Safety & Security

INTERPOL: AI Supercharges Existing Cybercrime, Not a New Threat

INTERPOL's global CISO says AI is boosting the speed and scale of existing cybercrime, and warns that agentic AI acting in the physical world poses new risks.

INTERPOL says AI is increasing the speed and scale of cyber threats. Here’s what companies should watch
INTERPOL says AI is increasing the speed and scale of cyber threats. Here’s what companies should watchAI-generated
By Sophie Lindqvist3 min read

Updated

Why it matters

  • INTERPOL global CISO Bjorn R. Watne: AI is 'an evolution and not a revolution' that increases the 'speed and scale' of existing criminal techniques
  • Watne warns agentic AI taking physical actions — including in cars and self-driving vehicles — could cause bodily harm, not just spread misinformation
  • Watne says people's trust in technology is 'through the roof' compared with the control-focused caution they apply to financial services

AI is making cybercrime faster and bigger, not fundamentally different, according to INTERPOL. Bjorn R. Watne, the agency's global chief information security officer, said the technology enhances criminal tactics that already work: scams, fraud, and social engineering at industrial scale.

"It's an evolution and not a revolution," Watne told CNBC on the sidelines of Tech Week Singapore on Thursday. AI is primarily increasing the "speed and scale" of existing techniques, he said.

The distinction matters for how companies allocate security budgets. Scam operators can now use AI to target multiple victims simultaneously. Improved machine translation and AI-generated digital identities make it harder to distinguish fraudulent interactions from genuine ones. The underlying crime is the same. The volume and polish are new.

Start with the crown jewels

Watne laid out a prioritization strategy for companies facing this shifting threat environment. First, businesses should identify their "crown jewels" — the assets most critical to keeping operations running — and determine who would want to steal or disrupt them.

Second, they should use threat intelligence to understand the tactics and technologies those specific adversaries use, then tailor defenses accordingly.

"There is no need for everyone to try and protect against everything all at once when they're not being targeted by it," Watne said. The defenses a company needs differ sharply depending on whether it faces opportunistic criminals or advanced persistent threat actors, he added.

The advice cuts against a common pattern in corporate security: spreading resources thin across every conceivable threat vector instead of concentrating on the assets and attackers that actually matter to a given organization.

The boardroom gap

Watne also flagged a persistent organizational problem: a disconnect between senior management and cybersecurity strategy at many companies.

"There are still many industries where they haven't realized that everyone today is an IT company," Watne said.

He acknowledged some progress. Cyber risk is moving higher on corporate risk registers. But cybersecurity has yet to fully make its way into the boardroom at many companies, he said, leaving security teams without the executive backing they need to act on identified risks.

Agentic AI raises the stakes

Watne said he is particularly wary of agentic AI — systems that can take actions on a user's behalf rather than just generate content. As these systems gain the ability to act, mistakes can extend beyond wrong answers to real-world harm.

"One thing is that an AI is feeding you the wrong information," Watne said. "But when an AI is actually performing an action and it starts doing the wrong actions, especially in the physical domain, that can have consequences on bodily harm of humans."

He pointed to the growing deployment of AI in cars and self-driving vehicles as a specific area of concern. The failure mode shifts from a bad answer to a bad action, with consequences that can be physical rather than informational.

Trust is the vulnerability

Watne said these risks are compounded by the unusually high level of trust people place in technology compared with other domains such as financial services.

People take a control-focused approach to financial services. They rely on safeguards like PIN codes and stay alert to card skimming and similar risks. With technology, the same caution rarely applies. Users adopt new devices and apps quickly, click through prompts, and grant access without hesitation.

"When it comes to technology, the trust level is through the roof," Watne said.

That asymmetry has security implications as AI agents gain the ability to act autonomously. A population that reflexively grants permissions to new software is a population that will extend the same default trust to systems that can transact, communicate, and operate machines on their behalf. Watne's message to companies is that this trust deserves far greater scrutiny as AI capability grows — and that the time to build that scrutiny into both products and corporate governance is before agentic systems are deployed at scale.

Source: CNBC Tech

Share this article:

More from Sophie Lindqvist

Sophie Lindqvist

Show full bio

Staff writer covering marketplaces and e-commerce at AI In Context.

160 articles

Related articles

  1. OpenAI Disrupts Cambodia-Based Scam Network That Used ChatGPT
  2. OpenAI Bans Cambodia-Based Accounts Running AI Dating Scams
  3. Microsoft Disrupts EvilTokens, AI Chatbot Platform Behind 12,000 Account Hacks
  4. Stolen AI Credentials Fuel a Booming Black Market in LLMjacking
  5. AI Could 'Supercharge' Election Disinformation in South-East Asia

« Previous article