AI-powered phishing scams: seven schemes you need to know
AI-generated phishing emails are becoming almost indistinguishable from legitimate messages, and attackers use new tricks like OAuth device code flows to bypass MFA and QR codes to hide links. The piece outlines seven current scams—Microsoft 365 login theft, support scams, fake Defender warnings, cloud/OneDrive phishing, parcel-delivery impersonations, online-banking fraud, and Postident fraud by post—and provides practical defenses: verify via official sites, enable MFA, use a password manager, avoid clicking links or scanning unknown QR codes, and resist unsolicited remote-support requests.
