
Social engineering trends and the impact of AI
AI-driven social engineering has reached industrial levels in 2026. Attackers use deepfakes and multi-channel tactics to bypass modern MFA setups.
The architecture of contemporary social engineering
The landscape of social engineering has shifted from primitive, isolated attempts to highly coordinated, multi-channel campaigns. The integration of Artificial Intelligence (AI) into the attacker lifecycle has optimized the delivery and success rate of these operations at a scale that legacy defenses were simply never designed to handle. Data from multiple threat intelligence sources confirms that social engineering is no longer a peripheral concern but the central mechanism for breaching hardened perimeters. The technical barrier to entry has collapsed while the precision of attacks has reached industrial scale.
The role of AI in offensive workflows
AI serves as a force multiplier for deception. Generative AI allows a single operator to execute hundreds of simultaneous, customized campaigns tailored to the specific digital footprints of individual targets. Research from Harvard Kennedy School, published in late 2024, found that fully AI-generated spear-phishing emails achieve a click-through rate of 54%, matching the performance of messages crafted by expert human operators - at roughly 30 times lower cost. The control group, receiving conventional mass-phishing emails, recorded just 12% engagement. This performance gap underscores how thoroughly AI has disrupted the economics of social engineering, primarily by eliminating linguistic errors and enabling consistent, emotionally intelligent personas across extended interactions.
Technical analysis of phishing traffic between September 2024 and February 2025 reveals that 82.6% of all analyzed phishing emails utilized AI in some capacity - a 53.5% year-on-year increase. These systems are used to build high-fidelity deepfake video calls and voice clones, targeting human trust rather than hardware vulnerabilities. Voice cloning is particularly efficient; attackers can replicate a specific individual's voice using as little as 10 seconds of captured audio.
The danger is no longer theoretical. In January 2020, a bank manager in the United Arab Emirates received what they believed to be a voice call from a company director they recognized; the audio had been cloned using AI, and the manager subsequently authorized a $35 million wire transfer. In early 2024, a separate incident in Hong Kong demonstrated the next evolution of the threat: a finance employee was deceived during a deepfake video conference call featuring AI-generated likenesses of multiple colleagues, leading to a $25 million loss. The common thread in both cases is that no technical vulnerability was exploited - only human trust.
Multi-channel coordination and the decline of email dominance
Traditional defense strategies focused heavily on email security. Empirical data from 2025, however, shows a significant shift in initial access methods that has rendered email-centric defenses structurally incomplete. According to Mandiant's M-Trends 2026 report, email phishing dropped to just 6% of intrusion cases - down from 22% in 2022 - while voice phishing (vishing) surged to 11% of all confirmed intrusions globally, making it the second most common initial access vector overall.
In cloud-related compromises specifically, the pattern was starker still. Vishing accounted for 23% of cloud intrusions, becoming the single most prevalent entry method, ahead of third-party compromise (17%), stolen credentials (16%), and email phishing (15%). Mandiant attributes the shift largely to the activities of threat clusters such as ShinyHunters and Scattered Spider, which have refined the art of impersonating internal IT and helpdesk personnel to bypass multi-factor authentication at scale.
Modern campaigns use a layered approach, weaving context across multiple platforms including SMS, Microsoft Teams, Slack, and direct voice calls. The objective is to establish legitimacy before making any malicious request - building rapport over hours or days before the payload is delivered.
Layered attack vectors
One documented tactic involves a high-volume email 'bombing' where a target's inbox is flooded with thousands of legitimate subscription confirmations. While the target is distracted by the noise, the attacker initiates a voice call posing as IT support to 'assist' with the issue. This manufactured urgency makes the victim far more likely to surrender credentials or grant remote desktop access.
A related technique - Telephone-Oriented Attack Delivery (TOAD) - begins with a seemingly benign email containing only a callback phone number. When the target calls, a human operator or AI voice agent walks them through handing over credentials or installing remote access software. Because the initial email contains no malicious link or attachment, it bypasses technical filters entirely. The payload is delivered entirely through the voice channel, outside the reach of conventional email security stacks.
Several additional technical exploits have also seen rapid adoption:
- ClickFix attacks involve tricking users into copying and pasting malicious commands into their browsers or system terminals via fake CAPTCHA prompts or error messages. According to ESET's H1 2025 Threat Report, this vector surged by 517% between the second half of 2024 and the first half of 2025, making it the second most common attack vector after phishing and accounting for nearly 8% of all blocked attacks. The technique is effective across Windows, Linux, and macOS, and the payloads it delivers range from infostealers to ransomware to nation-state malware.
