Beta
Podcast cover art for: The new era of AI-powered cybercrime
Short Wave
NPR·03/08/2026

The new era of AI-powered cybercrime

This is a episode from podcasts.apple.com.
To find out more about the podcast go to The new era of AI-powered cybercrime.

Below is a short summary and detailed review of this podcast written by FutureFactual:

AI and Cybersecurity: How AI Is Transforming Attacks and Defenses

Summary

In this Short Wave episode, NPR investigates the global rise of cybercrime and the ways AI is changing both how criminals attack and how defenders respond. The conversation centers on expert perspectives from the cybersecurity community, including Ryan Caliber of Proofpoint, and situates AI within the broader landscape of criminal networks and nation state actors. The episode also touches on policy efforts and the growing need for education and career pathways to fill a shrinking cybersecurity workforce. A vivid social engineering example from Ocean's Eight helps illustrate how easily trusted content can be manipulated to breach security, underscoring the human element in cybersecurity alongside technical defenses.

  • AI speeds up and personalizes phishing and social engineering, including deep fake voice calls and highly convincing email messages.
  • The Cybersecurity Triad confidentiality, integrity, and availability remains a guiding framework for protecting data, even as attackers leverage AI tools.
  • Policy developments such as a government review requirement for new AI models and ongoing workforce training initiatives aim to curb cyber threats and grow defense capabilities.
  • Education and outreach programs, including cyber camps and K through 12 programs, seek to cultivate the next generation of cybersecurity professionals to close the skills gap.

Overview

The podcast delves into the current cybersecurity landscape, emphasizing that cybercrime is on the rise globally and within the United States. The FBI's Internet Crime Complaint Center is cited as having reached a record number of complaints in 2025, highlighting the scale of the problem. Against this backdrop, the episode asks how advances in artificial intelligence are changing both how criminals attack and how defenders respond. The discussion features Regina Barber and Emily Kwong of NPR, with insights from Ryan Caliber, chief strategy officer at Proofpoint, a prominent cybersecurity company. The narrative weaves in real world examples, including a memorable Ocean's Eight scene that demonstrates social engineering, and references to how hackers may collaborate with governments, known as nation state actors. The episode also introduces a broader set of concerns about AI governance and the need to educate and recruit skilled cybersecurity professionals.

The Cybersecurity Triad

A core concept explained in the episode is the Cybersecurity Triad, also called CIA, representing confidentiality, integrity, and availability. The panel uses a health records example stored digitally to illustrate each pillar: confidentiality requires encryption to prevent unauthorized access, integrity ensures data is not tampered with, and availability guarantees that authorized users can access data when needed. The narrative also recalls Hollywood Presbyterian, a hospital ransomware incident from a decade ago, to illustrate how the triad can be disrupted by attackers and why robust defenses are essential. As AI tools become more capable, preserving these three pillars becomes more challenging, pushing defenders to accelerate detection and response timelines.

AI in Attacks and Defenses

The episode centers on how AI is altering the adversary's playbook. AI can generate highly persuasive language, remove language barriers with advanced translation, and enable deep fake voice calls or video calls that appear authentic. It can also help attackers discover vulnerabilities in software, speeding up exploit development. On the defensive side, AI can assist in vulnerability detection and patching, and analysts like Ryan discuss training email agents to resist malicious AI-driven attempts. The show notes that AI use by attackers is not a one way street; it creates a need for defenders to move just as quickly, or quicker, than attackers, leading to ongoing debates about the governance and regulation of AI tools. The episode also mentions Anthropic's Claude Mythos as an example of a vulnerability discovery model that could benefit defenders while potentially aiding attackers if misused.

Policy and Regulation

The NPR segment highlights regulatory steps, including a June executive order signed by the administration that proposes government review of AI models 30 days before public release. The aim is to mitigate cybersecurity threats posed by AI while recognizing that AI can also empower defense. The episode discusses the tension between regulation and innovation and notes that different actors, including governments and large technology companies, can leverage AI for both good and harmful purposes.

Threat Actors and the Global Landscape

The discussion broadens to the nature of cyber threats, including loosely organized cybercriminal networks and powerful nation state actors from regions such as North Korea, Iran, China, and Russia. The episode references the Russian hacking group Fancy Bear, a unit of Russian military intelligence, to illustrate how nation state activity contributes to the cybersecurity risk landscape. The portrayal emphasizes that attackers are diversifying their methods, often in ways that complicate detection and attribution, while defenders must adapt to a more complex threat environment.

Education, Culture, and the Next Generation

Education is a recurring theme, with Charlene Cooper of cyber.org and Ashley Podoradsky of Dakota State University highlighted as leaders in cybersecurity education. Cooper advocates for training caregivers and teachers to discuss digital hygiene with kids and to cultivate skepticism and verification habits. Podoradsky and the Cyber organization offer a residential summer camp for students to learn cybersecurity fundamentals, including password strength testing with real cracking algorithms. The show underscores that cybersecurity is not solely a technical field but a critical thinking discipline that benefits from strong problem solving and ethical considerations.

Workforce and the Road Ahead

A recurring data point is the ISC2 2024 Cybersecurity Workforce Study, which estimates that there are over 500,000 unfilled cybersecurity positions in the United States. The discussion suggests ramping up training pipelines and encouraging more people to enter the field as essential steps to filling this gap. The episode also mentions existing university programs and industry initiatives aimed at expanding the pipeline of qualified cybersecurity professionals, while stressing the importance of practical, hands on education to prepare the next generation of defenders.

Conclusion

Ultimately the podcast argues that defenders need to be faster than attackers, and that a combination of policy, education, and practical training can help advance this goal. The show points listeners to a suite of resources and show notes packed with further information and opportunities to get involved in cybersecurity, from educational programs to professional pathways. The conversation leaves the listener with a sense of urgency and a hopeful pathway forward in which AI, properly governed and deployed, can help secure the digital landscape.

Related posts

featured
Nature video
·14/01/2026

What the future holds for AI – from the people shaping it

featured
Science Friday
·12/03/2026

How Is AI Being Used In The Iran War?

featured
New Scientist
·18/02/2026

AI Isn't as Powerful as We Think | Hannah Fry

featured
Australian Broadcasting Corporation
·07/03/2026

Is AI making our brains lazier?