

For years, the battle against online fraud has felt like a losing game of cat and mouse. Cybercrime has ballooned into a staggering $1.24 trillion global industry, with sophisticated call centres operating like corporate enterprises to strip unsuspecting individuals of their life savings. However, the cybersecurity world is witnessing a dramatic plot twist.
Instead of AI simply being weaponised by bad actors to automate phishing, defender technology is turning the tables. An Australian technology firm called Apate has deployed a army of nearly 200,000 AI-powered "victims" designed specifically to waste scammers' time, ruin their efficiency, and harvest actionable intelligence.
Scam baiting—the practice of deliberately wasting a fraudster's time by acting gullible—used to be the domain of quirky internet hobbyists and YouTubers. Apate has taken this concept and scaled it into an enterprise-grade defence platform.
Originating from research led by Professor Dali Kaafar at Macquarie University in Sydney, Apate was born out of a real-world frustration. After stringing along a phone scammer for 44 minutes during a family picnic to entertain his children, Kaafar realised that automating this process could fundamentally dismantle the economics of scamming.
Today, Apate manages a stable of almost 200,000 distinct AI personas across social media, messaging apps such as WhatsApp and Telegram, and traditional phone lines. These bots feature realistic vocal tics, regional accents, natural pauses, and believable background noises to convincingly mimic real human targets.
While most technology companies track uptime or conversions, Apate measures success with a rather unconventional Key Performance Indicator (KPI): how many times frustrated scammers swear at their AI bots.
Because the bots play dumb and string fraudsters along for hours without ever revealing real banking information, scammers frequently lose their temper. This hilarious metric directly correlates with operational impact: every minute a scammer spends swearing at an AI persona is a minute they are not exploiting a vulnerable member of the public.
The impact is far from trivial:
Wasting a scammer's time is satisfying, but the true power of this technology lies in intelligence extraction. The AI models were trained on hundreds of hours of recorded interactions between seasoned scam baiters and fraudsters, allowing them to navigate complex conversations and actively solicit critical details.
When interacting with scammers, the bots function as active honeypots. They bait cybercriminals into revealing the infrastructure behind their operations:
This data is fed directly to major banks across the UK, Europe, Australia, South Africa, and South East Asia, allowing financial institutions to block suspicious accounts and freeze transactions before harm occurs.
Apate is not alone in using conversational AI to combat fraud. In the UK, telecommunications giant O2 previously launched "Daisy," an AI Granny persona designed to frustrate scammers by endlessly rambling about her 28 cats and mishearing instructions.
As cybercriminals increasingly deploy AI bots to automate text phishing—with an estimated 20% to 30% of scam messages already utilising AI—a fundamental question arises: What happens when defence AI bots meet offensive AI bots?
According to game theory models studied by researchers, the advantage firmly lies with the defenders. In an AI-versus-AI matchup:
Because the defensive model never yields real money or credentials, the scammer's AI is forced into revealing more of its underlying script, prompts, and infrastructure to overcome the impasse. Mathematically and strategically, the defender inherently wins the game.
By shifting from passive protection to aggressive, automated deception, platforms like Apate are rebalancing the cybersecurity equation. Making scamming unprofitably slow and exposing cybercriminal infrastructure in real time ensures that the good guys stay one step ahead.
Disclaimer: This article is provided for informational purposes only, mistakes may be made, and it's not offered or intended to be used as legal, tax, investment, financial, or any other advice.
