AI Social Engineering: How Cyberattacks Scale Across Email, Voice, SMS and Video, and How Organizations Can Defend Against Them

Key takeaways
- AI social engineering combines generated text, cloned voice and deepfake video with open source intelligence so that a fraudulent request looks like routine business.
- The decisive control is verification of the requested action through a channel the requester did not choose, over any attempt to detect the synthetic media itself.
- Email opens most AI social engineering campaigns, while voice, SMS and video supply the pressure that pushes an approval through.
- Cybersecurity awareness training reduces exposure only when it changes decisions under pressure and is measured through reporting and verification behavior in preference to course completion.
- Approval workflows should assume a trusted account can be hijacked, which makes independent confirmation and two-person sign-off the minimum standard for high-risk actions.
- A cybersecurity awareness training platform that connects phishing simulation results, reported messages and public exposure data gives security leaders one view of human risk.
In 2024, a finance employee at the engineering firm Arup joined a routine video conference in Hong Kong and authorized a transfer of roughly $25 million. Every other participant on that call, including the apparent chief financial officer, was a deepfake, according to CNN's 2024 report on the Arup deepfake fraud.

AI social engineering has turned that kind of loss into a repeatable operation. Cloned voices, synthetic video and generated text now arrive through the same channels employees use to do their jobs, and each one carries an ordinary business request.
The defensive question has changed as a result. Spotting a fake is no longer the skill that decides the outcome, because the protection that holds is a verification habit that survives a correct-looking face, a familiar voice and a legitimate email address.
This guide covers:
- How AI social engineering changes the economics of manipulation and what cyberattackers gain from open source intelligence;
- Which AI social engineering cyberattack types dominate email, voice, SMS, chat and deepfake video;
- How employees can recognize AI-generated phishing without relying on grammar mistakes or visual flaws;
- Which identity, payment and approval controls hold when a trusted account has already been compromised;
- How deepfake phishing simulation tests resilience and how cybersecurity awareness training results should be measured;
- What an organization should do in the first hours after an AI social engineering cyberattack.
Every channel employees trust has become a delivery path for synthetic identity fraud. Adaptive Security rehearses email, voice, SMS and deepfake video requests inside one measured program.
What Is AI Social Engineering?
AI social engineering uses generative AI, automation and synthetic media to persuade a person to disclose information, transfer funds, grant access or take another risky action. It pairs psychological pressure with generated text, images, audio and video that make a fraudulent identity credible. According to Verizon's 2026 Data Breach Investigations Report, 62% of confirmed breaches involve a human element, which is the decision point these campaigns are built to reach.
AI does not remove the human target from social engineering. It increases the cyberattacker's speed, scale, personalization and ability to adapt while an interaction is still running.
What Does AI Social Engineering Include?
Social engineering manipulates trust, emotion or judgment to obtain an advantage. Instead of defeating a technical control directly, a cyberattacker persuades someone to open a file, reveal a code, approve a payment, reset an account or ignore a warning.
Employees are not the problem to eliminate. A well-prepared employee is the decision point that can stop an AI social engineering cyberattack before money or access moves.
The method now runs across email, phone, SMS and video at once. Cyberattackers collect public details about a target's role, colleagues, interests and communication habits, build a credible pretext from that material and then automate the request.
Key techniques include:
- Open source intelligence (OSINT): Information collected from public sources such as company websites, professional profiles, conference videos, social media and public filings, used to personalize messages and identify reporting lines and high-value workflows;
- Phishing: A fraudulent message designed to make a recipient click a link, open an attachment, disclose credentials or provide sensitive information, now written without the awkward grammar and translation errors that once exposed it;
- Spear phishing: A targeted version aimed at a specific person, team or organization, drafted to match the target's language, current projects and internal terminology;
- Business email compromise (BEC): A fraud scheme in which a cyberattacker impersonates an executive, supplier, customer or employee to influence a business transaction such as a wire transfer, payroll change or invoice payment;
- Vishing: Voice-based phishing delivered through a phone call or voice message, strengthened by cloning that reproduces a person's vocal characteristics closely enough to sound familiar;
- Smishing: Phishing delivered through SMS or another text-messaging service, often directing an employee to a fake login page or a fraudulent support number;
- Deepfake: Synthetic or manipulated audio, video or imagery depicting a real person saying or doing something that did not occur, which adds authority to a fraudulent request;
- AI voice cloning: Machine-learning generation of speech resembling a specific person, which makes voice similarity useless as proof of identity.
The FBI 2024 warning on generative AI-enabled fraud identifies generated text, images, audio and video as tools criminals use for social engineering, spear phishing, impersonation and financial fraud. The advisory tells recipients to verify callers through independently sourced phone numbers and to treat a familiar voice or video appearance as insufficient authentication.
That guidance moves the defensive burden away from spotting visual glitches, unnatural wording or suspicious domains. Employees need to rehearse the decision that matters, which is stopping an urgent request, checking it through a second channel and reporting it before money, credentials or data move.
How Does AI Social Engineering Change the Economics of Manipulation?
AI collapses the time required to create convincing content. A criminal no longer needs advanced writing skills, fluent language ability, professional design capability or a team of impersonators to run a plausible campaign, because one operator can generate message variations, translate them, adjust tone by recipient and hold a live conversation.
Traditional social engineering forced a choice between scale and personalization. A mass email reached thousands of people with generic language, while a personalized spear-phishing message required reconnaissance and manual drafting that limited the target count.
Generative AI narrows that tradeoff by producing individualized messages from OSINT at a volume that previously demanded a coordinated operation. It also improves adaptation: a questioned payment request produces a more credible explanation, a request for confirmation produces an imitation of a manager's writing style, and a blocked domain produces new domains, identities and message variants.
The financial consequence is already visible in national reporting. According to the FBI Internet Crime Complaint Center's 2025 Internet Crime Report, internet crime drove $20.877 billion in reported losses, a 26% jump over the prior year ($16.6 billion in 2024).
The 2025 National Cyber Security Centre assessment states that AI will make elements of cyber intrusion more effective and efficient, increasing the frequency and intensity of cyber threats. Paul Chichester, NCSC director of operations, said AI is "transforming the cyber threat landscape, expanding attack surfaces, increasing the volume of threats, and accelerating malicious capabilities."
Because the messages change constantly, they are less likely to match yesterday's detection rule. Organizations should therefore build controls around high-impact decisions and stop expecting employees to become forensic analysts.
Require out-of-band confirmation for new payment instructions, executive requests and credential changes. Separate approval duties for large transfers, publish a clear reporting route and reinforce that pausing an unusual request is correct behavior even when it appears to come from a senior leader.
Which Human Decisions Does AI Social Engineering Target?
AI social engineering succeeds when a person makes a reasonable decision from incomplete or manipulated evidence. The cyberattacker rarely needs the victim to believe an entire story, because the objective is usually one small action such as replying to a message, sharing an authentication code or approving a vendor change.
The most targeted decisions include:
- Whether to trust an identity. A familiar name, face or voice can trigger automatic trust, so employees should confirm identity through a known channel whenever a request involves money, access or sensitive information.
- Whether to act under urgency. Cyberattackers frame delay as costly or dangerous, which makes pressure a reason to pause rather than evidence that a request is legitimate.
- Whether to follow authority. A request carrying the apparent authority of a CEO, customer, regulator or law enforcement official can suppress normal skepticism, so policy should give employees explicit permission to challenge high-status requests.
- Whether to protect confidentiality. Requests for payroll records, customer data, credentials or internal documents often arrive framed as routine, and data-sharing rules should state what can be sent, to whom and through which approved system.
- Whether to report a concern. Employees continue risky interactions when they fear raising a false alarm, so a low-friction reporting process with nonpunitive follow-up converts uncertainty into an early warning signal.
A 2024 Senate security notice described an AI impersonation of Ukraine's former foreign minister during a video call with U.S. Sen. Ben Cardin. The impersonator asked politically charged questions and pressed for answers, and Cardin ended the call and alerted authorities after noticing that the conversation did not match the real official's expected behavior, as reported by NBC News in 2024.
The lesson is narrower than the claim that people can always detect a deepfake. Identity, context and requested action have to be evaluated together, because any one of them can be manufactured.
