Short Wave - The new era of AI-powered cybercrime

Episode Date: August 3, 2026

Hacking has been on the rise around the world. In 2025, the FBI’s Internet Crime Complaint Center received over 1 million complaints of cybercrime, a record high in the US. Hackers are always gettin...g more creative, and now they have a new tool at their disposal: AI. Interested in more tech in the news? Email us your question at shortwave@npr.org.Support public media with NPR+ and enjoy perks for over 25 podcasts like this one. It includes perks like bonus episodes, early access, archive access, curated playlists and sponsor-free listening. Learn more at plus.npr.org. See pcm.adswizz.com for information about our collection and use of personal data for sponsorship and to manage your podcast sponsorship preferences.NPR Privacy Policy

Transcript
Discussion (0)
Starting point is 00:00:00 You're listening to Shortwave from NPR. Hey, Shr Waver is Regina Barbara here and Emily Kwong. And in today's episode of our tech camp series, we're talking about hackers, aka cybercriminals. Cybercrime is on the rise around the world, including in the U.S. The FBI's Internet Crime Complaint Center received over one million complaints of cybercrime in 2025. That is a record high. Wow. And listen, hackers are always trying to get more creative.
Starting point is 00:00:30 But these days, there are so many different ways a cybercriminal can trick you into handing over your password or transferring money or giving them something that they want. And one way is by pretending to be somebody that you can trust. A perfect example of this is in the movie Oceans 8. Yeah, I remember this. Rihanna, she plays this hacker and she figures out that somebody at the Metropolitan Museum of Art loves like a specific kind of dog. Wheaton Terriers. Yeah. And she sends them an email with this like adoption poster. It's like flashing.
Starting point is 00:01:02 There's colors. Yeah. And this is so that her and her team can gain access to the Met Security system. He has hard eyes for the Terriers and he totally clicks on the flyer. This scene, by the way, Ryan Callumber loves it. He's the chief strategy officer at ProofPoint, a major cybersecurity company. She actually does it perfectly. She understands what kind of content he would interact with and be likely to respond to.
Starting point is 00:01:27 And she fishes him. Shout out to Rihanna on this one. Great cyber criminal example there. I mean, Rihanna can do anything, really. Musician, entrepreneur, hacker. Yeah, she's a master hacker. And I guess that's why we need cyber security people like Ryan to stand up to them. Yeah. Yeah. And his field is getting more complicated because of clever attacks like these and, in part, because of AI. Because why wouldn't you? It's easier. It's faster. And it's actually harder to detect in a lot of cases. For cybercriminals who know what they're doing, AI is a tool that can help them write trickier emails, find more bugs in software, and automate parts of their attacks. And it's creating a lot more work for the people defending your networks.
Starting point is 00:02:09 So today on the show, the future of cybersecurity, how AI is transforming tech and what can be done to stop hackers in their tracks. I'm Regina Barber. And I'm Emily Kwong. And you're listening to Shortwave, the science podcast from NPR. All right, M. I'm super excited for this episode, and I'm also very unsure of where to start because it feels like these attacks can come from anywhere. Yeah, so much of daily life is connected to the Internet. And that is why, my friend, cybersecurity is so important. So I want to start with one of the key principles in cybersecurity.
Starting point is 00:02:49 It is called the Cybersecurity Triad, or CIA. Not that CIA, a different CIA, of course. This is Ryan at Proof Point, who we met earlier, the one who really likes that Ocean's Eight scene. And he explained to me that this CIA stands for confidentiality, integrity, and availability. That is the cybersecurity North Star. So can you give me an example of CIA in action? Yeah. Okay.
Starting point is 00:03:13 I'll give you an example. So say your health records are stored digitally on a shared computer system, right? These records should be available to you, to your medical team, maybe someone at your insurance company. But to stay within that close circle, they better be encrypted. Okay. So that's the confidentiality part. Mm-hmm. Now, the integrity part means no one should be able to corrupt or edit your health records, you know, to change something about your medication, et cetera. And availability is just about being able to access your data at all.
