←
AI for Government
Aware · M20 · lesson 20 of 31 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
📖
in this lesson

How AI Changes the Threat Landscape

10 min

On a Tuesday afternoon, Marcus Bell, a benefits processor at a state unemployment agency, picked up a call from someone who sounded exactly like his IT director. The voice knew the director's name, the agency's ticketing system, even a running joke about the broken third-floor printer. It asked Marcus to "reset a stuck account" by reading back a one-time security code. Marcus almost did it. What stopped him was a small detail: the real IT director never called staff directly; he always opened a ticket first. The voice on the line was not a person. It was a few seconds of the director's public conference talk, cloned by software that costs less than a monthly streaming subscription. The threat that nearly breached a government payment system was not a virus. It was a convincing imitation of a trusted colleague.

This lesson is for every government employee, not just the security team. Artificial intelligence, software that can generate convincing text, voices, and images, has not invented new categories of attack. It has made the old attacks cheap, fast, and frighteningly personal. Attacks that once required significant resources and specialized skills can now be automated. Attacks that were theoretically possible are now practical and scalable. The purpose here is not to make you paranoid. It is to make you aware, because awareness is your first defense, and to hand you a field guide you can pin next to your desk.

What Actually Changed

For years, the advice for spotting a scam was reassuringly concrete. Look for bad grammar. Watch for a generic greeting like "Dear Customer." Notice the odd email address. AI has erased most of those tells. A scam message can now be written in flawless English, addressed to you by name, referencing your actual project, in seconds, for free.

The shift is not that attacks are smarter in some mysterious way. The shift is scale and personalization at near-zero cost. An attacker who once wrote one clumsy phishing email an hour can now generate ten thousand polished, customized ones, each tuned to a specific agency, role, or current event. The economics flipped. When deceiving you becomes cheap, everyone becomes a worthwhile target, including a benefits processor in a regional office. The old advice was "look for the mistakes." AI removed the mistakes. The new advice is "verify the request, not the message."

What Is at Stake for Government

Government agencies manage sensitive information, critical systems, and public trust, and threats to those three things have distinct consequences. A breach of personal information affects citizens directly, often people who had no choice about handing their data over. Compromised systems affect public services, which means the harm lands on whoever needed the service that week. Loss of trust affects government legitimacy, which is slower to damage and far slower to repair. And attacks on democratic processes affect democracy itself, which is a category of harm no insurance policy covers.

Government also holds exactly what attackers want most: benefits payments, tax records, personal data on millions of residents, and public credibility. A single successful clone of a senior official's voice can authorize a fraudulent transfer or unlock a system. And unlike a private company, an agency cannot simply absorb a loss quietly. A breach becomes a public accountability event, a news story, and a hearing. Understanding how these threats now work is not a specialist interest. It is part of holding the job.

Deepfake Voices, Video and Images

A deepfake is synthetic media, audio, video or images, created or manipulated by AI to appear authentic. Marcus heard one. AI models can now produce convincing video of people saying things they never said and doing things they never did. "Here is video of the governor accepting a bribe," except it never happened and the footage is generated. "Here is audio of the agency director admitting to fraud," except she never said it and the voice is cloned. The raw material is often public: a recorded city council meeting, a press briefing, a webinar. Government is unusually exposed because so many officials speak on the record, in public, by design. The same transparency that builds trust also hands attackers a voice library.

The threat to an agency arrives in four shapes. Eroding trust: once a video of a leader can be faked, citizens lose their basis for knowing which videos are real, including the real ones. Impersonation: criminals impersonate officials to trick citizens or steal money, and the badge of authority does the work the technology cannot. Disinformation: fabricated media spreads false information about policies, agencies, and decisions faster than any correction travels. Blackmail: embarrassing deepfakes are created specifically to extort officials, and the extortion works whether or not anyone believes the clip.

Assume this gets easier rather than harder. Deepfakes have improved steadily and the tooling has become cheaper and more accessible; the visible artifacts that once made them obvious keep disappearing. Any personal detection skill you build is a depreciating asset, which is precisely why the defense later in this lesson is a process rather than a trained eye.

Automated, Personalized Phishing

Phishing is an attempt to trick you into revealing sensitive information, clicking a malicious link, opening a file, or handing over a credential. Traditionally these messages were sent by humans or simple scripts. They were generic, obvious and easy to spot, which is where all the old advice came from. AI changes that at three levels.

