AI Social Engineering: Attacks Now Span Every Channel
AI makes scams more personal and moves them across email, chat, and video. See the Arup deepfake case and the verification rules that hold up.
AI makes scams more personal and moves them across email, chat, and video. See the Arup deepfake case and the verification rules that hold up.
AI has changed cyber risk in two ways: precision and reach. Attacks now match your role, tone, and timing. They also move across email, chat, and video inside one conversation. Spelling errors no longer give them away. Defenders need new habits: check the context, verify through a second channel, and report fast.
Table of Contents
ToggleFor years, training taught one simple tell: bad grammar. Scam emails had typos, odd phrasing, and clumsy layouts, so staff learned to look for them. Then AI removed that tell, and AI social engineering now reads like a real colleague wrote it. A model now writes clean, natural prose in seconds, and it copies the tone of a real colleague.
The results are measurable. In a 2024 IEEE Access experiment, phishing emails written by GPT-4 drew 30 to 44% click-through. Generic phishing drew 19 to 28%. So polish is no longer proof of anything.
Attackers also scale. One person can now produce thousands of tailored messages in an afternoon. Each one can mention a real project, a real manager, or a real deadline. That is why phishing attacks stay so successful, even against careful staff.
Old phishing was a single email. Modern attacks are conversations. An attack might start with an email that looks routine. Then a chat message follows, asking for a quick favor. Finally, a “verification” call arrives on a Friday afternoon, when people want to finish and leave.
Each step borrows trust from the last. A person who ignores the first email may act on the third contact, because it feels like a real exchange. Meanwhile, most security tools watch one channel at a time. The email gateway sees the email. The chat platform sees the chat. Nobody sees the whole chain except the target.
That makes people the only sensor that spans every channel. It also explains why assessing human behavior across email, calls, and social platforms matters more than email tests alone.
Discover how Threatcop protects your workforce from modern cyber threats.
The Arup case shows where this leads. In January 2024, a finance employee at the engineering firm’s Hong Kong office received a message about a confidential transaction. It appeared to come from the UK-based chief financial officer. The employee was suspicious at first.
Then the attackers moved the conversation to a video call. On screen were the CFO and several colleagues. All of them were deepfakes. Reassured by familiar faces and voices, the employee made 15 transfers worth about HK$200 million, or US$25.6 million, to five bank accounts.
The fraud came to light only when the employee checked with the company’s UK head office. Arup later confirmed to Fortune that fake voices and images were used, and that its systems were not breached. Nothing was hacked. A person was persuaded. This is the pattern behind modern deepfake scams.
If wording no longer helps against deepfake and multichannel attacks, what does? Context does. Instead of asking “does this message look right?”, ask “does this request fit?” Three questions help:
Watch for a mix of urgency and secrecy, since real business rarely needs both. When you see it, stop and verify. Changed bank details are another classic trigger. Teams that handle payments should know how invoice fraud and fake vendor scams work, because these attacks reach finance staff first.
Do not rely on spotting a fake face. Detection tools lag behind generators, and people are poor at it. Rely on process instead. A good rule works even when the fake is perfect.
These rules take minutes to write and cost almost nothing. However, they only work if leaders back them. If a senior executive pushes staff to skip a step, the rule must still win. They also protect against CEO fraud in every form, with or without AI.
Training that covers only email leaves multichannel attacks a way in. Attackers already use text messages, chat apps, and cloned voices, so staff should practice against each of them in a safe setting.
Start with the channels where your money and data move. For example, a good drill might begin with an email, follow with a chat message, and end with a call that asks for a payment. Staff then practice spotting the chain, not just one message. Simulate SMS and chat lures, and then add voice, because a cloned executive voice tests a different reflex than a suspicious link does. A voice phishing simulation with cloned voices lets teams rehearse the callback rule before it matters.
Measure what people do next. The best sign of progress is reporting speed, not a lower click rate. Praise near misses, so staff feel safe to speak up.
Attackers can trick software as well as people. An AI agent that reads email, moves files, or books payments can be steered by hidden text. So treat each agent like a new colleague with limited trust.
Give every agent its own credentials, and keep its access narrow. Require a human sign-off for high-risk actions such as moving money or changing permissions. Log what the agent does, so you can trace a mistake later. In short, apply the same verification rules to machines that you apply to people.
AI social engineering did not create new goals for attackers. It made the old ones faster, more personal, and harder to see. The answer is not better eyesight. It is better habits: check the context, verify through a second channel, and report at once when something feels off.
AI-powered social engineering uses AI to make scams more personal and more convincing. It includes tailored phishing, cloned voices, and deepfake video. The goal is the same as before: to persuade a person to share access or send money.
Not reliably. Deepfakes can copy faces and voices well enough to fool trained staff. So the safer approach is a process rule, such as calling back on a known number before acting on any money request.
A multichannel attack moves a single scam across several platforms. For example, it might begin with an email, continue in a chat app, and end with a phone or video call. Each step builds trust for the next one.
Use rules that do not depend on spotting the fake. Require callbacks on known numbers, two approvers for large payments, and a hold on new payees. Also make it normal to question urgent, secret requests, even from senior leaders.
Yes, but the content must change. Old advice about typos no longer helps. Training should teach context checks, verification steps, and fast reporting, and it should include voice and chat, not just email. A strong security culture makes staff willing to pause and ask.
Anjali is the Cybersecurity Manager at Kratikal, leading a team focused on strengthening security through rigorous vulnerability assessments and penetration testing. With expertise across web, network, and cloud environments, she drives strategies to safeguard clients’ critical assets while mentoring her team and staying ahead of escalating cyber threats.
Anjali is the Cybersecurity Manager at Kratikal, leading a team focused on strengthening security through rigorous vulnerability assessments and penetration testing. With expertise across web, network, and cloud environments, she drives strategies to safeguard clients’ critical assets while mentoring her team and staying ahead of escalating cyber threats.
Prompt injection turns any text an AI agent reads into a possible command. See the EchoLeak case, the lethal...
Blocking AI backfires. Learn six steps to secure AI adoption: inventory, tiers, vendor review, limited pilots, role-based training, and...
A 19,500-person study found standard phishing training barely works. See where agentic AI could help, its risks, and how...
Table of Contents
×