Starting point is 00:03:42 In a ransomware attack, your health care information is not available to you, not available to your doctor, to your nurse, to anybody else involved in your care, which has happened in so, so, so many famous cases. Hollywood Presbyterian, actually where my father was born, was the first note. Worthy one. So back in 2016, this hospital was locked out of their system for two weeks and ended up paying the hackers in Bitcoin to regain access. That is so long. Yeah. And 10 years later, this perfect triad is becoming more difficult to maintain. Here's Ryan again. It's easier to do cybercrime than it's ever been before because the resources to educate yourself or even do it for you are freely available. to anybody on the internet. Oh, that's so scary. But let's, like, put a face to the name, like, who are these cybercriminals these days?
Starting point is 00:04:37 I have this mental image of somebody, like, in a hoodie, in a garage. But I imagine, like, cybercrime is more sophisticated now. It is for sure. Picture loosely organized networks all over the world. Stealing money, information, targeting individuals, yes, but we're also seeing attacks on major companies and supply chains. There is a lot of money to be made there. And sometimes, Gina, these cybercriminals will partner with governments.
Starting point is 00:05:04 Hackers doing the bidding of governments are called nation-state actors. There's a lot of this in North Korea, Iran, China, and the Russian Federation. Right. This makes me think of the Russian hacking group that interfered with the 2016 election. Yeah, and that group, now known as Fancy Bear, was an actual unit of Russian military intelligence. Nation-state actors are always trying to get better and harder to detect. But I want to focus this episode really on cyber criminals and what we know about how they're using AI. So can you say more about that? How is AI making attacks better? Yeah. So one of the reasons a lot of people use AI is for language, right? And AI breaks the language barrier.
Starting point is 00:05:44 Those emails from someone claiming to be a Nigerian prince written haphazardly in Google Translate are a thing of the past. Now Ryan says he's seen tidal waves of malicious emails in almost perfect Japanese. Wow. Then there's the fact that AI makes attacks harder to spot. Think hyper-personalize emails, deep fake voice calls, deep fake video calls. Lastly, there are certain AI models that can find vulnerabilities in computer code itself. Yeah, I remember all of our like cyber security training lessons here at NPR. And AI was being used to like trick us.
Starting point is 00:06:18 So can AI be used for good? Like with the vulnerability detection work? Yes. Yes, but if bad actors get their hands on those same vulnerability detecting models, that's bad. That worries cybersecurity folks like Ryan. So that's why there's a lot of chatter about this new model from the company Anthropic called Claude Mythos. That is really good at discovering computer code vulnerabilities. It helps defenders, but it could also help attackers.
Starting point is 00:06:45 It helps both sides if they make use of it properly. It makes us faster. It makes our adversaries faster. And the question was who was going to win that race. In June, President Trump signed an executive order about this. The administration wants to require developers to submit certain AI models for government review 30 days before going public with them. All of this is to mitigate the cybersecurity threats posed by AI. Wait, so this seems like a change of stance for the president.
Starting point is 00:07:14 Wasn't the Trump administration not going to regulate AI? It did seem that way. Okay. Yeah. But their argument now is these tools could. be dangerous in the hands of cybercriminals and other bad actors. I will say, though, the same is true on the other side. AI can help the good guys, too.