Personalized phishing. AI analyzes publicly available information about a person: social media, job title, organization, recent news. It then generates a message referencing specific details of that person's work or interests. "Hi [name], I noticed your recent work on [project] in [article]. I have similar interests and wanted to share [malicious link]." That is far more effective than generic phishing because it is targeted and credible, and every detail in it is genuinely true. Imagine the version tuned to your agency's actual grant deadline, in your supervisor's writing style, arriving the morning the deadline hits. The pressure feels real because the details are real, scraped from public budgets, press releases, and staff directories.

Spear phishing at scale. Spear phishing means phishing aimed at a specific individual or organization. It used to be expensive, so it was reserved for high-value targets. AI can now generate thousands of personalized messages simultaneously, which means an attacker can send individually targeted phishing to every employee at an agency in one pass. The economics that once protected ordinary staff no longer protect anyone.

Voice and video phishing. The same techniques arrive by phone and video call. Imagine a call from someone who sounds exactly like your supervisor asking you to transfer funds or send passwords. That is Marcus's Tuesday, and the only thing unusual about it is that he happened to have a rule that saved him.

Social Engineering at Scale

Social engineering means manipulating a person, rather than a computer, into revealing information or taking an action that breaks security rules. It targets your courtesy and your wish to be helpful, two qualities public servants are selected and trained for. AI supercharges it in three ways that are worth naming separately, because they look nothing alike from the inside.

Chatbot impersonation. An attacker runs an AI chatbot posing as a government agency or a trusted organization, builds rapport with a victim over a series of exchanges, and only then asks for sensitive information or system access. The request arrives late, after trust has been established, which is exactly when scrutiny is lowest.

Sentiment analysis and targeting. AI can analyze individuals' online behavior and tone at scale to identify who is angry, frustrated, or otherwise more open to manipulation, and then aim messages designed to move that person specifically. Vulnerability becomes a searchable attribute rather than something an attacker has to discover by hand.

Automated relationship building. AI can sustain months-long conversations with a target, building trust gradually, before making any request at all. By the time the ask arrives, the relationship feels established and long-standing, and nothing about the request feels like a first contact from a stranger, because it is not one.

Speed and Scale of Everything Else

AI also writes malicious code faster, translates scams into any language instantly, and probes systems around the clock without getting tired or bored. The practical effect for a frontline employee is simple. Assume the volume and the quality of deception aimed at your inbox and your phone has gone up, and will keep going up. That is not a reason to freeze. It is a reason to stop relying on personal detection and start relying on process, which is the subject of the rest of this lesson.

The Defense That Still Works

Here is the reassuring part, stated precisely. AI changed the attacks, but it did not change the defense that defeats the impersonation attacks in this lesson: verify the request through a separate, trusted channel. Marcus was saved not by spotting a fake voice, which is now genuinely hard, but by an agency norm: the IT director never calls directly. The process caught what the human ear could not.

The principle is to stop trusting the channel and start verifying the request. If a "colleague" calls asking for a code, hang up and call them back on a number you obtained yourself from the official directory. If an "urgent" email demands you click or pay now, contact the sender a different way, using contact details that did not come from the message. Attackers rely on urgency and a single channel. Break either one and most of these attacks collapse.

Be clear about the limits, because a defense you overestimate is a defense you eventually skip. Out-of-band verification answers one question: is this request really coming from the person it claims to come from? It does nothing about a malicious attachment you have already opened, a link you have already clicked, or an attacker who is already inside a legitimate account and can therefore answer your callback. It is not a substitute for your agency's technical controls, and an agency norm is only protective while people know it and follow it. Marcus was protected by a rule that was in his head on a Tuesday afternoon, not by a system that would have stopped him.

Field Guide: The AI-Era Verification Checklist

Print this. Keep it where you answer the phone and read email. It turns the abstract threat into five concrete habits.

