Agentic AI fraud: The next wave of cybercrime is here

AutomotiveCyberArticleSeptember 18, 2026

Agentic AI can streamline dealership operations, but it may also create new fraud and cyber risks that dealers should understand and address.
Share this

The AI revolution is a moment where both the opportunities and the risks seem almost infinite. For auto dealerships, like the vast majority of businesses, this may be the most transformative technology in history, so there’s an understandable rush to adopt it and keep pace with competitors.

“Agentic AI” may still be an unfamiliar term for many, but that will change quickly. A recent survey of 500 senior leaders at major companies showed 100% planned to expand agentic AI use this year.1

Agentic AI is a system (an “agent”) created to operate autonomously, accomplishing complex tasks with no or limited supervision. It is already being used for everything from automating workflows to customer support, technical troubleshooting, real-time recommendations to consumers, rapid financial data analysis, and much more.

Agentic AI offers promise and pitfalls

The positives for auto dealers are obvious. Agentic AI can be used to simplify and automate many processes that can be time-consuming, like booking service department appointments, processing documents, analyzing customer interactions, pre-qualifying used car acquisition leads, and…well, the possibilities do seem endless.

However, criminals are also adopting agentic AI at a record pace, creating new paths to fraud in an industry already plagued by it. According to a survey released in February, nearly 80% of auto dealer respondents saw a rise in fraud-related incidents over a two-year period.2 It’s too early for solid data on how much of that increase is due specifically to agentic AI, but the technology poses massive potential for misuse, including but by no means limited to:

  • Creating authentic-looking forgeries of bank statements and other financial records to secure financing
  • Enabling faster and more convincing identity fraud
  • Finding paths to unauthorized access to dealership systems 
  • Creating fraudulent statements of vehicle trade-in value
  • Generating false negative consumer reviews, damaging a dealer’s reputation
  • Breaching dispatcher communication portals to facilitate theft of vehicles in transit

Common attack vectors for agentic AI include:

  • Prompt injection or “agent hijacking” − Deceptive text inputted into a large language model
  • Integration vulnerabilities – Security gaps in connections between different systems, applications or data sources
  • Synthetic identities or impersonation
  • Jailbreaking – Bypassing limitations and controls implemented to secure the AI agent
  • Data poisoning – Corrupting training data to alter an AI model

An unpredictable adversary

The fact is, we are only in the very early stages of seeing where agentic AI fraud is headed, and it’s fraught with unknowns.

“We don’t fully understand how AI works,” explained Matthew Orme, a cybersecurity consultant for SpearTip, a Zurich-owned cyber counterintelligence firm. Orme has spent 15 years exposing vulnerabilities to help secure some of the largest corporate systems across many industries.

“We understand how to get AI to do, mostly, what we want,” he continued. “But even when it does, we’re not entirely sure why.”

And Orme’s comment doesn’t simply apply to the general public or those with limited cyber knowledge. One of the leading figures in AI development, Anthropic founder Dario Amodei, wrote, “People outside the field are often surprised and alarmed to learn that we do not understand how our own AI creations work. They are right to be concerned: this lack of understanding is essentially unprecedented in the history of technology.”3

Orme also noted that much simpler cybersecurity risks remain a hurdle.

“Randomly generated passwords of 12-plus characters — when not shared across accounts or between people — are very secure. Yet password attacks are among the most common sources of breaches,” he said. “AI is an entirely new attack surface with only partially understood function and design, so combatting threats is immeasurably more complex. Passwords are a very solvable exposure, and we haven’t solved it. AI might remain unsolvable for decades.”

“Almost every aspect of a car dealership is susceptible to AI fraud,” Orme continued. “Any time LLM (large language model) bots are used to interact directly with customers, the opportunity exists to take advantage of the technology.”

Considering its capabilities, a worst-case scenario for an AI agent disaster is hard to gauge, but one story from last year was pretty alarming. An app-building platform’s AI agent in development “went rogue” and deleted the company’s entire database.Fortunately, the developers were able to restore the database, but the incident points to the daunting risk exposure the autonomy of agentic AI presents.

On the bright side…

If this all sounds unbearably ominous, here’s the good news: Agentic AI is also already proving effective in combatting fraud and its risk-reduction power may be as unlimited as its threat potential. AI agents can be used to:

  • Rapidly identify fraud and other suspicious activity
  • Identify and track fraud trends to more quickly expose crime rings
  • Continuously monitor and analyze transactions, capturing fraud acts in real time

More than ever, combatting cybercrime demands expertise. Agentic AI is empowering criminals with limited technical knowledge to put your business at risk. The best defense is working with business partners and vendors who prioritize growing their cyber threat knowledge base, sharing best mitigation practices, and keeping a step ahead of evolving threats.

SpearTip, a Zurich-owned cyber counterintelligence firm, offers advisory, managed security and incident-response services to help protect your dealership. Learn more about SpearTip here, or contact your Zurich representative for more information.

 This article originally appeared in the Spring/Summer 2026 issue of Dealer Principal magazine.

 

1. “Agentic AI Reaches Tipping Point: 100% of Enterprises Plan to Expand Adoption in 2026, New CrewAI Survey Finds.” Business Wire. 11 February 2026.

2. “Dealership Fraud Surges as Digital Vehicle Purchases Increase.” PRNewswire. 2 February 2026.

3. Amodei, Dario. “The Urgency of Interpretability.” DarioAmodei.com. April 2025.

4. Forlini, Emily. “Vibe Coding Fiasco: AI Agent Goes Rogue, Deletes Company's Entire Database.” PCMag. 22 July 2025.

 

The information in this publication was compiled from sources believed to be reliable for informational purposes only. All sample policies and procedures herein should serve as a guideline, which you can use to create your own policies and procedures. We trust that you will customize these samples to reflect your own operations and believe that these samples may serve as a helpful platform for this endeavor. Any and all information contained herein is not intended to constitute advice (particularly not legal advice). Accordingly, persons requiring advice should consult independent advisors when developing programs and policies. We do not guarantee the accuracy of this information or any results and further assume no liability in connection with this publication and sample policies and procedures, including any information, methods or safety suggestions contained herein. We undertake no obligation to publicly update or revise any of this information, whether to reflect new information, future developments, events or circumstances or otherwise. Moreover, Zurich reminds you that this cannot be assumed to contain every acceptable safety and compliance procedure or that additional procedures might not be appropriate under the circumstances. The subject matter of this publication is not tied to any specific insurance product nor will adopting these policies and procedures ensure coverage under any insurance policy.