AI Social Engineering: How Is AI Changing the Social Engineering Attack Landscape
AI social engineering is the use of AI to make social engineering attacks more convincing and harder to recognize. It pairs familiar manipulation techniques, such as authority, urgency and trust, with AI-generated content that can make interactions feel more authentic. Attackers can now create personalized messages and convincing voices or videos with far less effort.
The scale of the problem is also growing. The FBI recorded 22,364 AI-related complaints and $893.3 million in reported losses in 2025. Gartner’s survey, which was conducted from March-May 2025, adds to the concern, finding that 62% of organizations experienced a deepfake attack in the previous 12 months.
Read on to learn how AI social engineering is changing traditional tactics and how organizations can prepare for these evolving threats.
Key Takeaways
- AI social engineering attacks make familiar scams more convincing, personalized and easier to scale.
- AI can create realistic phishing messages, cloned voices and deepfake videos with less effort.
- Spelling mistakes and generic messages are no longer reliable signs of a scam.
- Unusual requests, urgency and unfamiliar communication channels should prompt verification.
- Diopter can help assess voice, video, identity and behavioral signals for potential manipulation.
Traditional vs AI-powered Social Engineering
The way attackers manipulate people has changed significantly as technology has advanced. Earlier social engineering attacks often relied on generic messages, obvious mistakes and considerable manual effort.
Nowadays, AI-powered social engineering can help attackers create more convincing and personalized interactions across different channels. AI can also make it easier to adapt messages, imitate communication styles and produce realistic content at scale. This lowers the effort needed to make a scam appear genuine.
| Traditional Social Engineering | AI-Powered Social Engineering | |
|---|---|---|
| Effort | Traditional attacks require attackers to plan and carry out each step manually. | AI can automate several parts of an attack, helping attackers create and adapt deceptive content faster. |
| Targeting | Attackers send generic messages to a large number of potential victims. | AI can help attackers personalize messages using details gathered about specific individuals. |
| Channels | Traditional attacks were built around emails, text messages or basic online interactions. | AI-enabled attacks can combine text, voice, video, chat and social media to create more convincing interactions. |
| Quality of content | Spelling mistakes, awkward wording or unusual formatting can expose a fraudulent message. | AI can produce polished and natural-sounding communication that is harder to distinguish from genuine content. |
| Adaptability | Traditional attacks rely on familiar manipulation techniques and pre-planned scenarios. | Agentic AI can help attackers automate and adapt multiple steps of an attack, potentially changing tactics as an interaction develops. |
AI Social Engineering Attacks You Should Know About
AI is not creating new attack tactics, but it is making familiar scams easier to personalize, scale, and disguise. Here are the different AI social engineering attacks you need to know:
BEC Attacks
Business email compromise (BEC) involves impersonating a senior executive, colleague or trusted business contact or compromising their account, to trick someone into sharing information or authorizing a payment. AI can make these attacks more convincing by helping criminals copy a person’s communication style or even imitate their voice.
Ferrari’s voice-cloning BEC attempt
In July 2024, a Ferrari executive was targeted through a WhatsApp impersonation attempt in which the attacker posed as CEO Benedetto Vigna about a confidential business matter. The attacker called using an AI-generated voice to make the impersonation more convincing. The executive noticed inconsistencies and asked a personal question that only the real CEO would know. The impersonator could not answer and ended the call.
Key Learning: When a request involves sensitive information or action, identity verification becomes important for sensitive requests. In this case, a simple out-of-band personal question helped expose the impersonation attempt.
Phishing
Phishing uses emails or messages that encourage people to click a link, share information or take immediate action. AI can make these messages look more natural and credible, and attackers can also use popular AI brands to make their lures feel familiar.
Microsoft’s 2026 AI phishing campaign
Microsoft identified a phishing campaign that used generative AI to create highly personalized emails based on victims’ roles and workflows. It included lures like RFPs, invoices and manufacturing-related requests, making the messages more relevant and convincing. Attackers also generated device codes at the moment a victim clicked the phishing link, so the code was still valid when it was used.
Key Learning: AI can make phishing more personalized by automating parts of the attack, allowing threat actors to scale convincingly.
Video Deepfake
Video deepfake fraud uses AI to create or manipulate video so that someone appears to be speaking or acting when they are not. In a social engineering attack, criminals can use deepfake video to impersonate executives or other trusted individuals during virtual meetings.