  1. Did the request create urgency? "Right now," "before end of day," "don't tell anyone yet." Urgency is the most common pressure lever, and a request for secrecy belongs in the same category. Treat it as a yellow flag, not a reason to comply.
  2. Does it ask for money, credentials, codes, or sensitive data? These are the four prizes attackers want. Any request touching them earns automatic verification, no matter who it seems to be from, including people senior to you and including people you spoke with yesterday.
  3. Can I verify through a different, known channel? Call back on a number from the official directory. Walk to their desk. Open a ticket. Never verify a suspicious call using a number the caller gave you, and never use contact details supplied inside the suspicious message itself, including a signature block that looks correct.
  4. Is the channel itself the proof? A real voice, a real-looking email, a real-seeming video are no longer proof of anything. Identity must be confirmed by process, not by how convincing the contact felt. That applies to media presented as evidence too: an audio clip of an official is not a record of what the official said.
  5. If unsure, slow down and report. Pausing a real request by ten minutes costs almost nothing. Acting on a fake one can cost a breach. When in doubt, report it to security; a false alarm is a good outcome. And if you have already complied, report it immediately anyway. Reporting fast is what limits the damage, and a delayed report is far more costly to your agency than an embarrassing one.

Worked Example: The Email From IT

You receive an email that appears to come from your agency's IT department: "Hi [your name], we've detected unusual activity on your account. Please click here to verify your password: [link]." It looks official. Is it real?

Here is what you can check from the message itself. Look at the sending address and compare it to the official IT address, character by character; even a slightly misspelled domain is a reason to stop. Hover over the link without clicking and read the actual destination, which may not be your agency's domain at all. These checks catch sloppy attempts, and they are worth the few seconds they take. Understand what they cannot tell you: a display name is trivially forged, a lookalike domain can be misspelled in a place your eye skips, and a message that passes both checks has proved nothing. Passing a surface check is not evidence of legitimacy. It only means the attacker was not careless.

So do the check that actually settles it. Call IT directly, using a number you know is correct and did not get from the email, and ask whether they sent it. That is the step that survives a well-made fake. And apply the standing rule that makes the whole question easier: treat any message asking you to supply or confirm a password through a link as illegitimate. Legitimate IT departments do not ask for passwords through emailed links, so a request of that shape does not need to be investigated before it is refused. Refuse it first, report it, and let IT tell you afterward if something genuinely needed doing.

The Mental Shift

You do not need to become a cybersecurity expert. You need to internalize one change of question. The old question was "Does this message look legitimate?" and AI has retired it, because AI makes almost anything look legitimate. The new question is "Have I verified this request through a channel the attacker cannot control?" Marcus asked that question by reflex, backed by a simple agency rule, and that is why a cloned voice with a printer joke did not get a one-time code out of him. That reflex is now part of every public servant's job.

Anti-Patterns to Avoid

  • Assuming official media is authentic. You see a video of a government official and take it as real. The risk is that it is a deepfake and you make decisions, or spread information, on the strength of fabricated media. This cuts both ways: authentic footage can also be dismissed as fake, which is its own attack.
  • Trusting links or attachments from unexpected sources. An email arrives from what appears to be a colleague or an official with something to open. The risk is AI-generated phishing, a click, and a compromised system, and the compromise does not announce itself.
  • Believing voice or video without verification. A caller sounds like your supervisor and asks for something unusual. The risk is voice cloning or a deepfake, and you act on false authority. Familiarity of the voice is not authentication.
  • Oversharing on social media. You post details about your work, interests, location, and relationships. The risk is that attackers use exactly those details to craft highly personalized phishing and social engineering. Every public detail is free raw material.
  • Treating surface checks as clearance. The sender address looked right, the greeting used your real name, the grammar was clean, so the message must be genuine. None of those establish anything. They rule out a careless attacker, and AI made careless attackers rare.
  • Verifying through the channel that contacted you. Replying to the email, calling the number in the signature, or asking the caller to confirm their identity. Every one of those routes runs through infrastructure the attacker controls. The whole value of out-of-band verification is that you chose the channel.
  • Staying quiet after you complied. You read out the code, clicked the link, or sent the file, and now you are hoping it was nothing. That silence is the most expensive part of the incident. Report it immediately; the earlier the report, the more chance a response can still contain it.

Practice Prompts

  • Find the official directory number for your IT service desk and save it somewhere you can reach without opening email. That is your out-of-band channel, and it needs to exist before you need it.
  • Take the last suspicious message you received and write out which checks were surface checks and which would actually have settled the question.
  • Write down the rule your team would follow if a senior official called you directly with an urgent, unusual request. If no such rule exists, that is the finding.
  • Look at your own public footprint: job title, projects, colleagues, recent posts. Draft the phishing message an attacker could write from it, and notice how little of it they would have to invent.

