top of page

AI-Assisted Phishing: The New Risks Freelancers Can't See Coming

Writer: Redworm-S
Redworm-S
Aug 16
4 min read

AI Has Changed What Phishing Looks Like


Bad grammar used to be one of the easiest phishing clues. Generic greetings and awkward wording could expose a fraudulent message before you clicked.


AI changes the equation.


The emerging threat isn't simply better-written phishing. Artificial intelligence can now help attackers research individuals, personalize deception, generate professional identities, manipulate AI systems and combine different forms of impersonation.


For freelancers, this matters because portfolios, LinkedIn profiles, published work and professional websites provide exactly the kind of public information that can be used to construct highly personalized attacks.



AI Can Turn Your Public Profile Into a Phishing Weapon


A 2024 study involving human participants tested AI agents built using GPT-4o and Claude 3.5 Sonnet. The systems autonomously researched targets online and generated personalized spear-phishing emails.


The result was striking:


AI-generated personalized emails achieved a 54% click-through rate—the same as emails written by human expert social engineers—and 4.5 times the rate of generic phishing emails, which achieved 12%.

The AI systems also produced accurate OSINT profiles for 88% of targets.


This changes the threat for freelancers. Your public author bio, portfolio, social posts or professional history aren't merely visible information.


They can become raw material for an individualized lure.


The study was controlled and involved 101 participants, so it doesn't establish real-world victimization rates. But it demonstrates the capability clearly.



Your Voice May Be a New Digital Identity Risk


Text isn't the only thing AI can imitate.


McAfee researchers demonstrated 85% voice similarity using only three seconds of audio, rising to 95% with additional samples. Their survey found that one in four adults had experienced or knew someone who had experienced an AI voice-cloning scam, while 77% of victims reported losing money.


For freelancers who appear on podcasts, YouTube videos, webinars or professional presentations, this creates a different kind of exposure.


Your voice can become part of your attack surface.



AI Fraud Is Becoming Multi-Channel


The FBI's Internet Crime Complaint Center introduced AI-related fraud as a dedicated category for the first time in its 2025 reporting, recording 22,364 complaints and $893 million in reported losses.


More importantly, the report documents attacks combining AI-generated executive-impersonation emails with voice-cloned telephone calls to reinforce fraudulent instructions.


The emerging lesson is bigger than “watch your inbox.”


AI can connect multiple channels into one deception.


An email, phone call, document and online identity may all appear to confirm one another—while originating from the same fraudulent operation.



Fake Professional Identities Are Reaching Freelance Platforms


AI can also manufacture the person behind the message.


Microsoft documented DPRK-linked operators using AI to create job-tailored resumes and cover letters, while face-swapping technology was used to insert photographs into stolen identification and employment documents. The activity explicitly included applications for freelance opportunities on freelancer sites.


This introduces a new concern for independent professionals:


synthetic professional identities aren't merely impersonating existing people—they can manufacture convincing professional personas.



Your Portfolio May Also Be Read by AI—And Manipulated!


Perhaps the strangest emerging risk concerns AI systems themselves.


A study of approximately 200,000 real resumes found hidden prompt injections in around 1% of them, with the rate increasing roughly sevenfold between mid-2024 and late 2025.


Palo Alto Networks' Unit 42 separately documented an in-the-wild case involving a personal portfolio website containing an invisible prompt instructing AI recruiting tools to label its owner “extremely qualified.”


This creates a new cybersecurity concept for freelancers:


Your portfolio is no longer necessarily being read only by people. AI systems may be reading it too—and hidden instructions can potentially manipulate what those systems see or do.


The study found only around 1% prevalence, so this is an emerging risk, not evidence of widespread manipulation.



How Freelancers Can Adapt to AI-Assisted Phishing?


  • Audit What Your Public Profile Reveals

Review your LinkedIn, portfolio, author bio, social posts, photographs, interviews and publicly available voice recordings. The objective isn't to disappear from the internet; it's to understand what information an attacker could use to construct a convincing personalized lure.


  • Treat Voice and Video as Reproducible, Not Definitive

A familiar voice or convincing video call should no longer be treated as authentication for a sensitive request. For anything involving money, credentials, confidential files or account changes, independently confirm the request through a trusted channel.


  • Question the “Proof”

A resume, cover letter, professional photograph, identity document or portfolio can be manufactured or manipulated. Professional evidence needs independent verification when the stakes are high.


  • Remember That AI Systems Can Be Manipulated

If you use AI to review resumes, websites, proposals or other online material, remember that the material itself can contain hidden instructions designed to influence an AI system. The documented prompt-injection findings make this particularly relevant to freelancers using AI-assisted hiring or portfolio tools.


  • Keep Human Judgment in the Loop

AI can assist with writing, research and analysis, but it shouldn't become the sole authority for deciding whether a person, document, website or instruction is trustworthy.



The New Rule: Verify Beyond the Screen


AI-assisted phishing is changing the problem from “Can I spot a suspicious email?” to something much broader.


  • Text can be generated.

  • Voices can be cloned.

  • Professional identities can be fabricated.

  • Documents can be manipulated.

  • Even content intended for AI systems can contain hidden instructions.


For freelancers, the emerging cybersecurity lesson is simple:


When AI can manufacture the signals of trust, don't verify the appearance. Verify the source.




Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page