Arup, $25.6 million
An employee at engineering company Arup joined a video conference with people who appeared to be senior colleagues. However, the participants had been recreated using deepfake technology. Believing the instructions were genuine, the employee transferred around HK$200 million (US$25.6 million). The incident showed how a convincing video interaction can be used to manipulate someone into authorizing a high-value wire transfer.
Key Learning: A realistic video call can make a fraudulent request feel more credible than a typical phishing message. Familiar faces and voices can thus create a false sense of trust, making deepfake video detection and independent verification important.
Voice Cloning
Voice cloning attacks use AI to create a synthetic version of someone’s voice. Attackers can then use the cloned voice in calls or voice messages while pretending to be a trusted person. When combined with other information gathered about the target, this can make the interaction particularly convincing.
Senior US officials impersonated via AI voice messages
Attackers used text messages and AI-generated voice messages to impersonate senior US officials. They spent time building trust before moving conversations to encrypted messaging platforms. Once the target was engaged, attackers attempted to obtain sensitive information, authentication codes, documents, introductions or financial assistance.
Key Learning: The campaign shows how attackers can use positions of authority to build trust and make fraudulent requests appear legitimate. AI-generated voice messages can make these impersonations more convincing, highlighting the importance of voice deepfake detection.
Why Traditional Red Flags Are Losing Their Value
Traditional social engineering red flags used to be spelling mistakes, awkward grammar, generic messages and suspicious-looking links. These clues can still be useful, but they are becoming less reliable as attackers use AI to create polished and personalized content.
AI social engineering can produce messages that sound natural, match a target’s communication style and appear relevant to the situation. This means employees need to look past how a message is written and pay closer attention to unusual requests, emotional pressure, unexpected communication channels and attempts to bypass normal verification processes.
What Should Businesses Look for Instead?
With AI-powered social engineering, attackers can now personalize their approach using publicly available information, making it a more targeted attack. This is why it is essential to look at the signals around a request:
- Polished Communication: AI can create clear, error-free messages that do not immediately look suspicious.
- Personalized Messages: Attackers can tailor messages to specific people, roles or organizations.
- Strong Emotions and Urgency: Fear, panic or pressure to act quickly can be signs of manipulation.
- Unusual Requests: Verify requests outside an employee’s normal responsibilities.
- Unexpected Communication Channels: Requests to move conversations or bypass usual processes deserve caution.
- Independent Verification: Sensitive requests should be confirmed through a separate, trusted channel.
Also read: 6 Detection Methods That Catch AI Social Engineering Attacks
How Diopter Helps Detect AI-Powered Social Engineering
A convincing voice, familiar face or perfectly worded message can create a false sense of trust. Diopter helps organizations look beneath that first impression by examining the signals behind an interaction.
Diopter combines media analysis with identity and behavioral insights to spot signs of manipulation and assess risk. Here is how Diopter detects AI social engineering attacks:
- Detects Fake Audio and Video: Diopter examines voice and video to spot signs of deepfakes and cloned voices.
- Checks Multiple Signals: It looks at different audio and video signals instead of relying on just one indicator.
- Analyzes Conversations: Diopter can identify signs of pressure, urgency, and other behaviors commonly associated with social engineering.
- Helps Check Identity: It can help assess if the person on a call is genuinely who they claim to be.
- Flags Unusual Instructions: It can flag suspicious payment or wire-transfer requests for closer review.
- Provides Clear Risk Signals: Diopter provides a verdict, confidence level and supporting signals to give teams more context when assessing an interaction.
Learn How Diopter Defends a Call
From verifying identity and payment instructions, detecting AI or deepfake media, identifying manipulation, to checking policy alignment.
Conclusion
Social engineering has always relied on trust. AI-powered social engineering gives attackers more convincing ways to earn it. From polished phishing messages to cloned voices and deepfake videos, the signs are becoming harder to spot. Organizations need a way to assess what is happening beyond the surface.
Diopter uses media, identity and behavioral signals to help teams recognize potential threats. It brings these signals together to help identify suspicious interactions and make more informed decisions in real time.
Frequently Asked Questions
How can businesses verify a person’s identity during a suspicious interaction?
Can AI social engineering attacks target employees at any level or department?
Can AI detect social engineering when the person on the call is real?
Can AI social engineering attacks bypass traditional security controls?
Monthly analysis of AI social engineering, voice fraud and deepfake attacks on enterprises.
One email a month. No spam, and we never share your address.