By Interestana AI Editorial — AI-drafted, human-overseen. How we report
New AI-Powered Email Scams Bypass Traditional Defenses

Email scams have evolved significantly over the past decade, moving beyond easily detectable errors like poor grammar and broken links. Modern scams leverage artificial intelligence and advanced architectural techniques to appear legitimate, often bypassing traditional security advice such as checking for spelling mistakes or relying solely on two-factor authentication (2FA). These evolving threats require users to be aware of new tactics that are currently flooding inboxes.
One prevalent scam, termed "Quishing" or QR code mobile bypass, presents users with emails that appear to be from legitimate services like Microsoft 365 or DocuSign, indicating an urgent need to verify identity or sign a document. Instead of a clickable link, the email contains a QR code. When a user scans this code with their personal mobile device, they are directed to a malicious webpage. This tactic is particularly effective because it bypasses the security measures present on corporate networks and work laptops, directing the user to a less protected personal mobile browser. The advice for this scam is to treat any unexpected email requesting a QR code scan on a personal device for work-related credentials as a high-risk threat.
Another emerging threat is the "ClickFix" clipboard trap. This scam exploits a user's desire for productivity. After clicking on an email notification to open a document, the user is presented with a fake error pop-up on the webpage, claiming a rendering issue. The pop-up then instructs the user to press the Windows key + R, paste a provided verification code into the Windows Run prompt, and press Enter. This action does not fix a software error; instead, it tricks the user into copying malicious code onto their clipboard and manually executing it within their operating system's terminal. The critical security advice for this scam is to never paste text from a web browser into a computer's command terminal at the request of a website, as browsers are not designed to interact with system terminals in this manner.
These new scam methodologies highlight a significant shift in cybercriminal tactics, moving from brute-force, error-prone methods to sophisticated, psychologically manipulative approaches that exploit user trust and modern technological conveniences. The reliance on AI and clever work-arounds means that standard security protocols are becoming less effective, necessitating a more vigilant and informed approach from individuals and organizations alike. The continuous advancement in these deceptive practices underscores the ongoing need for updated cybersecurity awareness training and the development of more adaptive defense mechanisms to counter these evolving threats.
Original source — read the full reporting at the publisher:
Read on Fast CompanyGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.