The underlying manipulation predates generative AI. Confidence schemes and advance fee fraud also relied on an invented relationship, a persuasive story and a request for action, and AI-enabled campaigns follow the same psychological sequence of trust, pressure, narrowed choices and compliance.
Teach employees to slow down before a high-risk action, confirm through a separate channel and report the attempt. Those habits matter most when several channels are combined to make a fraudulent request feel routine.
A cloned voice and a correct email address can satisfy every trust cue an employee has been taught to check. Adaptive Security trains the verification decision instead.
How Does AI Make Social Engineering More Convincing and Scalable?
AI social engineering turns scattered public information into a coordinated cyberattack that looks personal, sounds familiar and answers resistance in real time. Poor grammar, unusual timing and a single suspicious message no longer function as reliable warning signs. Controlled research and documented incidents both show how the same impersonation model moves from written communication into live video and sensitive conversation.
How Does AI Reconnaissance Build a Target Profile?
AI reconnaissance begins with open source intelligence, the collection and analysis of publicly available information about a person and an organization. Cyberattackers scrape social media profiles, job postings, company blogs, public databases, conference videos and employee photos to assemble a working map of the business.
Data exposed in previous breaches adds email addresses, phone numbers, passwords, job titles and records that indicate which employees are likely to respond. The goal is to understand how work gets done, since a name alone rarely supports a credible pretext.
A model can connect a job posting that mentions Microsoft 365, Workday, Salesforce or a payroll provider with an employee's public role and the company's reporting structure. It can infer which vendor handles invoices, which executive oversees finance, who manages payroll and which IT team owns identity systems.
Public photographs can reveal a badge design, an office location or a conference-room background, while breach data supplies personal contact details for reaching the same target outside corporate email. This profiling maps the approval paths a cyberattacker can exploit: who authorizes payments, who resets accounts and who reports to whom.
AI compresses that work by summarizing thousands of records and ranking targets by likely value. Finance, HR and IT employees receive priority because they can authorize payments, change employee records, reset accounts or grant access, while assistants and coordinators provide entry to calendars, documents and internal procedures.
The 2023 IBM X-Force phishing research described the same pattern in a controlled exercise. Researchers used OSINT from LinkedIn, a company blog and Glassdoor to identify an employee wellness program, the person responsible for it and recent organizational developments before generating a tailored message.
Ordinary public details were enough to create a credible reason for contact. Security teams therefore need to treat public exposure as an organizational signal that carries no blame, audit executive and high-impact profiles, remove unnecessary detail from job postings and monitor breach exposure.
How Does AI Generate and Deliver More Persuasive Cyberattacks?
Once a target profile exists, generative AI produces content and tunes it to the victim's environment. It can mimic writing style, sentence length, punctuation, greeting habits and preferred formality after analyzing public posts or previous messages, so a request from a terse chief financial officer reads differently from one written by a conversational project manager.
Translation and localization extend the same campaign across a global workforce, preserving regional expressions, currencies, time zones and business conventions. AI translation removes the awkward phrasing that once exposed many fraudulent messages.
A single narrative can therefore run in New York, London and Singapore with different deadlines, spellings and payment references. The model can also rewrite an invoice request after a target questions the payment details, generate a fake policy notification for an HR audience or produce an attachment that appears to automate a routine business task.
Payloads increasingly hide in formats employees do not associate with executables, including SVG files that render an image while carrying script-based content when opened by vulnerable software. The speed difference behind all of this is stark.
In the 2023 IBM X-Force controlled test, five simple prompts produced a credible phishing email in five minutes, compared with about 16 hours for an experienced social engineer working manually. IBM found that the generated message nearly matched the human-created version, which lowers the cost of testing multiple narratives, audiences and delivery channels.
Delivery has also moved beyond a single email account. Cyberattackers build long-term impersonation accounts that publish posts, reply to comments and develop relationships over weeks, so a fake recruiter can engage a developer before sending a document and a false vendor representative can comment on company announcements before requesting a bank-account update.
The same campaign then shifts between email, SMS, voice and video. An email announces a confidential project, a text confirms a meeting and a cloned voice delivers the final instruction.
Confirm payment changes, credential requests and sensitive disclosures through a channel already on file, never through a number, link or contact supplied by the requester. Cybersecurity awareness training has to rehearse that decision in context, because accurate company details, polished language and a familiar tone are now table stakes for a fraudulent message.
How Do Adaptive Conversations and Autonomous AI Agents Change the Cyberattack?
Conversational systems make AI social engineering dynamic where it was once scripted. A cyberattacker no longer sends one message and waits for a click, because an AI system can read the reply, classify the objection and generate the next response.
A question about payment authorization triggers an explanation about a supposed deadline, a request for a callback produces a calendar invitation, and a refusal prompts a softer request for a document that reveals the target's workflow. This adaptive behavior exploits normal workplace politeness.
Employees often explain why they cannot complete a request, name the correct approver or suggest another contact, and each response hands over more information about reporting lines, controls and timing. The system can then raise urgency or introduce a second impersonated person so the story appears independently confirmed.
Autonomous AI agents extend the same logic to the whole operation. One agent collects OSINT, another maps reporting lines, a third drafts localized messages and a fourth manages replies or schedules calls.
An orchestration layer selects high-value targets, launches content across email and social platforms, records which pretexts generate responses and revises the campaign with limited human direction. That capability makes annual cybersecurity awareness training cycles inadequate on their own.
Security leaders need continuous, role-specific practice across every channel employees use, paired with clear approval and reporting procedures. Employees remain the decisive control because they can challenge an unusual request, pause a transaction and report the signal that automated systems miss.
Public job postings, conference videos and breach data give cyberattackers a working map of who approves what. Adaptive Security runs OSINT-informed phishing simulations against that same exposure.
What Types of AI Social Engineering Cyberattacks Are Most Common?

AI social engineering cyberattacks are distinguished less by the technology behind them than by the trust they manufacture and the action they demand. Email creates a written pretext, while vishing, smishing, chat and deepfake video add familiar voices, urgent messages and credible faces. Generated phishing scales broadly, whereas personalized spear phishing, business email compromise and vendor fraud target named individuals using details gathered through OSINT.
Voice and video raise the emotional pressure, especially when they seem to confirm an earlier email. Effective defense matches each mechanism to a verification control that slows high-risk decisions without treating employees as the failure point.
Email and BEC Cyberattacks
Email remains the opening move because it creates a credible record, names the requested transaction and gives the cyberattacker time to build context. Generative AI produces fluent messages at scale, strips the spelling errors that once exposed a scam and tailors wording to a recipient's role, industry and current projects.
According to the FBI Internet Crime Complaint Center's 2025 Internet Crime Report, phishing and spoofing generated 191,561 complaints, the highest number of reports in any category. Personalized spear phishing narrows the same approach to one employee or team.
A cyberattacker can use public job titles, conference appearances, company announcements and exposed email addresses to imitate a supplier, recruiter, attorney or executive. The requested action is usually credential entry, document access, payment approval or disclosure of internal information.
Warning signals include a request that bypasses normal workflow, a new reply-to address, pressure to keep the matter confidential and instructions to use a new payment account. BEC and invoice fraud carry the greatest financial risk because the sender already holds authority in the recipient's mind.
The table below maps each email-borne technique to its target, its warning signals and the verification control that interrupts it.
| Cyberattack type | Typical target and requested action | Warning signals | Best verification control |
|---|---|---|---|
| AI-generated phishing email | Broad employee population. Credential entry, malware download or data disclosure | Polished language, unexpected login prompt, mismatched domain or urgent deadline | Open the service through a known bookmark and report the message through the approved channel |
| Personalized spear phishing | Employees with access to sensitive projects. Document sharing, credentials or confidential data | References to public details, active projects or recent events the sender should not know | Verify the sender through an independently sourced contact method |
| BEC | Executives, assistants and finance staff. Wire transfer, gift cards or payroll changes | Secrecy, urgency, unusual tone or a request to ignore established approval steps | Require two-person approval and confirm account changes by voice using a known number |
| Invoice or vendor-change fraud | Accounts payable, procurement and vendors. Payment to a new account | New banking details, altered invoice, reply-chain manipulation or last-minute change | Confirm the change with the vendor using previously verified contact information |
| Credential theft | Employees with access to email, cloud applications or identity systems. Username, password or session token | Login page reached through a message, QR code or shortened link | Navigate directly to the application, use phishing-resistant MFA and report the message |
A verification process has to be specific enough to use under pressure. "Be careful" tells an accounts-payable employee nothing at 4:55 p.m., so the rule should require independent confirmation, dual authorization for account changes and a mandatory pause whenever a request alters payment details.