Reflection

  • Have you noticed an increase in phishing attempts or suspicious communications? What made them suspicious, and would that tell still work today?
  • In your agency, what critical systems or information would be most valuable to an attacker, and what do you personally have access to?
  • How would you verify that a communication claiming to come from a senior official was actually authentic?
  • What would happen if information you can reach were stolen, or if an attacker impersonated you or your agency? What is one action you could take this week to reduce that risk?

Glossary

  • Deepfake: Synthetic media, audio, video or images, created or manipulated by AI to appear authentic.
  • Phishing: Attempting to trick someone into revealing sensitive information by posing as a trustworthy entity.
  • Spear Phishing: Targeted phishing directed at a specific individual or organization.
  • Social Engineering: Manipulating people into revealing information or taking actions, rather than attacking a computer directly.
  • Voice Cloning: Using AI to create synthetic audio that mimics someone's voice.
  • Out-of-band verification: Confirming a request through a channel you selected yourself, using contact details the requester did not supply.

Closing

The threat landscape has changed because AI has made attacks easier, cheaper and more effective, and the tells that used to protect you are gone. Awareness is your first defense, not your last one: it works because it changes what you do, which is to be skeptical, to verify through a channel you chose, and to refuse to assume that media or communications are authentic without checking. Marcus nearly handed a security code to a piece of software. What stopped him was not a sharp ear. It was a rule, and rules are something an agency can give every one of its people.

Key Takeaways

  • AI didn't invent new attacks; it made old ones cheap and personal. Attacks that once needed resources and specialist skill are now automated, so every employee is a worthwhile target.
  • The old tells are gone. Bad grammar, generic greetings, and odd phrasing no longer reliably mark a scam; AI writes fluently and references real details about you.
  • Voices and faces are no longer proof. Deepfakes can clone any official who has spoken in public, and government officials speak in public constantly. Detection by ear or eye is a depreciating skill.
  • Social engineering now runs at scale. Chatbot impersonation, targeting of people who seem vulnerable, and months-long automated relationship building all arrive before any request does.
  • Verify the request, not the message. Confirm any sensitive ask through a separate channel you chose, never the one the contact came in on and never a number the caller supplied.
  • Surface checks are not clearance. A clean sender address and a personalized greeting rule out a careless attacker and prove nothing else.
  • Process beats perception, and process has limits. Clear verification rules catch what humans now cannot detect, but a norm only protects while it is known and followed, and out-of-band checks do nothing about a link already clicked.
  • Never supply credentials through a link. Treat any emailed request to enter or confirm a password as illegitimate and report it rather than investigating it.
  • When unsure, report; when you already complied, report faster. A false alarm costs minutes. An unreported compromise of a government system costs far more, and the earlier it is reported the more chance it can still be contained.

Frequently Asked Questions

How can I tell a cloned voice from the real person? Increasingly, you cannot, and building that skill is not the answer. A few seconds of public audio is enough raw material, and government officials speak publicly by design. Move the question from "does this sound right?" to "have I confirmed this through a channel the caller does not control?"

The email address and greeting both looked correct. Is that enough? No. Display names are trivially forged and a lookalike domain can differ by one character in a place your eye skips. Those checks catch careless attackers. They provide no evidence at all that a message is genuine.

My supervisor called and asked me to move a payment urgently. What do I do? Verify out of band before acting, regardless of seniority. Money, credentials, codes and sensitive data are the four categories that earn automatic verification. Call back on a directory number you looked up yourself, or walk to their desk. A genuine supervisor will not be offended by a rule.

Is out-of-band verification enough on its own? It defeats impersonation, which is the core of these attacks, and it is the single highest-value habit in this lesson. It does not undo a clicked link, a downloaded attachment, or an attacker operating from inside a real account. It sits alongside your agency's technical controls rather than replacing them.

I already gave out a code. Is it too late to say something? No, and the report matters more now than it would have before. Tell security immediately. The sooner security knows, the more of the response is still available, and the cost of a delayed report is always higher than the discomfort of making it.

Does any of this apply to what I post outside work? Yes. Details about your work, projects, location and relationships are the raw material for personalized phishing and for the long, patient relationship-building attacks. What you publish publicly is what an attacker gets for free.