Neural networks have radically transformed the landscape of cybercrime, enabling hackers to crack Russian users’ passwords in mere seconds. Simple combinations are breached instantly, while more complex ones take just a few minutes. This was reported by Izvestia, citing cybersecurity experts. So how can you create a secure password and protect yourself from AI-powered fraud schemes? Let’s break it down.
How Neural Networks Crack PasswordsAccording to Sergey Voldokhin, CEO of Start X and a member of the Cyberdom business club, neural networks function similarly to predictive keyboard assistants that guess what you’re typing.“Imagine you're composing a message on your phone, and the keyboard offers to complete a word or sentence. Sometimes it's so accurate, it feels like it's reading your mind. Modern neural networks work in a similar way when cracking passwords,” Voldokhin explained.
Neural networks are trained on millions of stolen passwords from data breaches. They identify popular patterns—like replacing "a" with "@", adding "!" or a year (e.g., "Password2025"). Using this data, they generate lists of likely combinations, which are then tested using brute-force software.
“As a result, a simple 8-character password with letters and numbers can be cracked in seconds, and a more complex 12-character password in a few hours,” the expert noted.
Most Vulnerable PasswordsVoldokhin explained that the quickest to crack are:
Dictionary words (“password”, “qwerty”). Birth years or seasons with a year (“summer2025”, “winter2024”). Pet names or personal names. Keyboard sequences (“zxcvbn”). Predictable character substitutions (“p@ssw0rd” instead of “password”).Reused passwords pose a particular danger. “If you use the same password across multiple sites, a hacker only needs to compromise your account on a less secure platform—like a forum or online game—to gain access to more critical services, including banking,” Voldokhin warned.
Alexander Dubrovin, a business partner at IT company Edna, added that leaked databases containing passwords from social networks and services significantly simplify hackers’ work. Users are advised to regularly check for data leaks (e.g., using services like Have I Been Pwned) and immediately change compromised passwords.
Cybercriminals' TargetsAccording to Sarkis Shmavonyan of Cyberprotect, fraudsters focus on accounts that provide financial or strategic value:
Financial services: Online banking, e-wallets, payment systems. E-commerce platforms: Marketplaces linked to credit cards, bonus accounts. Data storage: Cloud services (Google Drive, Yandex Disk), email, social media accounts with private conversations. Premium services: Gaming accounts, subscriptions (Netflix, Spotify).“Once they gain access, attackers can charge linked cards, apply for online loans in your name, steal or sell personal data (passport details, addresses, phone numbers), or impersonate you in fraud schemes,” said Voldokhin.
Hackers also focus on accounts of company employees handling confidential data (managers, IT specialists, lawyers, accountants), as well as public figures—celebrities, entrepreneurs, influencers. Access to such accounts may be sold to competitors or used for blackmail. In some cases, fraudsters publish private photos or videos and demand ransom.
How AI Assists CriminalsNeural networks are used not only to crack passwords but to power other fraud schemes:
Deepfakes: AI creates fake videos and audio mimicking a victim’s voice and appearance. Just 3–5 seconds of audio or a few photos are enough. Scammers create fake stories or video messages asking for money or data. Phishing websites: AI generates realistic websites imitating legitimate services. Fraudsters only need to provide a domain name; the neural network builds the design, text, and even a support chatbot. Chat analysis: Neural networks study a victim’s communication style to craft messages that build trust. This allows real-time conversation with adaptive responses. Multimodal attacks: AI simultaneously mimics voice and face to create lifelike video calls.“Neural networks can ‘animate’ a photo. Attackers use this to make fake video messages in messengers—so-called ‘video bubbles’—from animated photos and voice recordings. It looks especially convincing if the fake account uses the real person’s name and photo,” Dubrovin explained.
How to Protect YourselfExperts suggest several ways to minimize risks:
1. Create strong passwords: Length: Minimum of 12–16 characters. Composition: Mix of uppercase and lowercase letters, numbers, and special symbols (@, #, &). Avoid: Dictionary words, personal info (name, birthdate), predictable substitutions (“0” for “o”). Tip from Dmitry Galov of Kaspersky: “To create a strong password, take a line from a song or poem, remove the vowels, and replace them with special characters.”Example: “I have erected a monument to myself” → “Yp#mtn!ks#b#v#zdv!g”. 2. Use password managers: Tools like Kaspersky Password Manager, KeePass (free and open-source), LastPass, 1Password, or RoboForm generate and store complex passwords. KeePass stores data locally in an encrypted file for enhanced security. “Use content verification tools. Most social networks already label AI-generated images. Try free metadata analysis services,” Voldokhin advises. 3. Enable two-factor authentication (2FA): Prefer code generator apps (Google Authenticator, Microsoft Authenticator) or physical keys (YubiKey). Avoid SMS-based codes—they can be intercepted. 2FA is essential for banking apps, email, and social media. 4. Verify calls and messages: In video calls, look for unnatural eye movements, odd lighting or background, strange mouth/tongue animation. Ask the caller to turn their head or say a code word. “Use content verification tools. Most social media now label AI images. Use free metadata scanners,” Voldokhin recommends. Contact the sender via a known alternative channel (e.g., call a known number). 5. Avoid phishing traps: Don’t click suspicious links. Manually type website URLs. Use browsers with anti-phishing features.“Built-in neural networks can detect phishing signs using hundreds of indicators—like the domain’s creation date or traffic volume. The browser analyzes this in real time, preventing visits to malicious sites before they're even blacklisted. Since the start of the year, neural networks have blocked attacks that could have affected over 25 million users,” Yandex Browser’s press service stated. 6. Regularly update passwords: Change them every 3–6 months, especially after breach alerts. Check for leaks using tools like Have I Been Pwned. 7. Use secret code phrases: Agree on an emergency phrase with family or friends to help identify real messages from deepfake scams. AI on the Defense SideNeural networks are also used to protect users.Yandex Browser’s press service told Izvestia that AI is actively used to quickly detect new threats and block fraudulent attempts.Neural networks help respond to hacker activity in real time, shielding users from even the most sophisticated fraud tactics.For example, Yandex’s caller ID system analyzes over 300 factors (call frequency, duration, who ends the call) to identify scammers.
ConclusionNeural networks have made cybercrime more accessible and effective: passwords are cracked in seconds, deepfakes fool even cautious users, and phishing sites look indistinguishable from real ones. To protect yourself, use strong, unique passwords, password managers, two-factor authentication, and verify suspicious communications. Frequent password changes and attention to detail (especially during video calls) help reduce risks. Neural networks are also allies in the fight, helping browsers and services block threats proactively. In 2025, cybersecurity requires a multi-layered approach: combine tech tools with personal vigilance to avoid falling victim to AI-powered attacks.
Follow NEWS.am Tech on Facebook and Twitter