Artificial Intelligence Revolutionizes Social Engineering: Lessons from Sports Organizations
Every security team lives the same nightmare: an employee receives a message that seems to come from the boss and acts accordingly. No matter how much training is provided, something always slips through, leaving the IT department to handle the situation. This underscores the importance of preparation at all stages of the threat cycle.
During a recent webinar sponsored by Doppel and led by its chief strategy officer, Bobby Ford, two NFL technology leaders, Costa Kladianos, EVP and head of technology for the San Francisco 49ers, and Christina Morillo, senior director and head of information security for the New York Giants, illustrated how AI has rewritten the social engineering playbook ahead of the 2026 season. Their environments are extreme, but the lessons apply directly to any business.
The Threat Hasn’t Changed, but the Economy Has
Social engineering remains one of the most accessible ways for attackers to target an organization. Generative AI has changed the speed, scale, and credibility of these attacks. "I don’t think AI-generated threats are new," said Morillo. "I just think AI has made them a little easier. A process that might have taken minutes before might now take days or even longer."
Morillo also highlighted the collapse of required skills. "Before, we were just talking about script kiddies and what tools to use. Now you don’t need much. You can go to any model and the tools are there. Pay $20 a month and you’re in."
Ford cited research indicating that AI-powered phishing can produce higher click-through rates and that AI-assisted impersonation is on the rise. The speed and scale of these attacks concern both executives, who said the volume faced by sports organizations was already substantial.
The Quality of Attacks Has Improved
Another change concerns quality. "Before, it was messages like 'I’m from this country, send me your bank account and I’ll send you a billion dollars,'" said Morillo. "Now it might come from a vendor, a partner, or someone you work with, and it might not be them."
One of the most concerning threats is represented by deepfakes, manipulated videos or audio that can fool even the most attentive observers. Costa Kladianos, EVP and head of technology for the San Francisco 49ers, highlighted how the public visibility of employees can become a double-edged sword: "The more known a person is, the more training material an attacker can find online."
This technique can be used to create fake videos of the CEO requesting urgent payments or audio recordings of the CFO sharing sensitive information. The attack surface extends far beyond IT-managed systems, including social platforms like LinkedIn.
Advanced Defensive Strategies
In addition to the practices already discussed, organizations can adopt further measures to strengthen their security posture:
Implementation of Advanced Multi-Factor Authentication Solutions
The adoption of FIDO2-standard open MFA can reduce the risk of phishing attack bypasses. It is important to educate employees about the importance of not disabling these protections, even if they receive seemingly legitimate requests.
Continuous Monitoring of User Behavior
The adoption of User and Entity Behavior Analytics (UEBA) solutions can help detect anomalous activity that might indicate account compromise. These tools can analyze behavior patterns and identify suspicious deviations.
Development of a Social Engineering-Specific Incident Response Plan
Organizations should develop specific procedures for managing incidents related to social engineering, including protocols for quickly verifying suspicious requests and internal communication during an attack.
The Importance of Collaboration
As both executives emphasized, collaboration among organizations in the same sector can be invaluable. Sharing information about indicators of compromise, vendor assessments, and notes on security tools can help create a more robust collective defense against emerging threats.
This collaboration is not limited to data sharing but can extend to creating common security standards and conducting joint exercises to test incident response capabilities.
The adoption of artificial intelligence techniques by cybercriminals has made social engineering a more sophisticated and difficult-to-combat threat. However, by implementing the advanced defensive practices described in this article and promoting a security culture based on collaboration and continuous training, organizations can significantly improve their ability to resist these attacks.
The key to success lies in adopting a proactive approach to security that combines advanced technologies with solid operational practices and a risk-aware corporate culture.
Editorial Note and Disclaimer
The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.
GoYou does not constitute a journalistic publication or an editorial product pursuant to Law No. 62/2001 and does not perform real-time information activities.
The GoYou project does not provide professional, technical, legal, or financial advice and disclaims all responsibility for the improper use of the information published.
In the Crypto sector, every investment involves risks: readers are invited to always inform themselves autonomously before making any decision.