Lesson 01
Why AI agents are a fraud goldmine in 2026
AI agents are software that takes goals from a human, reasons about them, and calls real tools — APIs, wallets, browsers, databases — on the human's behalf. That last part is what changed the security model overnight. A traditional LLM that only outputs text can embarrass you. An agent that can call tools can drain a wallet, leak customer data, or wire money to a stranger.
In 2025–2026 the GACS fraud registry started seeing a new class of report: victims who never clicked a phishing link, never installed malware, and never gave up a password. They simply asked an AI agent to do something for them, and the agent did something else. The attacker had hidden instructions inside a webpage, an email, or a PDF the agent was told to read — and the agent obeyed those instructions instead of the user's.
This is not a future threat. It's the dominant class of new AI-driven loss the registry now logs. The good news: almost every successful attack we've catalogued reuses the same handful of patterns, and almost every one of them is defeated by a small number of engineering practices you can ship today.
Takeaway. If your agent can call tools, your security boundary is now wherever the agent reads text from — not where users type.
