New routine exploits make cybercrime more convincing and costly

Cybercriminals are shifting tactics from system breaches to exploiting human behaviour, with threats like OTP theft, SIM swaps, and AI-driven voice impersonation becoming more sophisticated and damaging, prompting calls for heightened vigilance and improved security practices.

Cybercrime is evolving quickly, and the latest wave of fraud is built less on breaking systems than on exploiting routine behaviour. According to ABP Live, the most common tactics now include one-time password theft, SIM swap fraud and artificial-intelligence-powered voice impersonation. All three depend on one weakness: people are still more likely to trust a call, a text or a familiar-sounding voice than they are to suspect a scam.

One-time passwords remain a prime target because they are often treated as a quick security check rather than a key to an account. Scammers pose as banks, courier services, shopping platforms or government offices and create enough urgency to persuade victims to read back the code sent to their phone. Once that happens, criminals can approve payments or take over accounts. Security guidance from the American Bankers Association and Kaspersky says the safest approach is to treat every OTP as private and to use app-based authentication where possible rather than SMS codes.

SIM swap fraud is more disruptive still. In these attacks, criminals gather enough personal information to persuade a mobile carrier to transfer a number to a SIM card they control. When that succeeds, the victim can suddenly lose service while texts, calls and verification codes start arriving on the attacker’s device instead. LegalClarity says the FBI received more than 1,600 SIM swap complaints in 2021, with reported losses exceeding $68 million, underlining how costly the crime can be. Warning signs include unexplained loss of signal, account lockouts and unusual login alerts.

The newest threat is deepfake voice fraud, which uses artificial intelligence to clone a real person’s speech from short clips gathered online. U.S. Bank says this kind of vishing, or voice phishing, can be used to impersonate a senior executive, colleague or relative and pressure the target into moving money or sharing sensitive information. The danger is that the request may sound authentic even when it is not. A callback to a known number, or verification through a separate channel, remains one of the most effective defences.

Experts say prevention comes down to disciplined habits: never disclose an OTP, watch for sudden network failures, add extra verification for financial requests, and move away from text-based authentication where possible. Kaspersky and other security specialists also advise setting carrier-level account protections, limiting personal details shared on social media and warning children and older relatives, who are frequent targets. For businesses, regular staff training is essential because one convincing call can still open the door to a serious breach.

Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.