Voice, SMS and Chat Cyberattacks
Voice and messaging cyberattacks close the trust gap that email leaves open. Vishing uses a phone conversation to apply pressure, while smishing uses SMS or a messaging app to deliver a link, request a code or continue an existing fraud.
Voice cloning makes the caller sound like a manager, family member or business partner, yet the requested action remains the reliable signal. A cloned executive voice can instruct an employee to approve a transfer, share a one-time passcode or join a private call.
A purported kidnapping call uses the same mechanism against a family member, replacing corporate authority with panic. The strongest response is to reach the person through a pre-agreed, independently verified channel before money or sensitive information changes hands.
SMS and messaging-app scams often begin with a short, familiar line such as "Are you free?" or "I changed my number." The conversation then moves toward an urgent payment, an authentication code or a fake support page.
Warning signals include a new number, a request to move platforms, a demand for a password or code and a support interaction that starts outside the application's normal help center. An out-of-band check that avoids the compromised channel entirely answers all of them.
Call an executive through the number in the corporate directory, contact a family member through a pre-agreed second number and disclose no password or MFA code to a caller. A short family or workplace safe word adds a barrier, though it never replaces account controls, payment approvals or incident reporting.
Deepfake Video and Blended Cyberattack Chains
Deepfake video cyberattacks exploit the expectation that seeing a person verifies identity. According to Sumsub's 2025-2026 Identity Fraud Report, deepfake attacks with sophisticated fraud surged 180% YoY including deepfakes, synthetics, and telemetry tampering.
The Arup case described at the start of this guide followed exactly that pattern, and the intended action was a wire transfer that independent confirmation would have interrupted. A transaction rule stating that no video call can override payment controls addresses the same risk directly.
Cyberattackers increasingly blend channels in preference to relying on one credible artifact. An email from a CFO requests an urgent payment, a cloned voice confirms it by phone and a deepfake video meeting supplies visual reassurance, yet all three can originate from the same operator.
Finance and executive-assistant teams face this chain because they can authorize or initiate payments. HR teams meet it through fake payroll, benefits and recruiting requests, while vendors and business partners meet it through account changes and fraudulent procurement instructions.
Synthetic social profiles support every stage. A cyberattacker can build a plausible profile for a recruiter, consultant, supplier or executive, populate it with copied photographs and posts, then use that identity to open a conversation before sending an email or placing a call.
The Zelensky deepfake showed the same risk at national scale. A video purporting to show Ukrainian President Volodymyr Zelensky urging troops to surrender circulated in 2022 and was identified as fabricated in Reuters' 2022 fact check.
The practical classification is simple. If a request changes money, access, identity data or public behavior, verify it independently even when the email is polished, the voice is familiar and every face on the call appears real.
Blended chains make one cyberattacker look like three independent confirmations arriving by email, phone and video. Adaptive Security builds deepfake, vishing and smishing scenarios that teach cross-channel verification.
How Can People Recognize AI-Generated Phishing, Impersonation and Scam Messages?
Recognizing AI social engineering in an inbox depends on evaluating the request, the pressure surrounding it and the verification path available, rather than judging grammar or visual polish. Employees should pause before acting, identify the psychological trigger, confirm the person and the request through a separate channel, and apply normal approval controls even when the message appears to come from a familiar executive. A credible voice or video proves only that a communication occurred, and it establishes nothing about the speaker's identity or the legitimacy of the instructions.
1. Stop Relying on Old Phishing Clues
Traditional phishing awareness focused on misspellings, awkward formatting, suspicious domains and generic greetings. Those signals still carry some weight, though generative AI now produces polished, localized and brand-consistent messages that copy an executive's tone, reproduce internal terminology and adapt to the recipient's language.
A grammatically perfect message can still be a cyberattack. The stronger test is request integrity, which asks what the sender wants, why the request arrived now, whether the action fits the sender's role and whether it bypasses a known process.
A CFO requesting an urgent wire transfer through a new bank account is suspicious because the payment details and workflow changed, and the absence of a typo is irrelevant. Credential theft follows the same logic, and according to Verizon's 2026 Data Breach Investigations Report, stolen credentials were involved in 13% of all breaches.
AI social engineering typically exploits one or more psychological triggers:
- Fear: A warning about account closure, legal exposure or an active incident pushes the recipient toward immediate compliance, so contact the supposed sender through a known channel before opening a link or moving funds;
- Urgency: A tight deadline suppresses deliberation, which makes "within 10 minutes" or "before close of business" a reason to slow down and follow the standard approval process;
- Curiosity: A confidential acquisition, payroll file or unexpected document invites a click, so confirm the context with the project owner before opening an attachment;
- Authority: The sender presents as a CEO, regulator, attorney or security leader, and the instruction should be verified with a second person outside the original conversation;
- Trust: Familiar branding, internal vocabulary and a known signature create comfort, so check the request against an independent record such as the vendor master or approved purchase order;
- Liking: Friendly language, shared interests or personal familiarity reduces skepticism, and the verification standard should stay identical for a trusted colleague or executive;
- Reciprocity: The sender offers help, a favor or access in exchange for an action, so separate the helpful gesture from the requested behavior and verify both;
- Commitment: After a recipient replies "yes," the cyberattacker escalates, which means every new step deserves reassessment, since an earlier agreement grants no authority over later ones;
- Social proof: Claims that another department already complied create pressure to conform, so confirm approval in the official workflow and disregard a forwarded screenshot;
- Helpfulness: An employee wants to resolve an incident or assist a leader quickly, and that instinct should be channeled into reporting the request for validation;
- Action bias: Acting immediately feels safer than waiting, so pausing and reporting must be the defined requirement when a request involves money, credentials, sensitive data or access.
This approach protects employees from being judged on whether they noticed a subtle visual clue. This test gives employees a repeatable decision process that still works when a generated message looks exactly like something the organization would send.
2. Apply a Human Verification Checklist
A practical checklist converts suspicion into a controlled action. Employees should not try to prove a message is fake through intuition, and the better sequence is to identify the risk signal, stop the requested action and move verification outside the cyberattacker's chosen channel.
Check the sender identity first. Inspect the complete address, phone number or account handle, while treating a matching display name, caller ID or profile photo as decoration with no authentication value.
If the sender is unfamiliar, reach the organization or person through a directory entry, a previously saved number or an official website. Contact details supplied inside the suspicious message are part of the cyberattack.
Check the requested action next. Unusual payment instructions, changed bank details, credential resets, multifactor authentication codes, gift-card purchases, payroll changes and requests for confidential files all require independent confirmation.
Replying to ask "Did you send this?" fails because the cyberattacker controls the conversation. Open a new message, place a call to a known number or use the organization's protected collaboration channel.
Check the context. AI social engineering frequently makes a request almost, though not quite, right: the project name is accurate while the deadline is unusual, the invoice belongs to a real vendor while the bank account differs, or the executive knows the deal but writes from a personal account.
Treat a mismatch in timing, channel, authority or process as a verification trigger. Check for cross-channel confirmation as well, because a cyberattacker may send an email, follow with an SMS and call from a convincing number to manufacture an agreement.
Multiple channels do not equal independent confirmation when one operator coordinates them. Verify through a channel the requester did not initiate, and require a second approver for high-impact actions.
The 2024 FBI advisory on criminal use of artificial intelligence emphasizes independently verifying identities and requests through trusted contact information. Check the consequence of delay last, since a legitimate emergency still has an accountable owner, a documented process and a safe way to confirm instructions.
If the sender demands secrecy, discourages escalation or insists that normal controls be bypassed, stop and report the request. Security teams can then preserve the message, block related indicators and warn other employees before a second target responds.
3. Use Challenge Phrases and Out-of-Band Confirmation
Voice and video confirmation deserve a higher standard because a face and a voice no longer establish identity. A cloned voice can answer questions, mimic hesitation and repeat details gathered from public recordings, while a deepfake video can create the appearance of a live meeting in which every participant is synthetic.
