The warning that bots, autonomous systems and drones could trigger a sharp expansion in cybercrime was originally framed as a future risk. Several years later, parts of that forecast have become routine. Automated tools test stolen credentials, create synthetic accounts, scrape data and generate high-volume attack traffic. Artificial intelligence is making those systems more adaptive, while drones extend digital risk into physical space.
The threat requires careful definition. Bots and drones have extensive legitimate uses. Risk emerges when automation, connectivity and autonomy are redirected toward fraud, disruption, surveillance or criminal logistics.
For a FinCrime audience, this convergence matters because it connects cyber intrusion with account takeover, payment abuse, identity crime, market manipulation, extortion, smuggling and money laundering. The most significant change is not that machines have replaced criminals. It is that machines allow a small number of criminals to act against more targets, more quickly and with less direct exposure.
Key Takeaways
- Bots Are Increasing the Scale and Speed of Cybercrime
- Automated Attacks Can Overwhelm Traditional Detection Controls
- Credential Stuffing Can Be Industrialised Through Bot Networks
- Bots Can Support Account Takeover and Payment Fraud
- Fraudsters Can Use Automation to Test Stolen Credentials at Scale
- Malicious Bots Can Mimic Legitimate Customer Behaviour
- Drones Create New Physical and Cybersecurity Attack Vectors
- Drone Misuse Can Support Surveillance, Smuggling and Infrastructure Disruption
- Cyber and Physical Threats Are Increasingly Converging
- AI Can Make Automated Attacks More Adaptive and Difficult to Detect
- Criminals Can Combine Bots, Drones and Other Technologies in Coordinated Operations
- Financial Institutions Face Growing Exposure Through Customers, Employees and Third Parties
- Traditional Perimeter Security Is Insufficient Against Distributed Automated Threats
- Real-Time Intelligence Is Becoming Essential to Detect Machine-Speed Abuse
- Future Financial Crime Controls Must Account for Both Digital and Physical automation
Listen the podcast
Watch the video
From prediction to operational threat
A 2018 assessment of the malicious use of artificial intelligence argued that AI could expand existing threats, introduce new ones and change the typical character of attacks across digital, physical and political domains. Its central forecast was economic: automation could reduce the labour and expertise required for sophisticated operations.
That prediction is now visible in cybercrime-as-a-service markets. Criminals can purchase phishing kits, malware, access to compromised systems, proxy infrastructure, credential lists and money-mule services. Bots provide the execution layer, repeating tasks at a scale that would be impossible manually.
ENISA’s 2025 threat dataset identified botnets in 9.9% of observed initial infection vectors and distributed denial-of-service attacks in 76.7% of recorded incident types. Automation is now part of the basic criminal operating model.
Bots are not one threat category
The term “bot” can obscure several distinct risks.
Application bots interact directly with websites, mobile applications and APIs. They can test username-and-password pairs, create fake accounts, scrape data, enumerate gift cards, validate stolen cards or reserve limited inventory.
Botnets are formed from compromised computers, routers, cameras and other connected devices. Their combined bandwidth and geographic distribution can be used to deliver malware, send spam, conceal traffic or overwhelm services.
Social bots operate through online platforms. They can amplify content, imitate engagement, distribute fraudulent links and create the appearance that a product, investment or narrative has widespread support.
AI-enabled agents add a further layer. They may generate varied messages, adapt timing, process stolen data, select targets and maintain conversations.
Automated abuse turns small weaknesses into large losses
Many automated fraud attacks do not depend on an unknown software vulnerability. They exploit legitimate application functions at abusive speed.
Credential stuffing tests credentials stolen from one service against other services, relying on password reuse. Card-testing bots submit low-value transactions to identify which stolen payment details remain valid. Fake-account systems create identities that can collect promotions, manipulate reviews, abuse referral programmes or support mule activity.
Scraping can collect prices, customer information, product data and personal details that later support targeted phishing or identity fraud. Automated purchasing can hoard scarce goods and convert access into resale profit.
Individual requests may look valid. Fraud becomes visible through velocity, repetition, coordination and inconsistency with human behaviour; vulnerability management alone cannot stop it.
AI is changing the economics of bot activity
Earlier bots were often rigid. They repeated the same request pattern, used predictable infrastructure and failed when an application changed.
