The evolution of social engineering: the impact of artificial intelligence on corporate defenses

Artificial intelligence is revolutionizing social engineering, breaking down the cost, time, and skill barriers that once forced attackers to choose between volume and precision. Today, a single operator can launch large-scale spear phishing campaigns with unprecedented levels of personalization, combining information from organizational charts, public repositories, and employees' social profiles.

Quick Answer

  • AI has made social engineering more effective, enabling large-scale attacks with high personalization
  • Three main techniques leverage AI: large-scale spear phishing, smishing, and deepfakes
  • Traditional defenses based on signatures and rules are ineffective against these attacks
  • New defense strategies require behavioral analytics and AI-assisted investigation

Attack techniques accelerated by AI

According to a KnowBe4 study, 86% of the phishing attacks analyzed in 2026 were AI-driven. These attacks exploit AI's ability to generate personalized messages for hundreds of recipients simultaneously, combining information from various sources both internal and external to the organization.

Another growing attack vector is smishing, or phishing via SMS. The Verizon 2026 Data Breach Investigations Report reveals that people are up to 40% more likely to fall victim to social engineering via text or phone compared to email. This is because text messages lack the authentication infrastructure present in emails.

Deepfakes represent another significant risk. While creating convincing fakes once required advanced editing skills, today a few seconds of audio or video are enough to generate a deepfake. These are often used in the final stage of an attack when a suspicious employee receives a call from a familiar voice to verify a payment request.

The critical aspect of identity

The common thread of these techniques is that the attacks focus on identity rather than malware. A false request to the helpdesk built on real internal knowledge is difficult to detect, even for trained experts. This approach exploits the inherent trust employees place in interactions with their colleagues and internal procedures.

Why traditional detection solutions can't keep up

Traditional detection solutions were based on a fundamental assumption: that attackers' output was limited by human effort. Email filters based on signatures, rule-based anti-fraud engines, and static awareness programs relied on attack patterns changing slowly enough for defenders to adapt.

AI has broken this assumption. When attackers regenerate lures, domains, and payloads at machine speed, trying to match known artifacts becomes a losing battle. Defenders need detection solutions that reason about behavior, not wait for a pattern they've seen before.

Restructuring defenses to adapt

Countering AI-powered social engineering isn't a problem that can be solved with a single product. It requires a shift in operational model, with some key capabilities making it possible. Among these, behavioral analytics based on unified telemetry, which allows detecting suspicious activities such as a legitimate access followed by an unusual OAuth consent grant, an early indicator known of compromise.

Another crucial capability is agentic investigation and response, which uses generative AI to correlate signals into prioritized attack narratives. This allows analysts to elevate their role, reading the summarized case, verifying the reasoning, and approving the response.

Finally, it is essential that the AI used for defense is transparent and agnostic. When AI makes decisions about identity-based attacks, the security team should be able to see the prompts and reasoning behind each decision. If it cannot be audited, it cannot be defended.

The new economy of social engineering

The economy of social engineering has changed radically. Reconnaissance, personalization, and impersonation are now economical, fast, and accessible to any adversary. Defenses built for a slower era desperately need an update.

To delve into detection priorities and defense strategies, a comprehensive guide is available on how to defend against AI-powered social engineering attacks.

The evolution of threats and the importance of continuous training

While defense technologies advance, so do attackers. New generations of deepfakes, for example, are becoming increasingly difficult to detect, even for experts. This is because artificial intelligence algorithms are improving in their ability to replicate the nuances of the human voice and facial expressions. A recent study demonstrated that the most advanced deepfakes have a 70% success rate in convincing recipients of their authenticity. In this context, continuous employee training becomes crucial. It's no longer just about teaching them to recognize a suspicious email, but about developing a cybersecurity mindset. Awareness programs must be regularly updated to reflect the latest threats and attack techniques. Additionally, it is important that employees understand the importance of cross-verification and direct communication with colleagues before acting on sensitive requests.

The integration of advanced security solutions

To effectively counter AI-powered social engineering threats, companies must adopt an integrated approach. This includes implementing advanced security solutions such as real-time behavioral analysis, which can detect anomalies in user activities and report potential compromises. Additionally, the use of multi-factor authentication (MFA) technologies can add an extra layer of security, making it more difficult for attackers to access corporate systems. Another important aspect is the adoption of unified security platforms, which allow centralizing threat management and responding quickly to attacks. These platforms can integrate data from various sources, such as endpoints, networks, and cloud, to provide a holistic view of the organization's security.

The role of transparency and auditability

The transparency and auditability of AI-based security solutions are fundamental to ensuring that the decisions made by algorithms are understandable and verifiable. This is particularly important in the context of social engineering, where identity-based decisions can have a significant impact on the organization's security. Companies must ensure that their security solutions are designed to allow security teams to understand and verify the reasoning behind each decision made by AI.

The need for a proactive approach

Countering AI-powered social engineering requires a proactive approach. Companies must be ready to quickly adapt to new threats and implement advanced security solutions. This includes investing in research and development to develop new security technologies and adopting best practices for threat management. Additionally, it is important that companies collaborate with other organizations and competent authorities to share threat information and develop common defense strategies. The landscape of AI-powered social engineering is constantly evolving, and companies must be ready to quickly adapt to new threats. The adoption of advanced security solutions, continuous employee training, and a proactive approach are fundamental to effectively countering these threats. Furthermore, the transparency and auditability of AI-based security solutions are crucial to ensuring that the decisions made by algorithms are understandable and verifiable. With an integrated and proactive approach, companies can protect their systems and data from increasingly sophisticated attacks. For more information on how to defend against AI-powered social engineering attacks, a comprehensive guide is available on how to defend against AI-powered social engineering attacks.

Editorial Note and Disclaimer

The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.

GoYou does not constitute a journalistic publication or an editorial product pursuant to Law No. 62/2001 and does not engage in real-time information activities.

The GoYou project does not provide professional, technical, legal, or financial advice and disclaims all liability for the misuse of the information published.

In the Crypto sector, every investment involves risks: readers are invited to always inform themselves independently before making any decision.