Establish a pre-agreed challenge phrase for high-risk communications. The phrase must be selected privately, stored in an approved password manager or other protected system, and changed once exposed.
It should never travel in the same email, chat or call that requires verification. Ask for it only when the request involves money, credentials, sensitive data, privileged access or an exception to policy.
A challenge phrase works only alongside an independent path. Call back using a number from the corporate directory or an existing contact record, and use a protected communication channel that the requester did not initiate.
For finance and payroll actions, confirm the details in the approved enterprise system and require two-person approval. For sensitive executive requests, confirm in person when practical or ask a trusted assistant or department leader to validate the instruction separately.
Do not reveal the correct phrase after an incorrect answer. End the interaction, preserve the evidence and report it through the organization's established channel, and treat any claim that an emergency prevents verification as part of the pressure tactic.
Employees judged on whether they spotted a typo will always lose to generated messages that contain none. Adaptive Security drills the verification sequence that survives a technically flawless fake.
How Can Cybersecurity Awareness Training Protect Organizations Against AI Social Engineering?
Modern cybersecurity awareness training has to prepare employees to verify identity and intent wherever a request arrives. Protecting against AI social engineering also requires layered technical controls that make trust verifiable rather than assumed. Identity systems, email authentication, AI usage governance, endpoint telemetry and detection tooling each carry part of the load, and each has a limit that practiced human judgment has to cover.
1. Strengthen Identity and Communication Controls
Identity controls have to make impersonation harder before a cyberattacker reaches an employee. Require phishing-resistant multifactor authentication based on FIDO2 security keys or passkeys for administrators, executives, finance staff and other high-impact roles.
These methods bind authentication to the legitimate site or device, unlike one-time codes that can be captured through a fake login page or extracted during a live conversation. Use a password manager across the organization to generate unique credentials and prevent reuse across business and personal accounts.
Enforce single sign-on where practical, remove dormant accounts quickly and review privileged access after every role change. Apply least privilege as well, separating the ability to create a vendor from the ability to approve a payment, and separating the ability to read sensitive data from the ability to export it.
Email controls need to examine more than grammar and sender reputation. Configure SPF, DKIM and DMARC to reduce domain spoofing, then combine authentication checks with attachment scanning, URL analysis, lookalike-domain detection and display-name inspection.
Filtering cuts the volume of malicious messages, though it cannot catch a legitimate executive account that a cyberattacker has taken over. Protect communication channels with known-good directories, verified callback numbers and approved collaboration spaces so employees retrieve a phone number from the company directory, never from the message requesting action.
Reporting must lead to fast action. A reporting button must route suspicious messages into a triage workflow that classifies the message, removes confirmed malicious copies and assigns targeted follow-up cybersecurity awareness training.
Connect the phishing response and phish triage program to the same identity and risk data used for training, so repeated risky behavior receives focused coaching in place of another generic annual module.
2. Govern AI Tools, Browsers and Endpoints

Employee AI use has become an AI social engineering exposure in its own right. According to the National Cybersecurity Alliance's 2025-2026 Oh Behave! The Annual Cybersecurity Attitudes and Behaviors Report, 52% of employed participants reported they have not received any training on the security or privacy risks of AI tools, despite 65% now using AI and 43% admitting to sharing sensitive work information with AI tools.
Material pasted into an unapproved assistant can resurface as the personalization inside a later spear-phishing message. Browser and chatbot controls therefore have to cover the paths that generative tools create.
Restrict unapproved browser extensions, block downloads from suspicious domains and warn users before they paste confidential information into public AI tools. Establish approved use cases, prohibit sensitive data in consumer accounts and log high-risk activity for review.
Banning every AI tool without offering an approved path drives use underground. A governed path gives employees a safer way to complete legitimate work while producing the visibility security teams need.
Endpoint controls remain useful, though their role is narrow. Endpoint detection can identify malicious files, suspicious processes, token theft and unusual device behavior after a user interacts with a cyberattack.
It cannot determine whether a synthetic voice persuaded the user during an otherwise clean phone call, whether a manipulated video appeared in a legitimate meeting or whether a generated request reflects a real business decision. Pair endpoint telemetry with transaction context and human reporting, because the device cannot interpret intent on its own.
3. Combine Detection, Provenance and Human Judgment
Detection controls need to analyze behavior across identity, email, browser, endpoint and business systems. Behavioral analysis can flag impossible travel, an unusual payment beneficiary, a sudden mailbox-rule change or a login followed by abnormal data access, while natural-language processing can identify shifts in tone, urgency, payment language and requests for secrecy.
Generated text removes the spelling and grammar errors that once alerted employees, so these behavioral signals carry more weight than they used to. They are leads rather than verdicts, because a legitimate executive can make an unusual request and a real compromise can resemble normal activity.
Tune thresholds with business owners, route high-confidence cases to automated containment and send ambiguous cases to human review. Record why an alert fired so analysts can adjust rules without creating hidden friction for employees.
Synthetic voice and manipulated video require a different expectation. Audio and video detectors look for irregular facial movement, inconsistent lighting, unnatural timing, spectral anomalies or mismatches between speech and visible motion, while text classifiers examine linguistic patterns and metadata.
Cyberattackers can compress, crop, regenerate or relay media through another device and change those signals. False positives interrupt legitimate meetings, and false negatives create dangerous confidence.
Content provenance adds another signal. The 2025 NSA Cybersecurity Information Sheet Strengthening Multimedia Integrity in the Generative AI Era, published with partner agencies in Australia, Canada and the United Kingdom, explains that cryptographically signed credentials become invalid when signed media is altered.
Provenance still does not establish that the person depicted approved the request or that an unsigned file is fake. Treat credentials, signatures and watermarks as evidence inside a broader decision process, and never as guarantees.
The final control is the practice of human judgment. Give employees a simple escalation path, rehearse payment verification and run realistic email, vishing, smishing and deepfake phishing simulations for the roles most exposed to financial or privileged actions.
Filters tuned for known patterns will keep passing novel AI-written messages to the inbox. Adaptive Security layers AI-native email detection on Microsoft and Google without MX changes.
How Should Organizations Test AI Social Engineering Resilience With Deepfake Phishing Simulation?
Deepfake phishing simulation and broader AI social engineering exercises should measure whether employees pause, verify and report across email, SMS, messaging apps, phone calls and video conferences. Ethical guardrails come first, followed by role-based scenarios, separate measurement of susceptibility and reporting, and difficulty that rises only when teams are ready. Realism matters, though consent, privacy, psychological safety and local law set the boundaries of every exercise.
1. Design the Phishing Simulation and Establish Governance
Begin with a written exercise charter that identifies the security owner, participating departments, approved channels, scenario types, data collected, retention period and escalation contacts. Obtain approval from security leadership, HR, legal and, where required, works councils or employee representatives before launch.
State clearly that the exercise evaluates organizational defenses and builds employee skill. Define stop conditions before anyone receives a message.
Pause the exercise if an employee reports acute distress, a real payment or account change begins, a customer or external vendor becomes involved, a message reaches an unintended audience or the phishing simulation intersects with an active incident. Finance exercises must never create actual payment instructions, alter vendor records or pressure employees to bypass established controls, so use inert links, test accounts and isolated infrastructure.
Scope scenarios around job responsibilities and business events:
- Finance: Rehearse vendor-change requests, invoice fraud and urgent wire instructions;
- Procurement: Verify altered banking details through an independently sourced contact;
- HR: Challenge requests for payroll data or employee records;
- Executives: Confirm sensitive requests that appear to come from the CEO or board;
- Customer support: Identify account-takeover pretexts;
- Administrators: Verify password-reset and privileged-access requests.
Use OSINT only to improve scenario relevance and only within approved boundaries. Public job titles, departments, speaking engagements and company announcements can inform spear-phishing themes, while private addresses, family details, health information and unrelated social activity stay out of scope.
Document the data used to construct each scenario and minimize it once the exercise closes. A practical baseline records four separate outcomes: whether a person engaged with the lure, whether they submitted information or attempted an action, whether they reported it and how quickly.
Susceptibility and reporting are not opposites. An employee can open a suspicious message, recognize the risk and still demonstrate valuable defensive behavior by reporting it promptly, so report those signals separately and let managers target coaching without punishing honest engagement.