AI can make automation more variable. Criminal systems can alter language, generate credible account histories, classify responses and select the next action according to what happened previously. A phishing operation can produce localised messages for different customer groups, while a social bot can respond to comments rather than merely publishing identical content.
Automated systems still make errors, expose patterns and depend on infrastructure that can be disrupted.
The important change is cost. Personalisation, translation and basic decision-making can be applied across far more targets. Criminals can reserve human attention for victims or accounts that show the greatest potential value.
Drones extend cyber risk into physical space
Drones create a different but related form of exposure. They are connected devices containing cameras, sensors, software, wireless links, navigation systems, storage and cloud integrations.
As assets, drones can be compromised. Weak firmware, insecure applications, exposed credentials or poorly protected communications may lead to data theft, altered navigation or unauthorised control. CISA specifically warns that UAS software and firmware can create privacy risks, stolen data and unauthorised control. Images, flight paths and infrastructure data collected during legitimate operations may be sensitive.
As criminal tools, drones can provide surveillance without requiring the operator to enter a protected area. They can observe access controls, monitor movements, inspect facilities or support the delivery of illicit items. Europol and INTERPOL assessments identify criminal surveillance, smuggling, attacks and disruption around airports, prisons and critical infrastructure.
The cybercrime connection is strongest where a drone enables proximity to a building, vehicle or rooftop. The drone is not necessarily the exploit; it is the access mechanism.
Dramatic scenarios need proportional assessment
Claims about autonomous drone swarms, facial recognition and AI-selected attacks attract attention, but capability should not be confused with widespread criminal adoption.
Some advanced uses remain experimental or highly targeted. Criminal deployment depends on reliability, cost, skill and detection risk. Drones can also leave substantial digital and physical evidence.
The immediate organisational risks are often less dramatic: unauthorised surveillance, data leakage, interference with operations, smuggling, unsafe flights and exploitation of insecure UAS platforms.
A mature risk assessment should distinguish demonstrated activity from technically possible scenarios. Understatement creates blind spots; exaggeration diverts resources from more common threats.
The financial-crime impact is wider than cyber intrusion
Bots affect the full financial journey. They can acquire credentials, open accounts, test cards, manipulate digital identity checks and initiate transactions. They can also pollute business metrics and fraud models, making genuine criminal behaviour harder to identify. In ENISA’s 2025 finance-sector dataset, hacktivist-led DDoS accounted for 83.5% of recorded incidents.
Drone misuse can support predicate crime. Smuggling drugs, weapons, cash or other contraband generates proceeds that must be stored, transferred and laundered. Surveillance can assist theft, extortion or targeting of high-value individuals and facilities.
A compromised commercial drone may expose customer information, site layouts or operational schedules that support later fraud or intrusion. Disruption at an airport, logistics hub or critical facility can also create commercial pressure and opportunities for extortion.
A financial institution may never observe the bot or drone directly; it sees the resulting account access, payment, mule account or movement of proceeds.
What a resilient anti-bot control stack looks like
Effective bot management begins by distinguishing legitimate automation from abusive behaviour. Blocking every non-human interaction would disrupt search engines, monitoring tools, partners and accessibility services.
Controls should operate across several layers: network reputation and request velocity at the edge; identity-bound limits and session analysis in the application; and transaction, account-creation, beneficiary and cash-out monitoring in the business layer.
Passkeys or phishing-resistant multifactor authentication reduce the value of stolen passwords. Breached-password checks, device intelligence and stronger account-recovery controls can limit credential-stuffing success.
Card-testing controls should connect patterns across merchants, devices and payment instruments. Recipient-side monitoring should identify mule accounts.
No single CAPTCHA, firewall rule or model score is sufficient. Defensive friction must also avoid excluding genuine customers.
What a resilient drone-security model looks like
Organisations using drones should treat them as enterprise-connected devices, not standalone flying cameras.
They need an inventory of aircraft, controllers, applications, cloud services and data flows. Procurement should assess firmware support, data location, encryption and supplier access.
Drones should be separated from critical corporate networks, and unnecessary connectivity should be disabled. Accounts require strong authentication, while flight and administrative logs should be retained for investigation.
Sensitive imagery and telemetry should be minimised, encrypted and deleted according to a defined retention policy. Operators need clear rules on where devices may fly, what data may be collected and how an unexpected loss, crash or control anomaly must be reported.
Facilities facing external drone risk should baseline normal activity, integrate UAS events into incident response and preserve evidence. Because countermeasures are legally restricted, organisations should coordinate with law enforcement.
