Introduction
It’s been over nine years since my last post about how to stay secure online. A lot has changed since then, particularly with Artificial Intelligence making everybody more effective at everything. (At least, this is what Corporate America is telling itself, and in the case of fraudsters, it’s actually true.) In this post I’ll briefly highlight some of the most pressing AI-driven threats, and then focus on what you can actually do to protect yourself, vs. what we’ll have to hope “they” can protect us from. Short version: be extra wary of phishing and spear-phishing attacks. (Oh, and no point in panicking … yet … as far as I know. I put “panic” in the title of this post just to grab your attention—and look, it worked!)
The top four AI-driven security threats
Here are some of the top Internet security threats presented by AI:
- Autonomous attacks: Fraudsters are using agentic AI to unleash fully automatic phishing and other attacks, greatly speeding up their campaigns.
- AI systems as attack surface: As companies build AI into email, documents, and workflows, attackers are targeting the AI stack directly rather than going around it. (Some call this “AI supply chain compromise.”) Malicious instructions can be hidden inside the content that an AI reads as it goes about its job, and training data can be poisoned.
- Deepfake-driven identity collapse: AI can produce realistic voice, face, video, and document forgeries cheaply and at scale. This can undermine authentication systems across corporate, banking, and consumer platforms.
- Data leakage from ordinary use: As corporate employees use AI normally, and get very specific in providing context for their prompts, they often share more info than they mean to, giving bad actors access to sensitive data without even having to steal it.
(Why four threats, instead of a nice round number like three or five? I based my assessment on queries I made to ChatGPT, Gemini, Copilot, and Claude, and these are the four top threats that all these models agreed on.)
On top of these threats, and overlaying them, is Open Source Intelligence (OSINT), which in the context of Internet security refers to personally identifiable information (PII) that over time has become public due to voluntary posting of it, such as on social media (e.g., Facebook users sharing info about themselves, their activities, and their families, assuming it’s only seen by friends and online “friends” and not realizing how easily shareable it is across the entire Internet). All this data has been increasingly well indexed by Google and other Internet tools, and now web scrapers and other generative AI tools can easily harness this sensitive data to create targeted phishing (i.e., spear-phishing) attacks.
An example of an OSINT hack
This will all make more sense, I think, if I provide an example. It occurred to me recently that anyone with a Gmail account could create a Gemini Notebook into which they could feed large batches of albertnet posts, to turn this very blog into a chatbot. They then could query this chatbot for any and all PII that could be used to answer security questions when trying to impersonate me. To identify such vulnerabilities, I did this exact exercise myself (employing a tactic called Defensive OSINT—basically beating hackers to the punch). I fed the most likely categories of albertnet posts (e.g., Parenting, Bits & Bobs) into a Notebook and asked the chatbot to build a comprehensive “public knowledge index” of PII based on the categories most often used for website authentication security questions. Then I had it produce a report describing the vulnerabilities it found.
Did it come up with anything? Well, yes: it found one item of rather sensitive information based on a bit of handwritten text that was included on a picture that was posted. I found that pretty embarrassing, but it was easy enough to remove since this is my blog and I manage the content directly. (Also, because I own the domain used by my blog, I can go to web.archive.org and have the original version of the post removed forever.) Fortunately, I’ve had an eye on privacy and security for the whole time I’ve been blogging, so other than some pet names and schools I attended, I’m overall in pretty good shape. Here’s a particularly amusing excerpt from the Gemini Notebook security audit report:
Category V: Workplace & Career
The author’s career trajectory is extensively documented, providing a roadmap for Business Email Compromise (BEC) and “Career Gate” attacks.
- Specialist: Identified in the Blogger Profile metadata as the current occupation.
- Professional Trajectory:
- Artillery Regiment (1985–1988)
- Bike Mechanic / Radio Station Receptionist (Late 1980s)
- Underwear Canner
- Office Worker (Trained)
- Staff Writer / Syndicated Columnist
- Company Man (Current status)
Security Risk Assessment: Attacker groups scrape metadata from Blogger sidebars (e.g., the “Specialist” title) to craft highly targeted BEC lures. By referencing past roles like “underwear canner” or “radio station receptionist,” an attacker can establishing [sic] a false commonality to bypass corporate security screenings or impersonate a former HR representative for the purpose of credential harvesting.
As you can see, when you share personal information on the Internet, it’s highly advisable to bullshit a lot. I have a feeling that the above career information, even in the hands of the most devious hacker, isn’t going to get me in a lot of trouble. I do need to warn family members not to use any of the PII in my report (e.g., a pet’s name, a school name) as security answers, though I’ve already cautioned them—as I’ll now caution you—to not use real PII for security questions in any case; after all, you can’t change your mother’s maiden name or the city you were born in, so once somebody hacks a website and gains these answers, you’re pretty much hosed. And good luck remembering what security questions and answers you’ve set up over the years across all the sites that use them for authentication.