2. Build Cross-Channel and Event-Driven Scenarios
Test one channel at a time before combining channels. A generated email can imitate a familiar executive style and request a confidential document, while a smishing simulation can claim that a mobile device requires immediate identity verification.
A vishing simulation can use a synthetic voice to confirm an invoice or request a password reset. Messaging-app exercises can imitate a colleague whose account appears compromised, and a video scenario can depict an executive approving an unusual transfer.
The most valuable exercises reflect how real fraud unfolds. A blended email-and-call sequence might open with a generated message from a supposed supplier, followed 10 minutes later by a phone call from someone claiming to be the supplier's finance director.
The caller reinforces urgency, repeats details from the email and asks the employee to bypass the normal callback process. The correct behavior is to stop the transaction and verify through a trusted channel sourced independently of the request, and determining whether the voice is synthetic is beside the point.
Video exercises require the highest threshold of care. The Arup fraud should translate into a controlled rehearsal of payment verification rather than a surprise imitation of a real executive during a live business meeting.
Give employees practice at questioning unusual requests, checking meeting context and reaching the executive through a known number. The Cardin call carries the parallel lesson for senior leaders, since a familiar face and voice do not replace identity verification when a conversation introduces political pressure, secrecy or an unexpected demand.
Randomize timing, senders, wording, devices and paths so employees learn decision rules in preference to memorizing templates. Begin with clear warning signals such as an unusual payment request or a mismatched domain, then progress to polished language, accurate organizational details, multilingual messages and coordinated voice or video follow-ups.
Test supported languages with native-speaker review, and never penalize employees for a translation defect created by the exercise. Run low-volume exercises monthly or quarterly, with additional event-driven tests before acquisitions, major system migrations, tax deadlines, executive travel, payroll changes and high-value procurement cycles.
Avoid predictable schedules. Repetition should build recognition and reporting habits without turning the workplace into a constant trap, and a multi-channel phishing simulation program can centralize these exercises while preserving separate outcomes for email, voice, SMS and video.
3. Protect Privacy, Dignity and Employee Safety
Collect the minimum data required to answer the exercise question. Phishing simulation systems do not need to retain voiceprints, facial embeddings, raw webcam footage, personal phone content or biometric identifiers to measure whether someone verified a request.
Use synthetic personas, preapproved recordings and test-only metadata wherever possible. Restrict access to individual results, set deletion deadlines and document whether local privacy, employment or biometric laws apply.
Communicate before and after the exercise at the right level. Employees need to know that the organization runs controlled social engineering tests, how to report concerns and where to obtain support, while scenario details can remain undisclosed.
Afterward, provide a private explanation, immediate coaching and a clear account of what the employee did correctly. Public dashboards must show team-level trends without names or rankings.
Results have to lead to better controls and targeted practice. If finance staff engage with invoice fraud yet report suspicious follow-up calls quickly, preserve the reporting strength and rehearse transaction verification, and if administrators ignore password-reset anomalies, assign a short scenario focused on identity checks.
Do not treat one failed interaction as evidence of incompetence. Do not tie a phishing simulation result to discipline unless a separate, documented policy violation exists outside the exercise.
The final review should ask whether the scenario was fair, whether approvals were held, whether stop conditions worked, whether the team deleted the data and whether employees understood the expected action. A program that produces fear without reliable verification behavior has exceeded its purpose.
Surprise deepfake tests that humiliate employees suppress the very reporting behavior security teams depend on. Adaptive Security runs governed multi-channel exercises that score susceptibility and reporting as separate outcomes.
How Should Organizations Measure Whether Cybersecurity Awareness Training Reduces AI Social Engineering Risk?
A cybersecurity awareness training program reduces AI social engineering risk only when it changes decisions under pressure. Completion records describe exposure to content and say nothing about whether an employee will challenge an urgent payment request from a synthetic CFO. Measurement therefore has to track reporting, verification and repeat behavior across every channel, then feed those signals back into the next intervention.
From Completion to Behavior
An eight-month randomized study of 19,500 UC San Diego Health employees found no significant relationship between recent annual training and phishing susceptibility, and embedded training reduced clicking by only 2%, according to the University of California San Diego study published in 2025. The finding does not justify abandoning employee education.
It requires security leaders to test whether education survives realistic conditions and to redesign programs when it does not. Annual instruction creates a long interval between the lesson and the decision, while generic end-user content assumes every employee faces the same cyber threat in the same way.
A modern cybersecurity awareness training program starts with a baseline. Send controlled scenarios across the channels employees actually use, then record what each person did: whether the recipient clicked, submitted credentials, opened an attachment, approved a payment workflow, answered a vishing call or reported the message.
Record whether the employee verified the request through a known phone number or an approved second channel. Those actions establish a behavioral profile that is far more useful than a completion percentage.
Instruction then follows observed behavior. An employee who reports suspicious email correctly needs reinforcement rather than another introductory module, while an employee who clicks a generated phishing email should receive short, immediate remediation explaining the missed cue and a retest using a different scenario.
Someone who shares sensitive information with an unauthorized AI tool needs data security awareness training and clear instructions on what information can be entered, where it can be stored and how to report a mistake. Role context determines which practice matters most:
- Finance teams: Business email compromise, invoice manipulation and executive impersonation;
- Executives and executive assistants: Deepfake awareness, voice verification and urgent travel or payment requests;
- Customer service and help desk teams: Vishing and identity-verification drills;
- Mobile-heavy teams: Smishing scenarios delivered to the devices those employees actually use;
- Developers and researchers: Protection of secrets, source code and confidential data;
- Managers: Insider threat awareness that distinguishes risky behavior from malicious intent and routes concerns through a defined process.
The purpose of a failed phishing test is a short learning cycle while the decision remains memorable. Employees become a stronger line of defense when the organization supplies realistic practice, clear escalation paths and feedback tied to the exact behavior being improved.
Metrics and Experimental Design
A defensible measurement model separates activity from risk. Track these signals at the employee, role and department levels:
- Report rate: The percentage of suspicious messages, calls or videos reported through the approved channel;
- Click or submission rate: The percentage of users who open a simulated lure, click a link or submit requested information;
- Time to report: The median time between delivery and employee reporting;
- Repeat susceptibility: The percentage of employees who fail more than one scenario after remediation;
- High-risk action rate: The frequency of payment approval, credential entry, sensitive-data sharing or access-granting behavior in controlled exercises;
- Verification adherence: The percentage of high-impact requests verified through an independent, trusted channel;
- Retention: Whether employees can identify and explain relevant warning signs days or weeks after instruction;
- Department-level human risk trends: The direction and distribution of risk across finance, executive operations, IT, sales and other groups.
Use rates in preference to raw totals. A department that reports 200 messages might look stronger than one that reports 40, though the comparison reverses if the first group received 10,000 scenarios and the second received 100.
Segment results by channel, scenario type, role, tenure and exposure, because a low overall click rate can conceal a serious weakness in voice verification or concentrated risk among payment approvers. Testing whether instruction changed behavior requires more than comparing one month with the previous month.
Run a pre-intervention campaign, deliver targeted cybersecurity awareness training, then run a matched post-intervention campaign of comparable difficulty. Keep the scenario theme different enough to test a transferable skill, so an employee who learned to distrust an Outlook password reset later faces a vendor invoice request, a cloned executive voice or a deepfake video meeting.
Use a control group when operationally and ethically appropriate. One group receives immediate role-specific remediation while another follows the standard schedule, and the comparison covers report rate, submission rate and verification adherence.
If random assignment is impractical, use matched departments or staggered deployment and document differences that could affect results. Report uncertainty and avoid overstating precision, showing the sample size and a 95% confidence interval for each rate.
A click rate falling from 12% to 10% across a small team might reflect normal variation. A report rate rising across thousands of employees with confidence intervals that do not materially overlap gives leadership stronger evidence that behavior changed.
As NIST computer scientist Julie Haney and University of Maryland Associate Professor Wayne Lutters concluded in their peer-reviewed analysis published in Computer (October 2020), compliance metrics do not tell the whole story and fail to measure the effectiveness of the program in a sustained change in employee attitudes and behaviors. Repeat the test across multiple campaigns, since one successful lure does not establish durable resistance.
