As artificial intelligence supercharges the capabilities of digital scammers and cybercriminals, a parallel movement is emerging where AI is being recruited as a primary line of defense to protect potential victims. Governments and international law enforcement agencies have long grappled with the borderless nature of cybercrime, often finding themselves limited by jurisdictional boundaries and the sheer volume of automated attacks. This frustration has catalyzed a shift toward alternative, technology-driven strategies: using automation to go after scammers en masse by squandering their most valuable resources—time and manpower.

The emergence of AI-driven "scambaiting" marks a significant evolution in cybersecurity. Historically, scambaiting was a niche hobby performed by tech-savvy individuals who manually engaged with fraudsters to frustrate them. However, new platforms are now scaling this concept, turning experimental "trolling" into a sophisticated intelligence-gathering and resource-depletion tool. By deploying thousands of highly realistic AI personas, companies are now able to engage in a digital war of attrition against global scam syndicates.

The Rise of the Automated Victim

At the forefront of this defensive shift is Apate, an Australian cybersecurity firm named after the Greek goddess of deception. For the past two years, Apate has refined a system designed to divert phone scammers away from vulnerable humans and onto calls with AI bots. These bots are meticulously trained to sustain conversations for as long as possible, maintaining a delicate balance of interest and skepticism that keeps the fraudster on the line without ever succumbing to the scam.

Dali Kaafar, the founder and CEO of Apate, describes the project as an effort to build "the perfect victims." The logic is rooted in mathematics and resource management: every minute a scammer spends attempting to defraud an AI bot is a minute they are not targeting a real person. Given that modern scam operations utilize automated dialing tools to reach thousands of individuals simultaneously, the ability to "sink" these calls into a digital void provides a scalable form of protection that traditional law enforcement cannot match.

Currently, Apate’s platform, which has gained support from major banks and telecommunications providers, manages approximately 350,000 distinct bots. These entities do not merely answer phone calls; they are also programmed to infiltrate online scam chat groups and respond to fraudulent text messages. The primary objective is twofold: to frustrate the attacker and to harvest real-time intelligence.

Intelligence Gathering and the Mechanics of Deception

The effectiveness of these AI defenders lies in their diversity. To avoid detection by increasingly sophisticated criminal organizations, Apate’s bots are equipped with different personalities, language proficiencies, and digital profiles. Some bots may possess WhatsApp accounts while others do not; some may pick up immediately, while others might hang up and promise to call back later, mimicking the unpredictable behavior of a real human being.

This "human-centric" behavior has proven highly effective. In controlled tests, researchers have observed AI-driven conversations lasting upwards of two hours. During these interactions, the bots are programmed to extract specific pieces of information, including:

  • Fraudulent URLs used for phishing.
  • "Money mule" account numbers.
  • Bank details used for illicit transfers.
  • The scripts and psychological tactics currently being employed by specific syndicates.

To date, Apate reports having collected more than 250,000 pieces of real-time data regarding fraudster infrastructure. This intelligence is invaluable to banks and law enforcement, allowing them to flag suspicious accounts and block malicious domains before they can be used against real victims.

Case Study: Testing the Limits of AI Skepticism

To evaluate the realism of these systems, researchers and journalists have engaged with demo versions of the Apate tool, playing the role of the scammer. In one such test, an AI persona named "Lucy" was subjected to a rigorous "investment" pitch regarding a fake cryptocurrency opportunity. Despite the use of high-pressure tactics and the introduction of a second "scammer" acting as a financial advisor, the AI maintained its persona perfectly.

The AI expressed a "healthy amount of skepticism," which researchers found more convincing than total gullibility. By asking circular questions and expressing mild confusion or feigned interest, the bot managed to keep the "scammers" engaged for several minutes without ever providing sensitive data. This dynamic illustrates the "frustration factor"—a key component of the defense strategy. When a scammer realizes they have spent significant time on a lead that yields nothing, the economic viability of their operation begins to diminish.

The Broader Context: A Global Fraud Crisis

The push for AI-driven defense comes at a time of unprecedented growth in the global scam economy. According to data from the Federal Trade Commission (FTC), consumers in the United States alone reported losing a record $10 billion to fraud in 2023, a 14% increase over the previous year. Investment scams accounted for the highest losses, totaling $4.6 billion, followed by imposter scams at $2.7 billion.

The Global Anti-Fraud Alliance (GASA) estimates that nearly $1 trillion is lost annually to scams worldwide. This crisis is exacerbated by the rise of industrial-scale scam compounds, particularly in Southeast Asia, where thousands of people are often trafficked and forced to run "pig butchering" and technical support scams. These operations are run with corporate-like efficiency, making them nearly impossible to stop through traditional policing alone.

Beyond Voice: LLMs and Server Honeypots

The application of Large Language Models (LLMs) in cybersecurity extends beyond voice-based scambaiting. Security researchers have long used "honeypots"—decoy servers or systems designed to attract hackers—to study attack patterns. However, traditional honeypots often suffer from being too predictable, allowing experienced hackers to identify and bypass them quickly.

Mark Vero, a doctoral researcher at ETH Zurich’s department of computer science, has been investigating how LLMs can make these decoys more realistic. In recent research titled "Honeyval," Vero and his colleagues found that LLM-powered honeypots could keep AI-driven attacking agents engaged for significantly longer periods than static systems.

"The agentic attackers are much more convinced by the LLM-simulated honeypots and they also mark them as actual honeypots at a much lower rate," Vero noted. This suggests that as attackers begin to use AI to automate their intrusions, defenders must use AI to create more complex, responsive environments that can deceive even the most advanced automated tools.

Psychological Warfare and the RESCIND Program

The shift toward active disruption is also being explored at the governmental level. In the United States, the Intelligence Advanced Research Projects Activity (IARPA) has launched the RESCIND (Reimagining Security with Cyberpsychology-Informed Network Defense) program. This initiative seeks to exploit the "psychological vulnerabilities" of cybercriminals, such as their cognitive biases and emotional states.

By using AI to "troll" or mislead attackers, defenders can induce decision-making errors, increase the attacker’s workload, and sap their morale. This represents a transition from "passive defense" (blocking attacks) to "active cognitive defense" (manipulating the attacker’s perception of the target). Examples of this include directly messaging ransomware operators to sow doubt about their affiliates or using AI to flood their communication channels with misinformation.

Implications and Future Outlook

While the deployment of AI bots represents a significant leap forward, it is not a silver bullet. The relationship between scammers and defenders is a classic arms race. As defensive AI becomes more adept at wasting scammers’ time, criminal organizations will likely develop their own AI "gatekeepers" to vet targets before a human ever enters the conversation.

Furthermore, there are ethical and privacy considerations regarding the mass deployment of bots. The collection of data from scammers, while beneficial for security, requires careful handling to ensure that legitimate privacy rights are not infringed upon and that the data is shared securely among trusted partners, such as banks and social media companies.

Despite these challenges, the use of generative AI as a tool for resource depletion is proving to be one of the most innovative developments in modern cybersecurity. By flipping the script on the "automated attack," defenders are finally finding a way to scale their efforts to match the industrial proportions of global crime. For the first time, the "perfect victim" is not a person at all, but a digital ghost designed to fight back by simply refusing to hang up.

As these technologies continue to mature, the integration of AI-driven intelligence sharing between telecommunications providers, financial institutions, and law enforcement will be critical. The goal is a future where every fraudulent call or message becomes a liability for the criminal, rather than an opportunity, effectively pricing them out of the digital market.

By