So can everyone run this kind of audit? Well, any blogger can, but if you’ve been active on multiple social media platforms over the last ten or fifteen years, it’s gonna be really tough. And remember, in many cases (e.g., Facebook) you do not actually own that information. Probably the best thing you can do is keep an eye out for spear-phishing attacks.
Some updated anti-phishing basics
In my previous post on phishing, I pointed out that you could often spot fraud based on bad spelling or grammar (e.g., “Security fraud alerted corporate card!” or “Account info updating needs!”). This is no longer a reliable rule of thumb, because AI has gotten so good at grammar and even at matching the style of the supposed sender. It’s more likely to produce a realistic subject line as well (as opposed to something generic like “Hello”) and isn’t so prone to excess emoticons, weird fonts, and/or tacked-on numbers (e.g., “✅ 𝙋𝙡𝙚𝙖𝙨𝙚 𝙘𝙤𝙣𝙛𝙞𝙧𝙢 if you're qualified for a compensation✅ 5078227).” My previous advice still stands: don’t click on any link in an email unless you completely trust the sender, and have hovered your cursor over the link to make sure the domain matches what you’d expect based on what your contact purports to be sending you.
For example, if a cycling buddy sends you an email that says, “You’ve got to check out this Tour de France blow-by-blow report from albertnet,” and the link says “Tour de France Stage 15,” and you hover over the link and see the URL “https://www.albertnet.us/2026/07/biased-blow-by-blow-2026-tour-de-france.html, ” that would be safe. But if you get an email from $CashApp$ (nxaqlvxcvm@ekgkx1ylmv.co.us via arbeitsstellepro.com) with the same message (or any message, actually), you shouldn’t click on any link in it. Or, let’s say you get the same aforementioned Tour de France email from a trusted pal, but hover over the included link and see “https://www.xtremecloudmontzer.xyz/encryptvictimHD” … you obviously shouldn’t click it. Now let’s say you got a legit albertnet link to the Tour de France post, but from a friend who constantly bags on my blog and/or on the Tour de France. Valid-looking URL aside, you might reasonably decide the message fails the sanity test, and you should send a separate email to that friend asking, “Did you really send me a link to an albertnet post?”
Always be especially careful with any email that conveys a sense of urgency and wants you to take immediate action. Fraudsters will employ that to try to get you to bypass your normal habit of being careful and deliberate with your email. It isn’t always the foreboding kind of urgent; it could alternatively be the upbeat kind of urgent, like a party invitation, which gets us excited because hey, fun, party!
Anatomy of a spear-phishing attack
A friend of mine fell prey to a spear-phishing attack recently because an email she received was from a friend who’d been on a volunteer board of directors with her, who quite reasonably could be hosting a reunion. The email looked like a standard punchbowl.com invite, with the right logo, etc. My friend, due to a momentary lapse of reason, clicked the link without hovering over it. If she had bothered to hover, she’d have seen this (click to enlarge):
Since my friend doesn’t use Outlook, she wouldn’t have been falsely comforted by the “Protected by Outlook” indication and in fact would have found it suspicious—had she hovered over and seen it! Meanwhile, even if the fraudster had lucked out and my friend were on Outlook, she would have been wise to suspect the “roves.sbs” because a) it isn’t the punchbowl.com domain, b) it isn’t anything recognizable, and c) that .sbs top-level domain is automatically suspicious because that’s an extremely cheap domain, perfect for hackers. (They love a cheap domain they can set up to snare as many victims as possible before the fraudulent site is identified and flagged by security community filters like Google Safe Browsing or Norton.) On top of all this, the URL shown above isn’t even itself the real URL—it’s a bogus tooltip set up by the hackers. You need to look in the lower left of your browser screen to see the real URL, which in this case was “accounts.lifeofastartryfghjgd.icu,” which a) also isn’t the punchbowl.com domain, b) also isn’t recognizable, c) looks like somebody started to type something plausible but lost patience, and d) has another disposable, cheap, very phishy landing page domain. Alas, my friend missed all of this, delighted as she was to be invited by a friend to a party, and just clicked the link.
From here, things went even more sideways. First, she was presented with a CAPTCHA she had to solve to prove she was human. This was employed by the attacker for three reasons:
- It stymied her security software, hiding the phishing page and thereby preventing the software from blocking it;
- It established a sense of trust, because users associate CAPTCHA screens with security (i.e., it made my friend think the site was establishing that a bot wasn’t trying to accept the invitation);
- It confirmed to the attackers that a real human—i.e., a dupe—had actively taken the bait, and they probably added my friend to a list of suckers who should be actively phished again in the future.
Then, the page went in for the kill, saying that to accept the invitation and add it to her calendar, my friend should log in to her Google account. It helpfully provided the input fields to do so. Only at this point did my friend smell a rat, and closed the page instead of serving up her Gmail address and password to the hackers. Probably there was no harm done, but man, what a close call! (It’s possible the site could have meanwhile instigated a “drive-by” malware download, but this probably wouldn’t have worked without her browser asking her to explicitly approve a file download or browser extension installation.)