Board-Ready Reporting and Program Value

Boards need a risk narrative tied to business exposure, and the accountability behind that request keeps rising. According to the World Economic Forum's 2026 Global Cybersecurity Outlook, 30% of highly resilient organizations reported that board members hold personal liability in the event of cyber breaches, compared with 9% of organizations with insufficient resilience.
Start with the population and the exposure surface, then show how behavior changed. A useful quarterly view includes the number of employees tested, channels covered, report rate, high-risk action rate, repeat susceptibility and median time to report, with department-level trends so directors can see where exposure is accumulating.
Translate the metrics into prevented exposure without claiming that instruction guarantees breach prevention. Report that fewer payment approvers entered credentials during phishing simulations, that more employees verified executive requests, or that the median time to report suspicious messages fell from hours to minutes.
Those outcomes connect directly to containment speed, fraud exposure and analyst workload. Directors reviewing them can then judge whether the program is closing exposure or simply generating activity.
Compare the cost of instruction, phishing simulation delivery and employee time with measurable reductions in high-risk actions, repeat failures and response delays. Track analyst hours saved when employees report suspicious messages consistently and when triage workflows classify reports quickly.
A credible report also identifies remaining exposure. If employees improve on email phishing yet fail deepfake video requests, state that gap and fund another test, and if report rates increase while verification adherence stays flat, add procedural practice in place of another awareness video.
If one department's human risk trend worsens, investigate workload, incentives, access privileges and manager reinforcement before assigning blame to employees.
Course completion tells the board nothing about whether the finance team would stop a fake executive on a Friday afternoon. Adaptive Security reports verification behavior and reporting speed instead.
What Should an Organization Do After an AI Social Engineering Cyberattack?
After an AI social engineering cyberattack, activate incident response immediately, stop additional payments or access, preserve every relevant artifact and assign one owner to coordinate security, finance, legal and communications. Work in time order: contain the active intrusion, investigate what happened, notify affected parties and change the process that failed. Recovery is uncertain, because a bank or payment provider can attempt a recall on a fraudulent transfer without any guarantee that the funds return.
1. Take Immediate Actions
The opening hour decides whether the incident stays inside one compromised account. According to the CrowdStrike 2026 Global Threat Report, the average adversary breakout time, the window between initial access and lateral movement, dropped to 29 minutes, with the fastest measured at just 27 seconds.
Open an incident record with the discovery time, reporting employee, suspected cyberattacker, affected systems, transaction amounts and immediate decisions. Preserve evidence first, and do not delete the suspicious message, block the sender, wipe a device or reset an account until the team has captured what it needs.
For payment fraud, contact the sending bank, receiving bank and payment provider through verified telephone numbers. Request an immediate recall, hold or freeze, provide the transaction reference and ask whether the receiving institution can place a fraud restriction on the funds.
A deepfake executive call, an altered invoice or a cloned voice does not make a transfer automatically recoverable, so escalate quickly while preserving the approval trail. For credential disclosure or account takeover, disable exposed credentials, revoke active sessions and refresh tokens, reset passwords from a trusted device and require new multifactor authentication enrollment where appropriate.
Contain the identity provider by disabling suspicious accounts, reviewing recent authentication events, terminating unfamiliar sessions and checking newly registered devices, applications, OAuth grants and recovery methods. If malware was delivered, isolate the endpoint from the network without powering it off unless safety or business continuity requires that action.
Investigate the delivery path while containment continues. Review the affected mailbox for inbox rules, forwarding rules, delegated access, sent messages, deleted items and unusual sign-ins, then search other mailboxes and collaboration platforms for related messages, URLs, attachments, QR codes, phone numbers and chat invitations.
Phishing response procedures can route reported messages to security analysts without destroying the original evidence. The FBI advises victims of AI-enabled financial fraud to report incidents to the Internet Crime Complaint Center with payment details, receiving institution information, contact details, the interaction history and any information provided to the criminal.
Submit an IC3 report through the channel named in the FBI advisory on generative AI-facilitated financial fraud, and contact the local field office when the loss, targeting or cyber threat warrants direct engagement. For senior-official impersonation involving smishing or vishing, the 2025 FBI advisory on impersonation of senior US officials also directs victims to IC3 or an FBI field office.
2. Preserve Evidence and Investigate the Cyberattack
Evidence preservation must begin before broad remediation. Export the original email with complete headers rather than a screenshot or forwarded copy, and preserve the message body, URLs, attachments, embedded images, QR codes, sender details and authentication results such as SPF, DKIM and DMARC.
Capture call recordings, transcripts, voicemail files, chat logs, video files, meeting invitations and associated metadata before retention periods or collaboration settings remove them. Record who received what and when.
The incident timeline must identify the initial contact, every reply, every link visit, every download, every credential or multifactor code disclosed, every approval, every bank instruction and every containment action. Collect identity provider logs, mailbox audit events, endpoint telemetry, browser history, DNS records, proxy events, payment approvals and relevant access records.
Preserve original files in read-only storage and calculate hashes when the forensic process supports them. Evidence integrity depends on a defensible chain of custody, so document the collector, collection time, source system, collection method, file name, hash and every later transfer or access for each artifact.
Limit access to the incident team, preserve a working copy for analysis and keep the original untouched. Do not open a suspicious attachment on a normal workstation, edit a transcript to improve readability or rely on a screenshot when the underlying log is available.
Privacy limits still apply. Collect only information relevant to the incident, restrict employee and customer data to authorized investigators, and follow retention, employment, contractual and cross-border data rules.
Legal counsel sets privilege boundaries and determines whether investigators can access personal devices, private accounts or recorded calls. Coordinate with IT before deleting malware, removing mailbox rules or rebuilding a device, since those actions can erase artifacts needed to identify persistence and scope.
The investigation should answer five questions:
- How did the cyberattacker establish trust?
- Which identity or payment control failed?
- What data or access was exposed?
- Did the cyberattacker maintain access?
- Which other people or organizations received the same lure?
Both the Arup wire fraud and the Cardin impersonation call show why voice and video belong in the evidence file. Neither medium should be accepted as proof of identity during an investigation, and both should be collected, hashed and timestamped like any other artifact.
3. Notify, Recover and Change the Process
Notification follows verified scope. Inform the bank, payment provider, identity provider, affected customers, vendors and employees according to the incident facts and legal advice.
Legal and compliance teams should assess contractual duties, privacy and breach-notification laws, sector rules, insurance requirements, securities obligations, and regulator or law-enforcement reporting. Tell employees what happened, which indicators to report and which verification channel to use, without assigning blame to the person who was targeted.
Recovery requires more than a password reset. Confirm that unauthorized forwarding rules, OAuth grants, delegated mailbox access, browser sessions, payment beneficiaries and recovery contacts have been removed.
Reconcile financial accounts, monitor for repeat attempts, validate endpoint integrity, restore only from trusted backups and maintain heightened logging for affected identities. Keep the incident record, forensic images and communications under the organization's retention policy.
Close the response with a blameless review that changes behavior and control design. Require independent verification for urgent payment, credential, data-release and executive requests, use previously known contact details and disregard numbers or links supplied in the message, and define an escalation path when a request crosses email, phone, SMS or video.
Convert the cyberattack pattern into role-specific instruction and controlled phishing simulations for finance, executives, help desk staff and administrators. Immediate containment stops the current intrusion, while long-term remediation ensures the next believable voice, message or deepfake meets a prepared employee and a process built to slow unsafe trust.
Deleting the message and resetting the account first destroys the evidence that fund recovery and law enforcement referrals depend on. Adaptive Security preserves every reported cyberattack through structured triage.
Which AI Social Engineering Risks Matter Most for Individuals, Small Businesses and Enterprises?
AI social engineering reaches every organization size, though the most damaging path depends on the target's resources, relationships and approval structure. Individuals face concentrated cyberattacks against personal identity, accounts and family trust, while small businesses face payment fraud routed through a handful of decision-makers. Enterprises face automated, multilingual campaigns aimed at executives, third parties, public information and complex workflows, and each group needs controls matched to its own exposure.
Individual Risk: Voice Cloning, Account Recovery and Fake Support
Individuals meet AI social engineering through relationships and recovery channels that already carry high trust. A cloned voice can imitate a family member asking for emergency money, and a fake support chatbot can request passwords, one-time codes or remote access.
