Webinars

AI-Powered Social Engineering: The New Threat Landscape

Expert analysis of how AI is changing social engineering attacks and what organizations need to know.

Guides, reports, webinars, and field notes on cyber compliance, cloud posture, policy management, vendor risk, AI governance, and security awareness.

  • Webinar
  • 60 min
  • February 5, 2025

AI-Powered Social Engineering: The New Threat Landscape

The AI Revolution in Cyber Attacks

Artificial intelligence is transforming the threat landscape. Attackers are leveraging AI to create more sophisticated, personalized, and scalable social engineering attacks than ever before.

How Attackers Use AI

1. Deepfake Voice and Video

AI can now clone voices from just a few seconds of audio. Attackers use this for:

  • Voice phishing (vishing): Impersonating executives in phone calls
  • Video calls: Creating real-time deepfake video for video meetings
  • Voicemail attacks: Leaving convincing voicemails from "trusted" sources

Real Case: A UK energy company lost $243,000 when attackers used AI to impersonate the CEO's voice in a phone call requesting an urgent wire transfer.

2. AI-Generated Phishing Content

Large language models create flawless, personalized phishing emails:

  • Perfect grammar and natural language
  • Personalization based on target research
  • Dynamic content that evades detection
  • Rapid generation of thousands of unique variants

3. Automated Reconnaissance

AI analyzes social media, company websites, and data breaches to:

  • Build detailed target profiles
  • Identify relationships and organizational structure
  • Find topics of interest for personalized lures
  • Determine optimal timing for attacks

4. Conversational AI Attacks

AI-powered chatbots can maintain extended conversations to:

  • Build trust over time
  • Adapt responses based on target reactions
  • Gradually extract sensitive information
  • Scale attacks across many targets simultaneously

Defense Strategies

Enhanced Verification

Implement out-of-band verification for sensitive requests:

  • Callback procedures using known numbers
  • Video calls for unusual financial requests
  • Multi-person approval for large transactions

AI-Powered Detection

Fight AI with AI:

  • Tools that detect AI-generated text
  • Voice analysis for deepfake detection
  • Behavioral analytics for anomaly detection

Updated Training

Employees need to understand these new threats:

  • Awareness that AI attacks exist and are sophisticated
  • Training on verification procedures
  • Examples of AI-powered attacks

The Future

As AI capabilities advance, social engineering attacks will become increasingly difficult to distinguish from legitimate communications. Organizations must adapt their defenses accordingly, combining technical controls with human awareness and robust verification procedures.

"The next generation of phishing attacks won't have typos or suspicious URLs. They'll be perfectly crafted, personally targeted, and increasingly automated."

Related insights