Safety

Recognizing and Defending Against Phishing and AI-Enhanced Scams

Phishing attacks are evolving: attackers now use AI to craft fluent, convincing messages in any language, exploit QR codes and approval-notification fatigue, and assemble personal profiles from social media.

Recognizing and Defending Against Phishing and AI-Enhanced Scams

Cybercriminals increasingly use sophisticated techniques to steal credentials, including falsified emails, QR-code redirects, repeated approval-notifications (so-called “approval fatigue”), and AI-generated text and voice. The primary goal remains the same: to trick recipients into revealing passwords, banking information or other authenticators.

What to watch for in emails

  • Check the sender: the displayed name proves nothing, and addresses can include subtle character swaps (for example a capital "I" instead of a lowercase "l") that make a malicious address look legitimate at first glance.
  • Suspicious subject lines: urgent or emotionally charged subjects ("Immediate action required", "Your account will be suspended within 24 hours") are classic manipulative tactics that aim to short-circuit critical thinking.
  • Links: hover the cursor over links to see the real URL; attackers often use similar domains or shortened links (for example bit.ly). If in doubt, do not click — type the known web address manually.
  • Attachments: endpoint protection catches many malicious attachments, but a PDF can still contain embedded links that lead to harmful pages.

Newer techniques: QR codes and approval fatigue

  • QR codes: a QR code is essentially a hidden link and should be treated like any suspicious URL. Vaspöri Ferenc, head of IT security services at One Solutions IT, warns that scanning a code can lead to a fake website.
  • Approval fatigue: attackers repeatedly attempt to sign into an account, causing the victim to receive numerous approval requests. Some people eventually approve simply to stop the notifications — which grants the attacker access. Rule of thumb: never approve a sign-in you did not initiate.

The role of artificial intelligence

With large language models in common use, language mistakes are no longer a reliable indicator of fraud: AI can produce fluent, native-quality Hungarian text. Attackers can also assemble realistic, personalized messages from publicly available information.

For example, posts shared on Facebook or LinkedIn (such as a new job or a home renovation) allow an attacker to build a profile and send a convincing, bank-looking email mentioning real details. If the attacker previously gained access to the victim’s mailbox, they can send the fake message as a continuation of authentic correspondence. The deception escalates if the victim is also called: an AI-generated voice can imitate a bank representative or a relative and pressure the victim to disclose data or transfer money.

What to do when you receive a suspicious message

  • Do not click links, open attachments, or provide data in the message.
  • If the message pressures you to act immediately, verify it via a different channel (for example by phone or through the service provider’s official app).
  • If a compromise occurs: change the affected password immediately on every service where it was reused; notify your bank; enable two-factor authentication (2FA) on important accounts.

Prevention and tools

  • Use unique, strong passwords and preferably a password manager such as KeePass, Proton Pass or 1Password to avoid reuse across services.
  • Adopt a verification-first mindset: judge authenticity by the source, not by the message content; be skeptical of urgent, emotion-driven requests.

Conclusion

AI does not invent new fraud techniques but makes existing ones far more believable, personalized and effective. Attackers increasingly target people rather than systems. The best defenses remain awareness, cross-channel verification, and basic technical measures — strong unique passwords, 2FA, and password managers.

One Magyarország is a partner of the KiberPajzs program. The piece was produced on behalf of One with the cooperation of HVG BrandLab; the editorial teams of HVG hetilap and hvg.hu did not participate in creating the content.