Social Engineering In The AI Era
What Is Social Engineering?
Social engineering attacks people, not systems. Instead of breaking the code, the attacker convinces someone to do something for them: click a link, share a password, approve a payment or give away information that should stay private. A phishing email that looks like it comes from your bank, a phone call from someone who says they work in IT, or an invoice from a supplier that does not exist are all examples of the same idea. Even the best firewall cannot help when an employee decides to trust the wrong message.
Con artists have used these methods for centuries. What has changed is the tool in the attacker’s hands: artificial intelligence.
What Has Changed?
In the past, social engineering had natural limits. Writing a convincing phishing email took time and good language skills. Copying someone’s voice was very difficult. Researching one person and building a personal attack around their life required a lot of effort. AI removes most of these barriers.
Today, a well-written email in any language, in the style of your company, can be created in seconds. If an attacker gives an AI tool someone’s LinkedIn profile, company bio and a few social media posts, it can write a message that feels surprisingly personal. Voice cloning needs even less. In a McAfee study, three seconds of audio were enough to create a clone with an 85% match to the original voice.
Work that once took a skilled attacker several hours can now be done by almost anyone in a few minutes. It also scales. Before, an attack was either mass-produced or personal. Now it can be both at the same time: ten thousand emails, and each one reads as if it was written for a single person. Spam filters that look for repeated patterns have a much harder time with messages like these.
Common AI-Powered Attacks
Spear phishing, a targeted form of phishing, used to focus mainly on senior managers because it required a lot of research. Now it is cheap enough to use against any employee. Vishing, or voice phishing, follows the same logic on the phone. A cloned voice, often of a manager or CEO, calls an employee, creates pressure and asks for a money transfer or login details. Because the voice sounds real, people trust it more than they should. In 2025, the FBI warned that criminals were using AI-generated voice messages to impersonate senior US officials.
Deepfake video calls are a newer method. In 2024, an employee of the engineering company Arup in Hong Kong joined a video call with people who looked and sounded like senior colleagues. All of them were deepfakes. The employee transferred about US$25 million to the criminals. Fake support chats and fake HR portals, often run by AI chatbots, are also becoming more common.
The IT helpdesk is a popular target as well. Imagine a call from someone who sounds exactly like a senior manager. He is stressed, locked out of his account just before an important meeting, and needs a password reset right now. The helpdesk agent resets it. But the caller was not the manager. His voice was created from a video he had posted online months earlier. In 2023, attackers reportedly gained access to MGM Resorts’ network after a short phone call to the IT helpdesk.
Why These Attacks Are Harder to Detect
Many security trainings still tell employees to look for spelling mistakes, strange formatting or general greetings such as “Dear Customer.” These signs are disappearing. Messages written by AI are clean and well formatted, and they use your real name and job title.
“Look for mistakes” was good advice for a long time, but it is no longer enough. Today, an attack can look normal, sound normal and even include correct details about your life and work. This matters, because people are still involved in around 60% of data breaches, according to Verizon’s 2025 Data Breach Investigations Report.
How to Protect Your Organization
Urgency should make you more careful, not less. Both human attackers and AI-supported attacks use time pressure more than any other trick. If a request cannot wait five minutes for a quick check, it probably should not be handled immediately.
Sensitive requests should always be confirmed through a second channel. If a message asks for money, access or passwords, do not reply in the same email thread or chat. Call the person on a number you already know, not the number given in the message.
Voices and faces can no longer be trusted on their own. If something feels a little strange, ask a question that only the real person can answer, or end the call and call back using the usual contact details.
Training is more important than many people think, but it has to be updated. AI-written phishing, cloned voices and deepfake calls should be a normal part of awareness training, not a short note on the last slide.
One simple rule covers most situations: verify first, then trust. This applies to emails, phone calls and even a message from a colleague at 6 p.m. asking for a “quick favor” that involves money.
Companies also need clear processes, for example a verified callback list for payment approvals, a shared code word between departments for urgent requests, and approval by at least two people for payments above a certain amount, without exceptions, no matter how senior the caller seems. Phishing-resistant multi-factor authentication also helps, because a stolen password alone is then not enough to log in. These measures work even when nothing feels wrong, and that matters, because AI-supported attacks are designed to feel normal.
AI did not invent social engineering. It made it cheaper, faster and more personal, and it allows attackers to do all of this at scale. What protects organizations today are strong verification habits and clear processes.
Contributed by GuestPosts.biz




Email: info@cyber-gear.com