Skip to content
Aspire SAT
AI cybersecurity awareness handbook

Understand the request.
Recognize the risk.

Give your team a starting point for conversations about AI-enabled threats. Explore impersonation, identity and data-access scenarios, then connect them to your organization’s own security practices.

  • Three topic groups
  • Warning signs
  • Team discussions
Read. Discuss. Apply.

Make the topic
part of the work.

  1. 01

    Understand the scenario

    Start with the description and the request someone might receive.

  2. 02

    Look for the warning signs

    Discuss which parts of the request need independent verification.

  3. 03

    Connect the response

    Match the discussion to your approved controls and reporting process.

Preview the themes

Different threats.
Connected decisions.

Browse the topics introduced on this page. Open a topic for a short description, then use it to frame a discussion with your team.

01

Emerging AI-Enabled Cyber Threats

Explore scenarios involving AI-assisted messages, impersonation and the use of AI tools at work.

AI-Powered Phishing & Spear Phishing

Personalized scam emails, SMS and chats can appear convincing. Discuss how your team verifies the request beyond its writing style.

Deepfake Voice & Video Fraud

Cloned executive voices and fake video calls that pressure staff into urgent transfers or data sharing.

Fake Profiles & Synthetic Identity Fraud

AI-generated faces, resumes, and documents used for romance, job, vendor, and insider-access scams.

AI Data Leakage & Shadow AI

Sensitive data pasted into unapproved public AI tools — exposing clients, code, and contracts.

Prompt Injection Attacks

Malicious instructions in content an AI system processes may attempt to redirect its behavior or expose information.

AI Agent Misuse

Over-permissioned AI agents tricked into sending emails, moving files, or triggering payments.

AI Model Poisoning

Corrupted training data that pushes AI systems toward wrong, unsafe, or attacker-friendly outputs.

AI-Generated Malware & Adaptive Ransomware

Malware written, disguised, and adapted with AI to evade detection and scale faster.

AI-Assisted Business Email Compromise (BEC)

Messages impersonating executives or vendors may request changed payment details or misuse an existing conversation.

Fake Apps, Payment & QR Fraud

Lookalike apps, payment pages, and malicious QR codes that harvest OTPs, PINs, and card data.

02

AI-Enabled Cloud, Identity, Data & Banking Integrity Threats

How attackers turn stolen access into data theft, extortion, and manipulated transactions across cloud and banking systems.

Cloud Credential Compromise & MFA Failure

Stolen sign-in details and repeated approval prompts can put cloud access at risk. Discuss how unexpected prompts are reported.

OAuth Token Theft & Malicious Connected Apps

A connected app may request access to mail or files. Discuss how your organization reviews permissions and removes unapproved access.

Customer Data Exfiltration & Extortion

Bulk data theft, prioritized by AI, followed by threats to leak or sell what was stolen.

API & Open-Banking Integration Abuse

Weak authorization and exposed endpoints exploited to reach data and transactions they shouldn’t.

Privileged Account Takeover & PAM Failure

Admin and service accounts hijacked through AI phishing and fake help-desk escalation.

Banking Data Manipulation & Transaction Integrity

Altered beneficiaries, amounts, and approvals that look like valid transactions until it’s too late.

03

Research, Document & Remote-Access Threats

The quieter attacks on intellectual property, collaboration platforms, and the tools your IT teams trust.

Research Data & Intellectual Property Theft

Source code, formulas, models, and strategy documents stolen and sorted by AI for maximum value.

Document Platform Zero-Day Exploitation

Vulnerabilities in document-sharing platforms can put files and access at risk. Discuss who handles platform updates and suspicious activity reports.

Remote Support & IT Management Tool Compromise

Fake IT support that convinces users to hand over screen and device control for theft or ransomware.

Watch the introduction

A starting point
for your next discussion.

Watch the existing handbook introduction, then choose a theme to explore with colleagues in finance, IT, operations or your security team.

Pair it with the awareness toolkit
Open video in a new tab
Take the next step

Continue with the handbook.

Request access through the handbook form. Use the resource alongside your organization’s policies and reporting channels.

For guided practice, explore deepfake simulation or role-based security awareness training.

Continue through the resource access form. Follow the instructions shown there after submission.

Need help accessing a resource?

Handbook access

Open access form in a new tab ↗

The form will load here. You can also open it in a new tab using the link above.

Review the form’s consent options before submitting. Read our privacy notice.

From reading to practice

Build a program your people can use.

Explore training, simulations and reporting in the context of your team’s daily work.