Public photos, videos, social profiles, data-broker records and breached credentials supply the material for personalization. Protecting the account behind the identity matters more than detecting the cyberattack itself.
Use a password manager, phishing-resistant multifactor authentication where available and unique recovery email addresses. Establish a family verification phrase for urgent financial requests, end any call that pressures immediate payment and reach the person through a known number.
Account recovery deserves equal attention. Review recovery phone numbers, backup email addresses and active sessions quarterly, and avoid posting travel plans, children's names, birthdays or employer details that help a cyberattacker answer security questions.
When a support chatbot requests a password, a full payment-card number or an authentication code, move to the provider's verified application or website. Families should rehearse a second-channel check before an emergency creates pressure to act.
Small-Business Risk: Payment Fraud Through Trusted People
Small businesses concentrate authority, which gives impersonation a short path to money and sensitive information. According to Verizon's 2026 Data Breach Investigations Report, 96% of ransomware victims were small and medium-sized businesses (SMBs), as SMBs present unpatched devices, compromised credentials, and limited recovery capabilities.
The same structural weakness applies to fraud: an owner, bookkeeper, office manager or long-standing vendor may carry enough trust to approve an invoice without a second reviewer. Limited segregation of duties can let one person receive a request, change vendor details and release payment.
Payment controls have to match the transaction's risk. Require a callback to a verified number before changing bank details, separate invoice entry from payment approval, set approval thresholds and prohibit payment changes based on email, text or voice alone.
Require a second approver for unusual urgency, new beneficiaries, split invoices and any request involving cryptocurrency or gift cards. Owner and vendor impersonation also extends past email, and a spoofed invoice can arrive alongside a cloned voice message, a fake supplier text and a convincing video meeting.
Train employees to verify the transaction and treat the requester's identity as unproven, since a trusted person can still issue a fraudulent request once an account or likeness is compromised. Small firms also benefit from publishing less operational detail online.
Remove unnecessary direct phone numbers, internal reporting lines and staff travel schedules, and write job postings that describe responsibilities without identifying who controls payroll, vendor onboarding or executive calendars. A short written policy, a shared verification script and a quarterly payment-fraud drill give smaller teams a practical control system.
Enterprise and Sector Risk: Scale, Deepfakes and Third-Party Trust
Large enterprises face a broad threat surface. Public organizational charts, executive interviews, job postings, conference videos and supplier relationships hand a cyberattacker a ready-made map of the business.
Remote and hybrid work add ambiguity as employees collaborate across time zones, use personal devices and communicate through video, messaging and cloud applications. Automated systems can then tailor multilingual spear phishing, vishing and smishing campaigns to thousands of employees at once.
The table below matches the highest-exposure scenario in each sector to the control that deserves priority investment.
| Organization or sector | Highest-exposure scenario | Proportionate priority |
|---|---|---|
| Finance | Executive deepfake, vendor fraud or payment diversion | Dual approval, verified callbacks and finance-focused phishing simulations |
| Healthcare | Impersonated clinician, supplier or administrator seeking records or access | Out-of-band verification and strict identity checks for privileged requests |
| Government | Foreign-official impersonation, politically timed requests or sensitive-data extraction | Independent confirmation and protected executive communications |
| Education | Fake financial-aid, payroll or research requests targeting decentralized departments | Central payment rules and instruction for faculty, staff and students |
| Technology | Multilingual credential theft, software supply chain impersonation and shadow AI use | Secure development workflows, AI-use policy and rapid reporting |
| Professional services | Client, partner or senior-partner impersonation involving confidential files or transfers | Matter-specific access controls and client-request verification |
Executive communications need a defined authenticity policy. Public photos and videos should serve a clear business objective, and executives should state plainly that payment, credential and data-transfer requests always require separate confirmation through a known channel.
Organizations also need to inventory shadow AI use, because employees who paste confidential material into unapproved tools open another route for AI social engineering and data loss. Acceptable-use rules must name approved tools, prohibited data and reporting procedures.
Enterprises need centralized visibility without making every employee responsible for forensic judgment. Role-based phishing simulations should test executive impersonation, third-party requests and multilingual messages, while reporting workflows route suspicious activity to security teams quickly.
Human risk signals must guide targeted coaching for finance, executives, help desks and administrators. A human risk management program can connect exposure, behavior and remediation across these groups, and the same principle scales down: individuals secure identity and recovery, small businesses secure payment authority, and enterprises secure trust relationships between employees, vendors and the systems they use.
Match the control to the exposure, because a two-person payment rule protects a 40-person firm as effectively as a global bank. Adaptive Security scales that practice to any headcount.
How AI Social Engineering Fits Into a Modern Human Risk Program
AI social engineering belongs inside a human risk program because cyberattackers manipulate trust across email, voice, SMS, video, chat and workplace applications. A finance employee who reliably reports suspicious email can still be unprepared when an apparent executive calls with a payment request or appears in a synthetic video meeting. The program's job is to connect those separate signals into one view of exposure while keeping monitoring proportionate, transparent and focused on reducing risk.
How Do Human Risk Teams Connect AI Social Engineering Signals Across Channels?
A unified view links events that email-only programs keep apart. A failed spear-phishing exercise, a delayed report, repeated exposure in public data and risky use of an unapproved AI service each describe part of the same threat surface.
Together they can show that an employee is unusually exposed to impersonation because an executive role, public speaking footage and sensitive business access create a credible target. Continuous multichannel testing supplies the behavioral signal, phish reporting and triage supply the response signal, and OSINT exposure monitoring surfaces the information cyberattackers can use to personalize contact.
AI and shadow-IT governance adds a fourth input by identifying risky data handling, such as confidential material pasted into an unauthorized assistant. Risk scoring then turns those signals into an action queue for security, HR and business leaders.
That connection has to stay proportional. A risk score should prioritize coaching and additional verification for high-impact roles, and it should never determine employment decisions on its own.
Security teams need to document which signals affect the score, distinguish confirmed events from exercise results and provide a review path when context changes the interpretation. Human review is essential whenever several weak signals combine into a high-risk assessment.
What Privacy Principles Should Govern Defensive AI?
Defensive AI that analyzes employee communications, voices, faces or behavior requires explicit governance before deployment. The organization must define a narrow purpose, such as identifying impersonation exposure or improving security coaching, and prohibit unrelated uses such as productivity scoring or continuous personality profiling.
Purpose limitation prevents a security program from becoming a general employee-surveillance system. Data minimization then determines what the system collects and retains.
If an exercise can measure whether an employee verified a request, it does not need to keep a complete voice recording indefinitely. Access controls must separate administrators who configure exercises from investigators who review incidents, audit logs should record sensitive-data access, and retention limits should delete recordings, transcripts and behavioral details once they no longer serve a documented security purpose.
Transparency also improves employee behavior. Workers need to know which channels are tested, what data is collected, how risk scores are calculated, who can view results and how long records remain available.
Identify exercise scenarios as such afterward, with feedback that explains the signal an employee missed and the action that would have prevented escalation. Bias testing must cover language, accent, disability, communication style, job role and work arrangement.
A voice-analysis model that treats an accent as suspicious, or a behavior model that penalizes employees working unusual hours, produces unreliable risk data and unfair interventions. The NIST AI Risk Management Framework, published in 2023, places trustworthiness, privacy, fairness and accountability inside AI risk management, which makes those controls part of the security design.
Shadow AI usage, phishing simulation results and public exposure data sit in three separate consoles for most security teams. Adaptive Security scores all of them as one human risk profile.
How Can Cybersecurity Awareness Training Build Approval Workflows That Resist AI Impersonation?
AI social engineering defeats approval workflows that treat a familiar email address, voice or face as proof of identity. Effective cybersecurity awareness training teaches employees to verify the requested action before extending trust to the apparent requester. Transaction controls should assume that a trusted account can be hijacked, which means high-risk actions need independent verification gates, separated request and approval channels, and documented exceptions.
1. Identify High-Risk Actions
Inventory the actions that move money, access or sensitive information. Include payments, bank-detail changes, privileged-access grants, payroll amendments, credential resets, data releases, vendor onboarding and urgent executive requests, then rank each by financial value, reversibility, sensitivity and potential business disruption.
