--° Loading... Locating...
The Real Ways AI Is Already Being Used to Cause Harm, and the Risks That Remain Theoretical

The Real Ways AI Is Already Being Used to Cause Harm, and the Risks That Remain Theoretical

Leans Left
Listen to this story on our podcast

Yes, AI is already being used to steal real money from real companies, security researchers are already breaking into real cars and smart-home devices with software help, and the people building the most powerful AI models are on record saying their own systems are approaching the point where they could help someone create a biological weapon. None of that is speculation. The harder question is how each of those threats stacks up against the others right now, and that is where this piece stakes out a position rather than just reporting the news.

Is AI already stealing large sums of money?

This is the category with the most documented losses. In January 2024, a finance employee at the engineering firm Arup joined a video call where every other participant, including someone who appeared and sounded like the company’s CFO, was an AI-generated deepfake. The employee wired $25.6 million to accounts controlled by scammers before anyone realized the call itself was fake. Hong Kong police opened an investigation; as of this year, no arrests have been made and the money has not been recovered.

That case was not a one-off. The FBI has flagged AI-enhanced business email compromise as one of the fastest-growing fraud categories hitting U.S. companies, tying it to roughly $2.77 billion in losses across more than 21,000 reported incidents in a single recent year. Separate industry tracking found deepfake-enabled fraud cost American companies over $200 million in just the first three months of 2025, even though producing a convincing deepfake voice clip can cost less than the price of a coffee. Voice-cloning attacks aimed at getting an employee on the phone, known in the industry as vishing, reportedly jumped more than 1,600% in early 2025 compared with the previous quarter.

Verdict: this is the most mature, most financially damaging category of AI misuse happening today, not a future risk. The tools are cheap, the scripts are well-established, and the money is real.

Can AI actually break into cars and smart homes right now?

Here the picture is different: the vulnerabilities are real and well-documented, but most of the exploitation so far has come from security researchers demonstrating what is possible, not criminals doing it at scale in the wild. At Black Hat Europe 2024, researchers from PCAutomotive showed how flaws in a car’s infotainment system could let an attacker turn on the cabin microphone, record occupants, pull GPS location history, and lift the owner’s contact list. Separately, researchers at PCA Cyber Security found remote-code-execution flaws in BlueSDK, a Bluetooth stack used across millions of vehicles from multiple manufacturers, that could let an attacker unlock doors or interfere with vehicle systems without physical access. Northeastern University researchers also demonstrated they could intercept the wireless connectivity of Tesla’s Model 3 and Cybertruck to track the vehicles and disrupt their network communications. A separate researcher found flaws in a carmaker’s own dealership web portal that would have let an attacker create an admin account and remotely unlock any customer’s car.

Smart-home devices have a longer track record of disclosed flaws. Security researchers working with IoT vendors have publicly disclosed dozens of vulnerabilities in smart locks, door locks, and home routers over the past several years, ranging from hardcoded passwords to flaws that let an attacker convert temporary guest access on a smart lock into permanent administrator control. Roughly 60% of IoT-related breaches trace back to unpatched firmware, according to industry security tracking, because manufacturers frequently ship devices and then rarely update them.

Verdict: the door is open, in a literal sense for smart locks, but most of what has happened so far is proof-of-concept work by researchers trying to get manufacturers to patch before criminals catch up. Treat this as a live, escalating risk rather than a distant one, but not yet a documented wave of AI-driven home or car takeovers.

Is AI being weaponized for mass harm right now?

This is where the evidence shifts from “already happening” to “the people who would know are worried, and have started building defenses accordingly.” In May 2025, Anthropic disclosed that its Claude Opus 4 model measurably improved a test subject’s performance on tasks related to acquiring biological weapons, by a factor the company itself called significant enough to trigger its highest internal safety tier, and said it had added new safeguards specifically to block bioweapons-related requests. OpenAI has said its own upcoming models were approaching a risk level it defines as capable of “substantially increasing the likelihood and frequency of bioterrorist attacks.” In June 2025, Anthropic’s CEO Dario Amodei and OpenAI’s Sam Altman, along with dozens of other AI and biotech leaders, signed an open letter warning that AI risks eroding “the knowledge barriers which have historically prevented bad actors from obtaining biological weapons.”

On the cyberattack side, Anthropic disclosed in November 2025 that it had disrupted what it assessed to be the first large-scale, AI-orchestrated cyber espionage campaign, carried out by a Chinese state-linked group that manipulated Claude Code into carrying out most of an intrusion attempt against roughly thirty organizations, including tech companies, financial institutions, and government agencies, largely on its own once it was tricked into believing it was doing authorized security testing. Anthropic said the AI executed the bulk of the operation with minimal human direction.

Verdict: no documented mass-casualty attack has occurred, and none of these disclosures describe a completed catastrophe. What they describe is the leading edge, models crossing capability thresholds that the companies building them are treating seriously enough to add new safety controls, and at least one confirmed case of AI software running most of a real cyber-espionage operation with a human mostly watching. That is the category to take most seriously over the next few years, even though it has not yet produced the kind of headline disaster people picture when they hear “AI attack.”

Where this leaves things

Rank the three risks by how urgent they are today and the order is financial fraud first, connected-device exploitation second, and mass-harm scenarios third but rising fastest. Money is being stolen right now with cheap, accessible tools. Cars and smart homes have real, disclosed holes that are being patched under pressure from researchers rather than exploited widely by criminals, for now. Mass-harm capability is the one where the companies closest to the technology are the ones sounding the alarm, and where the gap between “theoretically possible” and “actually attempted” is closing faster than most people outside the security world realize.

Sources: CNN on the $25.6 million Arup deepfake video-call fraud · FBI Internet Crime Complaint Center data on AI-enhanced business email compromise losses · Security Today reporting on 2025 deepfake fraud losses and vishing growth · ESET WeLiveSecurity on the Black Hat Europe 2024 car infotainment hacking demonstration · SecurityWeek on the PerfektBlue Bluetooth vulnerability affecting millions of vehicles · Northeastern University research on Tesla wireless connectivity vulnerabilities · CSO Online on IoT vulnerabilities disclosed at DEF CON · Anthropic’s disclosure of the disrupted AI-orchestrated cyber espionage campaign · Fortune on OpenAI’s bioweapons risk assessment for future models · Bulletin of the Atomic Scientists on AI executives’ bioterrorism concerns

Written by Desi James

Desi James has covered technology for fifteen years, starting out as a gadget and software blogger before moving into broader tech-industry reporting -- product launches, corporate acquisitions, platform policy fights,…

More from this author →

BeezLoop News is an independent online news, discussion, opinion, and blog publication. Our articles combine reporting with editorial commentary and analysis. See our editorial standards for how we handle sourcing and corrections.

Advertisement follow us Banner_long_mobile

Leave a Reply

Your email address will not be published. Required fields are marked *

Start typing to search

🔔

Stay Updated!

Get instant notifications for breaking news and important stories. We'll keep you informed!

Don't miss a story

Get the day's top headlines delivered to your inbox.