Starting point is 00:07:32 It can help cybersecurity experts like Ryan, find holes in code, and patch them. Wow. So AI is having almost a civil war within itself, like good AI, fighting bad AI, and then it turns into good AI. At the direction of humans, yeah. Yeah. Yeah, yeah. And one of the things Ryan wants to do is train our email agents like Microsoft co-pilot or Google. Gemini to stand their ground against this other malicious AI. If you can just convince the AI to do something, then some of that same human risk has now
Starting point is 00:08:03 become AI risk. And if our AI agents are just as gullible as us, that's a big problem. Wow. I hadn't even thought of that. Yeah, I feel like this whole episode, I'm just watching your eyes get wider and wider and wider. Yeah. But no, at the end of the day, governments and companies and cybersecurity experts are responsible for this. They have a lot of work to do to do. deal with these problems. And in the meantime, training can help prepare us individuals for this future. What I would love is if for once the defenders are able to move faster than the attackers. But we need to mobilize the defender workforce. Not enough people like Ryan do this work. According to the ISC2-20204 cybersecurity workforce study, there are over 500,000 unfilled
Starting point is 00:08:47 cybersecurity positions in the U.S. Yeah, I remember when I was teaching at Western Washington University There was just a huge push for people to go into this field. Oh, really? Yeah. So someone also trying to make that push is Charlene Cooper. She's the director of cyber.org and focuses on K-12 cybersecurity education. Charlene's got a 16-year-old son and has learned this technology for all its upsides and downsides right alongside him. There was a misconception he had about people that were online.
Starting point is 00:09:17 And it was like, well, this person says they're from here, here and here. And how do you know that for sure? I live by the old X-Files rule. Trust no one, right? Like I tell my kid to always verify and just like, don't talk to strangers. I've made her more scared of the world. But you know what? She is skeptical of the internet.
Starting point is 00:09:34 Yeah, that makes sense. Because honestly, a lot of Charlene's work lately is focused on training caregivers and teachers to be comfortable talking to their kids about their digital hygiene. Asking questions like, what do you like to do online? What types of sites are you going to? and especially if your child is engaging in chatting people on websites, on online video games. Roblocks. Teach your kid to not give away any personal information.
Starting point is 00:10:00 Their name, their school name, their age, where they live. Oh, stranger danger. They need to know that. Yeah, stranger danger will save you. And for kids who want to level up their cybersecurity education even further, they can go to camp. So I'm going to introduce you to Ashley Potterodzky. She's the vice president for research and economic development at Dakota State University. And there she co-founded an entire organization devoted to teaching the next generation cybersecurity.
Starting point is 00:10:27 It's called Saib Her. And at Saib Her, they offer a residential cybersecurity summer camp for students who want to learn how to do things like crack a password. Not because we're trying to create little hackers, but we're trying to get them to understand how easy it is for a bad actor to crack a password. And then she has campers make their own password as a test. And then the algorithm that we're using to crack the password. It says it's going to take 200 years with current computing power. Then they know they made a good password. Oh, that's so cool.
Starting point is 00:10:57 It's like being graded right away, too. You're such a student. I know. And that's good. That's the right attitude. I mean, all the experts I spoke to kept saying, cybersecurity is not an all-tech field. It's really a critical thinking field.
Starting point is 00:11:12 It's about problem-solving. So if AI is making it easier to commit cybercrimes, let's make it easier for young people to get involved and fight back. Here's Ashley. So growing up, people always said, are you good at math and science? Maybe you should look at a career in STEM. I think we need to flip that. I think we need to ask kids, are you curious? Do you like technology? Do you want a high-paying job? And if they can say yes to those three, then that's something that they should pursue for STEM and Cyber. Emily Kong, thank you so much for bringing another illuminating story. You're welcome, Gina. There are a ton of resources we've included with this episode from cyber and cyber.org. check out the link in our show notes. If you like this episode, check out the rest of our series
Starting point is 00:11:55 on our Tech Future. We're airing episodes every Monday through August. We know the future's scary, but we can get through it together. I'm excited about the future. This episode was produced by Hannah Chin. It was edited by our showrunner, Rebecca Ramirez, and fact-checked by Tyler Jones. Special thanks also to Jenna McLaughlin, NPR's cybersecurity correspondent, who reports on this stuff around the clock. Robert Rodriguez was the audio engineer. I'm Regina Barber. And I'm Emily Kwong. Thank you for listening to Shorewave from NPR.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.