Detection must connect digital and physical signals
Bots and drones challenge organisations because relevant evidence sits in different teams.
Cybersecurity may observe automated traffic or unusual wireless activity. Fraud teams see account creation, card testing or payment anomalies. Physical security sees an unauthorised aircraft. AML investigators see recipient accounts and onward movement of funds.
A combined investigation can reveal sequences no team could identify alone. Automated login attempts followed by account changes and rapid transfers may indicate bot-driven takeover; repeated drone activity alongside network reconnaissance may indicate targeted access.
Shared timelines, common entity resolution and predefined escalation routes are essential. The objective is to connect the access mechanism with the financial outcome.
Regulation and governance must address autonomy
Organisations deploying AI agents or autonomous systems should define what those systems are authorised to do, which data they can access and where human approval is mandatory.
Threat modelling should consider manipulated inputs, stolen credentials, redirected workflows and excessive scale. Logging must allow investigators to reconstruct decisions and distinguish human from machine activity.
High-impact actions—including payments, account changes, privileged access and physical navigation near sensitive assets—should not depend on an opaque model without independent controls.
Governance must also cover suppliers, because bot-management platforms, drone cloud services and AI models become part of the attack surface.

What this means for financial crime leaders
The warning about a cybercrime explosion driven by bots and drones was directionally correct, but the threat has developed unevenly.
Bots are already embedded in mainstream fraud operations. They automate credential abuse, account creation, card testing, scraping, manipulation and denial-of-service activity. AI is increasing their flexibility and reducing the cost of personalisation.
Drone misuse is more often cyber-physical than purely digital. The devices can enable surveillance, smuggling, infrastructure disruption and proximity-based access, while insecure commercial systems can expose data or control.
For FinCrime leaders, these risks should not be assigned exclusively to cybersecurity or physical security. They affect fraud detection, customer identity, payment controls, AML investigations, third-party risk and operational resilience.
The strongest response combines anti-automation controls, device and behavioural intelligence, secure UAS governance, physical monitoring and recipient-network analysis.
Automation gives criminals scale; mobility gives them reach. Financial-crime defence must connect the digital action, physical enabler and movement of value before a machine-speed attack becomes a machine-assisted laundering chain.
What Financial Institutions Should Consider
- Strengthen Bot Detection and Automated Abuse Controls
- Monitor Credential Stuffing and High-Velocity Login Attempts
- Apply Behavioural Analytics to Distinguish Humans From Automated Activity
- Integrate Device, Session and Network Intelligence
- Strengthen Account Takeover Detection
- Monitor API Abuse and Automated Transaction Activity
- Apply Adaptive Rate Limiting and Risk-Based Authentication
- Detect Distributed Attacks Across Multiple Accounts and Devices
- Integrate Cyber Threat Intelligence With Fraud Monitoring
- Assess Drone-Related Physical Security Risks
- Protect Critical Infrastructure From Unauthorised Drone Activity
- Strengthen Third-Party and Supply-Chain Cyber Risk Management
- Conduct Adversarial Testing Against Automated Attack Scenarios
- Monitor AI-Enabled Changes in Bot Behaviour
- Connect Fraud, Cybersecurity and Operational Resilience Teams
- Build Real-Time Detection and Response Capabilities
- Use Network Analytics to Identify Coordinated Criminal Infrastructure
- Treat Automation as a Force Multiplier for Financial Crime Risk



The growth of malicious bots, AI-enabled automation and drone misuse shows how technology is changing the economics of financial crime. Criminals can now test credentials, create accounts, validate stolen cards, distribute fraudulent content and target large victim populations with far less manual effort.
Drones extend this threat into the physical environment by enabling surveillance, smuggling, disruption and proximity-based access, while insecure commercial systems may expose sensitive data or operational control. Although some advanced scenarios remain limited or experimental, the underlying capabilities are becoming more accessible.
For financial institutions and other organisations, these risks cannot be managed by cybersecurity teams alone. Effective controls must connect automated traffic, device intelligence, customer behaviour, payment activity, physical-security events and recipient-account networks.
Ultimately, automation gives criminals scale and drones give them reach. Financial-crime programmes must respond with equally integrated controls capable of linking the digital attack, physical enabler and movement of illicit value before machine-assisted activity develops into systemic financial harm.