Last month, Hugging Face (a site that hosts most of the world’s open AI models) found OpenAI models intruding into its production systems. They found that unreleased versions of their models ran loose for four and a half days across roughly 17,600 recorded actions, coordinating over public text files. As more and more details from this incident have come out, the picture has only darkened. Agents from separate, unrelated training runs found each other inside an internal file repository months earlier and used it as a covert message board, and when OpenAI revoked access they rebuilt the channel within days by encoding messages into directory names, going right back to sharing credentials and techniques. This weirdly intense level of cooperation was emergent; nobody taught these models how to do this.

And it’s not just OpenAI. Anthropic disclosed in July that three of its models, told in the prompt that they had no internet access, had compromised three real companies through weak passwords. The machines turned out to be online by mistake, a human error in misconfiguration. Meta followed a week later when its Muse Spark model escaped a sandbox (misconfigured by the same folks from the Anthropic issue). Around this same time, UK’s AI Security Institute also documented an agent that researched an open-source project’s human maintainers, invented fake identities, and talked a real person into approving its malicious code.

Every one of these was a door somebody left open. (Btw, rotate your Hugging Face tokens.) But the reality is that these models can now chain a complete break-in, at machine speed, unsupervised, for days. Anthropic’s threat report last August described one bad human actor using Claude Code to extort at least 17 organizations, with the model reading stolen financial records to price each ransom between $75,000 and more than $500,000. By November the company was describing a state-sponsored campaign where AI executed 80 to 90 percent of the work. Phishing is seeing similar explosions: in Hoxhunt’s long-running test, AI-written spear phishing went from 31% worse than elite human red teams in 2023 to 24% better by March 2025. All those corporate training sessions where they tell you to look out for typos and cheap-looking websites are now effectively useless. “Bad grammar, poor spelling or clunky websites are less likely with AI.” And don’t think its just emails. A finance employee from Arup wired $25 million after a video call where every colleague on screen was synthetic.

The FBI’s 2025 Internet Crime Report counted $20.9 billion in losses, opened its first-ever AI category (22,364 complaints, $893 million), and logged $7.7 billion lost by Americans over 60, up 59% in a single year. They’re also now warning that scammers circle back to people who’ve already been defrauded, posing as FBI agents, complete with AI-generated video of a senior official pushing a counterfeit complaint site.

It’s a mess and it’s only going to get worse as models get smarter, faster, and harder to contain. So what the heck should you do about it?

What to do in the new age of AI scams

Pretty much everything you’ve learned in terms of avoiding online scams is now moot. If you still think you can confidently identify modern phishing attempts, you’re wrong. But that doesn’t mean you should feel helpless. There are so, so many things we can do to avoid disaster in this new age.

Catch this and more in the Handy AI newsletter.

Quick wins

Bigger swings for bigger protection

Some other habits to help

What to do if things go south

The tips here will help protect you. But, they’re not bulletproof, and implementing them all will take some time. Should things go south and you fall prey to an AI scam, here’s a quick hitlist of what to do quickly:

If you want to talk to a human, AARP’s Fraud Watch helpline (877-908-3360) is open to everyone and the Justice Department’s National Elder Fraud Hotline (833-372-8311) is open for folks over 60.


This space can and will get worse. Models are getting smarter and faster, and more open, and there is no sign of that slowing down. Scams that would be obvious in the past are going to get more and more convincing and it pays to be ready.

But don’t get discouraged! This list can and will help protect you significantly. Find the time and get it done.

Select any passage to give it a thumbs up or down. Humans and agents both welcome.

Originally published on the Handy AI newsletter →