According to the FBI's 2025 Internet Crime Report (released April 2026), cyber-enabled fraud accounted for almost 85% of all losses reported to IC3, totaling $17.7 billion (up from $13.7 billion in 2024), and business email compromise (BEC) remains the persistent risk at the costly center, accounting for $3.046 billion in losses (24,768 incidents, averaging $123,000 per case). Those losses concentrate in a small set of repeatable actions, which is why tiering them works.
Use clear tiers so employees can act quickly without making risk decisions from scratch:
- Tier 1: Routine, low-value requests that fit an approved process and require standard authentication;
- Tier 2: Vendor changes, invoices outside normal patterns, payroll updates, credential resets and access changes that require a callback to a known contact and a second approver;
- Tier 3: Large payments, new beneficiaries, privileged access, sensitive data releases and urgent executive requests that require independent verification, two-person approval and documented evidence before execution.
The Arup transfer failed at exactly this layer. Identity appeared confirmed, and no independent control stood between a realistic meeting and an irreversible payment, which makes it a workflow failure rather than an employee failure.
2. Design Verification Gates
Every high-risk request should trigger a rule the requester cannot satisfy alone. Require a callback to a phone number already stored in the vendor master, HRIS or corporate directory, and never use contact details supplied in an email, text message or meeting invitation.
For payments and bank-detail changes, procurement and accounts-payable teams should match the invoice against the purchase order, contract, prior payment history and approved vendor record. Route bank-account changes to a separate review queue, and confirm any account change with an established vendor contact through a different channel before releasing funds.
Do not accept a new payment destination because the request includes a correct logo, a familiar signature or a plausible explanation of urgency. Separate the request channel from the approval channel as well.
An email can initiate a payment, though approval should happen inside the payment platform or an authenticated ticketing system. Set transaction limits that force escalation above defined thresholds, and require two people from separate reporting lines for Tier 3 actions.
An email and a voice call from the same compromised executive account do not constitute two forms of verification. Record the callback number used, the person contacted, the time, the verification result, the approvers and the supporting documents.
That record gives finance and security teams an audit trail while exposing repeated exception patterns. Finance employees should also be able to reject or escalate a request without executive permission when it violates policy, which converts caution from an act of disobedience into an expected control.
Urgency deserves its own gate. A request that bypasses normal process because an executive is traveling, a deal is closing or payroll is due should attract more scrutiny.
Global teams need approved callback scripts, multilingual escalation paths and an on-call verifier in each operating region so employees have a practical way to pause and confirm. Define exceptions before an incident occurs: if a verifier is unreachable, the request waits or moves to a named backup approver, no executive override erases two-person approval, and every emergency exception receives review by finance and security leadership the following business day.
3. Exercise and Improve the Workflow
Implement the program through a controlled operating sequence. Inventory high-risk actions, assign verification rules, configure transaction limits and approval routing, train each role, run multi-channel phishing simulations, review exceptions and update policies.
Instruction must show finance, procurement, HR, IT and executive teams exactly how to pause, verify and report. Test the workflow quarterly with realistic invoices, voice calls, smishing messages and deepfake video requests.
Measure callback completion, approval separation, time to report, exception volume and the percentage of simulated requests stopped before execution. Update thresholds when business operations change, vendors are added or cyberattackers exploit a new channel.
A workflow resists AI impersonation only when durable operating practice makes one convincing email, voice or video insufficient for a high-risk action. The strength of that protection depends on whether employees have rehearsed the pause before pressure turns a synthetic identity into a real transaction.
One convincing video call should never carry the authority to release a payment. Adaptive Security rehearses tiered approval and callback discipline with the teams that hold that authority.
How Adaptive Security Reduces AI Social Engineering Risk

Security and IT leaders want one answer to a question that spans several tools: would this workforce stop a fraudulent request delivered by email, voice and video together? Adaptive Security answers it by running realistic AI social engineering exercises across every channel employees use, then converting each result into targeted coaching and a single human risk score. Finance teams rehearse vendor impersonation, executives rehearse identity verification under pressure and help desk staff rehearse fake password-reset calls, all measured through reporting speed and verification adherence in place of course completion.
The same program closes the gaps that sit on either side of the employee. Cloud Email Security applies behavioral signals, intent analysis and language-model reasoning to catch generated phishing and BEC that native filters pass, then removes confirmed messages from every affected inbox and feeds the detection back into that employee's risk profile. AI Governance surfaces every AI tool and personal account in use across the browser, blocks or coaches when sensitive data heads into an unapproved assistant, and enrolls repeat offenders in focused cybersecurity awareness training automatically.
Compliance obligations are handled in the same place through Compliance Training, so mandatory coursework and behavior-change work no longer live in separate systems with separate reporting. The result is one cybersecurity awareness training platform where a detected cyberattack, a reported message, a phishing simulation outcome and an AI policy violation all describe the same person and the same exposure, which gives leaders evidence that human-layer defenses are improving.
Human-layer defense fails quietly when email detection, employee coaching and risk reporting never exchange a single signal. Adaptive Security unifies all three inside one measurable human risk program.
Frequently Asked Questions About AI Social Engineering
What Is the Biggest Risk of AI Social Engineering for Businesses?
The biggest business risk is a trusted employee approving a fraudulent payment, disclosing credentials or granting access after a cyberattacker manufactures authority across several channels at once. The 2024 FBI warning on criminals using artificial intelligence describes generated voice and video cloning used to impersonate trusted people and solicit money or sensitive information. Cyberattackers use OSINT to personalize requests aimed at finance, HR, executives and vendors, so exposure falls when organizations apply risk-tiered approvals, known-number callbacks, phishing-resistant MFA and a culture that rewards pausing to verify an unusual request.
Can AI Social Engineering Cyberattacks Be Detected Reliably?
No single detector, grammar check, voice analysis tool or deepfake classifier detects AI social engineering reliably. Detection works best as a layered process that combines sender and domain analysis, authentication events, behavioral anomalies, content provenance, reporting signals and independent verification. Treat any detector result as evidence rather than proof of identity, and require employees to verify high-risk requests through a known communication channel, especially when a message demands secrecy, urgency, payment, credentials or an exception to normal procedure.
How Can Employees Verify an AI-Cloned Voice or Deepfake Video?
Employees should verify through a separate trusted channel, never through the suspicious call or meeting itself, because appearance and voice establish nothing about identity. Yale guidance for recognizing AI-enabled scams advises skepticism toward realistic generated audio and video for that reason. Pause the request, end the interaction and call the person using a number from the corporate directory or an established contact record. Use a pre-agreed challenge phrase for urgent voice requests, require two-person approval for payments or privileged access, and confirm account changes in a protected channel. Lip movement, caller ID, background details and a familiar speaking style are not authentication.
What Should a Company Do After AI Social Engineering Payment Fraud?
A company should contact its bank and payment provider immediately to stop, recall or trace the transfer while preserving evidence and containing any exposed accounts. Record timelines, payment instructions, email headers, URLs, call recordings, transcripts, chat logs, video files, approval records and authentication events. Reset exposed credentials, revoke sessions, inspect mailbox forwarding rules, notify legal and insurers, and assess affected-party reporting duties. Avoid deleting messages or devices until investigators establish preservation requirements, then use the findings to tighten verification gates and retrain the affected roles.
What Are the Legal and Compliance Obligations After an AI-Enabled Impersonation Cyberattack?
Obligations depend on the affected data, the jurisdictions involved, contracts, industry rules and whether the incident caused unauthorized access or financial loss. In the United States, the FTC Impersonation Rule addresses deceptive government and business impersonation and supports enforcement against covered conduct, as described in the FTC's 2025 statement on impersonation scam enforcement. Involve counsel immediately, preserve evidence, document decisions, notify banks and insurers, and determine whether privacy, breach, sector, securities, employment or contractual notices apply. Report qualifying cybercrime to law enforcement and relevant regulators within required deadlines, keep employee communications factual and record remediation steps for audits and board oversight.
Trusted communications now carry payment, credential and access risk that no single detector resolves alone. Adaptive Security measures verification behavior and focuses remediation where exposure runs highest.
As experts in cybersecurity insights and AI threat analysis, the Adaptive Security Team is sharing its expertise with organizations.


