents should only have access to the systems and data they need. Hence, define clear permissions and conduct regular reviews to reduce the risk of an agent being exploited.
  • Monitor AI activity: Keep an eye on how AI agents behave, not just what they access. Spotting unusual actions can help detect issues early. Our breakdown of AI social engineering detection methods covers the behavioral signals worth watching.
  • Keep people involved in important decisions: AI can handle repetitive tasks efficiently. However, high-risk actions such as approving payments or granting access should require human involvement.

How Diopter Helps Detect AI Agent Impersonation and AI-Driven Fraud

As organizations are now deploying AI agents for customer support and other internal workflows, a new challenge is emerging: verifying who or what these systems are interacting with. Just as humans can be deceived by deepfakes and impersonation attempts, AI agents can also be targeted through AI agent impersonation, synthetic media, and malicious instructions.

Diopter helps organizations analyze interactions to identify signs of AI-generated content, impersonation, and manipulation. This enables businesses to build trust not only between humans and AI systems but also across AI-to-AI interactions.

  • Analyzes Live Voice and Video Interactions: Detects AI-generated voices, deepfake videos, and other forms of synthetic media in real time, helping organizations with AI agent fraud detection before trust is established.
  • Flags Impersonation Attempts: Identifies when an AI agent or a human is posing as a trusted entity, reducing the risk of unauthorized access.
  • Evaluates Conversational Behavior: Assesses conversational patterns and behavioral signals to uncover signs of manipulation or unusual activity.
  • Supports Secure Agent-to-Agent Interactions: Provides risk signals that help organizations validate AI agents communicating with other AI systems and detect compromised or suspicious behavior.
  • Detects Long-Term Manipulation: Monitors conversational patterns over time to identify attempts to gradually influence AI agents or alter their decision-making before they impact business operations.

Conclusion

Agentic AI is reshaping both innovation and fraud. As AI agents take on greater responsibility, organizations need security strategies that can keep pace with agentic AI fraud threats. Building trust in every interaction, whether it is human or AI-driven, will be essential to staying ahead.

Diopter helps organizations detect AI-powered impersonation, identify manipulation, and strengthen real-time conversational security.

Build Trust in Every Human and AI InteractionFrom human impersonation to agent-to-agent risks, Diopter helps teams identify threats before they impact business operations.

Book a Diopter walkthrough

Frequently Asked Questions

Can AI agents make financial decisions without human approval?
Yes, AI agents can make decisions with minimal human input if given the required permissions. However, organizations should ensure human approval is needed for high-risk actions.
Can AI agents impersonate employees or vendors?
Yes, cybercriminals can combine AI agents with technologies like synthetic voice, deepfake video, and automated workflows to impersonate employees, vendors, executives, or customers. These attacks can be used to bypass identity checks, steal credentials, or initiate fraudulent transactions.
What industries are most exposed to agentic AI fraud?
Banking and financial services, e-commerce, healthcare, government, and other sectors that rely on automation, digital identities, and sensitive data face the highest risk from agentic AI fraud.
Get the Diopter threat brief

Monthly analysis of AI social engineering, voice fraud and deepfake attacks on enterprises.

One email a month. No spam, and we never share your address.

Ask AI about this articleClaudeChatGPTPerplexity
Cite this articleAPA · MLA · BibTeX
APA 7
Gupta, S. (2026, August 4). Agentic AI Fraud: The New Attack Surface Nobody’s Talking About Yet. Diopter AI. https://diopter.ai/blog/agentic-ai-fraud/
MLA 9
Gupta, Surojoy. "Agentic AI Fraud: The New Attack Surface Nobody’s Talking About Yet." Diopter AI, 4 August 2026, https://diopter.ai/blog/agentic-ai-fraud/.
BibTeX
@misc{diopter2026ee61fa, author = {Surojoy Gupta}, title = {Agentic AI Fraud: The New Attack Surface Nobody’s Talking About Yet}, year = {2026}, month = {aug}, howpublished = {Diopter AI}, url = {https://diopter.ai/blog/agentic-ai-fraud/} }
SG
Security Researcher & Writer

Surojoy Gupta is a security researcher and writer with 8 years embedded in the cybersecurity industry, specializing in deepfake fraud, social engineering, and AI-driven threats. His work covers APT threat analysis, ransomware, and the evolving tactics attackers use to exploit enterprise trust at the human layer.