As you can see, phishing has gotten more sophisticated. And the worst part of the phishing email my friend received was that it did come from a known person, and (whether through luck or knowledge of the person’s work experience) created a plausible scenario: this was exactly the kind of invitation my friend would expect to receive from this person. This is one of the ways spear phishing attacks are engineered.
Incidentally, my friend contacted the sender, and sure enough, this person’s PC had been compromised and the attack mounted against everyone in her address book. Why she hadn’t warned anyone is a mystery to me, and I hereby implore you to let all your contacts know if your system ever gets hacked. It’s no different than the responsibility a sexually promiscuous person has to notify his or her paramours about testing positive for a venereal disease. (For a charming comedy series on this theme, you might check out “Lovesick” on Netflix.)
AI and spear-phishing
Getting back to AI, it changes the game by making phishing attacks more realistic than ever, and at a lower cost to hackers. In the past, spear phishing was time- and labor-intensive, and thus reserved for people who are (no offense) bigger targets than you. But now, with AI, producing a bespoke attack with maximum plausibility has gotten easy, fast, and cheap. Gemini describes it thus:
Traditionally, gathering intelligence on a target required significant manual effort. If an attacker wanted to map out a corporate hierarchy, scrape executive social media, identify software stacks, or build custom spear-phishing personas, it took days or weeks of painstaking human research.
AI-driven OSINT compresses that timeline from weeks to seconds:
- Automated Harvesters: AI tools can scrape public records, forum posts, code repositories, blog archives, and dark web dumps simultaneously.
- Instant Synthesis: LLMs [large language models] parse millions of lines of unstructured text, connect disconnected data points across 15 different platforms, and output a clean, actionable “target profile” with zero fatigue.
This means that instead of a person employing just a few methods to get the target to let his or her guard down (e.g., crafting a realistic-looking, well-written email seemingly from a friend who might plausibly have written it), AI can generate a hyper-personalized attack, presenting specific contextual details designed to boost the sense of authenticity, with a high likelihood of dissolving the recipient’s natural defenses of skepticism and caution.
Imagine if my blog were less slippery, and the career info I posted were actually relevant and factual. I could get an email from someone purporting to have served with me in the Artillery Regiment in the late ‘80s, who has announced he’s become very successful in the underwear canning business; understands my frustration with modern corporate America; and would like to talk to me about an executive position at his startup with great pay, a signing bonus, and stock options—and all I have to do is go to this website and upload my CV! The specificity of this email might dupe me, if I actually had served in the same Artillery Regiment, and if canning underwear had been a bigger part of my career. And imagine if the fraudster spoofed the identity of a guy I actually knew (“it’s your old pal Fred, from the Hot Chillys cannery!”) … the email would seem pretty legit. Somebody harvesting LinkedIn PII instead of albertnet might actually get somewhere.
The ABC mnemonic
To protect yourself from spear-phishing attacks, I recommend borrowing a concept from police detective training: the investigative doctrine of “ABC.” Across the UK and Commonwealth, detective trainees are taught to “Assume nothing; Believe nothing; Check everything.” Adapting this for Internet security:
- Don’t assume an email is safe, just because it has proper formatting and logos, good grammar and spelling, etc.
- Don’t believe an email is really an intentional communication from your friend, even when the source email address checks out, if there’s anything even slightly phishy about it
- Check for any sign that the email could be fraudulent.
Here are things to watch for in that third “check everything” step:
- The email has a mismatched “From” vs. “Reply-To” address (e.g., purports to be from Bank of America but the reply-to address has a phishy domain like banksupport@bank.sbs)
- It includes a link it wants you to click, especially from an unusual top-level domain (basically anything other than .com, .gov, .edu, or .us and especially the johnny-come-lately TLDs like .xyz and .biz or anything you don’t recognize—always remember to hover over a link before clicking it)
- It includes a link with a shortened URL like bit.ly (which can be used to hide a phishy domain)
- It has a file attachment, especially something besides a PDF or JPG
- It conveys a sense of urgency (especially from a bank or other business telling you they’re going to have to block your account, or already have, or will have to close it unless action is taken such as updating your payment details, etc.)
- Is from a business but has emoticons in the subject line (I mean, really?!)
Is albertnet safe?
Yes, albertnet is perfectly safe. This website doesn’t run any scripts; doesn’t employ cookies or tracking pixels or Google Analytics; won’t try to install anything; and never includes links to unsafe websites. I won’t serve you ads, don’t want your money, and respect your privacy. About the only risk you’ll run is believing I served in an artillery regiment, or that Strava has a new nighttime KOM category, or that the Tour of Sweden was held in 2020 at the height of the COVID-19 pandemic. And at least when I bullshit you I always fess up.
—~—~—~—~—~—~—~—~—
Email me here.
For a complete index of albertnet posts, click here.





















