- Swipe-up mobile exploits use mobile UI behavior to hide address bars. A user clicks a trusted shortened link, but after scrolling, the malicious URL remains concealed, making the site appear legitimate throughout the session.
- Tokenized access blocking allows phishing pages to identify and filter out security scanners and researchers, ensuring the malicious infrastructure stays active longer and evades takedown detection.
In 2026, over one-third of social engineering incidents involve these non-email vectors - a structural shift that demands a corresponding shift in defensive investment.
Targeting IT infrastructure and identity management
A primary objective in 2026 is the bypass of multi-factor authentication (MFA). Rather than attacking the cryptographic integrity of MFA systems, attackers circumvent them through the humans who administer them. By impersonating internal support personnel, attackers convince helpdesk staff to reset MFA tokens or share session cookies, effectively handing over authenticated access without triggering any technical alert.
The group Black Basta has been documented using legitimate Microsoft Teams sessions to establish rapport and impersonate internal agents before escalating to credential theft. UNC3944 - also tracked as Scattered Spider - has run vishing campaigns targeting SaaS help desks since at least 2022, using them to harvest long-lived OAuth tokens and session cookies that then enable seamless pivot into downstream customer environments.
KnowBe4's phishing simulation data for Q2 2025 illustrates the scale of the internal impersonation problem. Internal-themed email templates accounted for 98.4% of the top 10 most-clicked simulations. HR-related topics - reimbursements, performance reviews, policy updates - drove 42.5% of all clicks, while IT-themed messages accounted for 21.5%. The most effective single subject line of the quarter was: "Microsoft Teams: You have been added as a guest to [Company Name] Strategic Planning." Employees are not failing to recognize attacks; they are failing to question communications that mirror the everyday texture of their working lives.
The professionalization of the criminal ecosystem
The industrialization of social engineering is sustained by a robust Phishing-as-a-Service (PhaaS) economy. Platforms such as SheByte provide subscription-based attack kits for approximately $200 per month. These services supply templates, fake website builders, and voice spoofing tools that were previously the exclusive domain of nation-state actors. This democratization allows for surgical targeting of high-value individuals with privileged access, particularly in manufacturing, healthcare, and biotech sectors. Manufacturing remains the most targeted industry, representing 26% of all incidents.
A further development is the rise of the division-of-labor intrusion model. Mandiant's 2026 investigations found that 9% of breaches now involve two or more distinct threat groups: one focusing exclusively on initial access, another executing the follow-on stages of the attack lifecycle. This specialization compresses breach timelines, amplifies scale, and significantly complicates both attribution and response.
The deepfake identity crisis
Beyond voice cloning, the broader deepfake threat has escalated rapidly enough to warrant treatment as a distinct attack category. By Q1 2025, deepfake-related fraud incidents had already surpassed the total recorded for the entirety of 2024. Research published in 2025 found that humans correctly identify AI-generated audio only approximately 60% of the time, rendering sensory skepticism an unreliable defensive tool at the individual level. An iProov study found that fewer than one in a thousand participants could perfectly distinguish synthetic from authentic media across all formats.
Threat actors now construct synthetic identities that combine real and fabricated data to pass conventional identity verification checks. These profiles are used to obtain insider access, open fraudulent accounts, and execute slow-burn infiltration of target organizations - operations that may unfold over months. Mandiant's 2025 dwell time data reflects this trend: overall median dwell time rose from 11 days to 14 days, and for cyber espionage campaigns and North Korean IT worker operations specifically, the median reached 122 days, with some intrusions persisting undetected for over a year.
Statistical analysis of impact and behavior
The financial consequences of social engineering continue to compound. The FBI's Internet Crime Complaint Center recorded $16.6 billion in cybercrime losses in 2024, a 33% increase over the prior year. Business Email Compromise (BEC) remains one of the most lucrative single vectors, generating $2.77 billion in reported losses from 21,442 complaints in 2024 alone. IBM's 2024 Cost of a Data Breach Report found the global average breach cost reached $4.88 million - the largest year-on-year increase since the pandemic - with the United States recording an average of $9.36 million per breach, the highest of any surveyed country.
User behavior metrics reveal a persistent and structural gap in defensive readiness:
- Only 20% of users successfully recognize and report phishing attempts in simulation environments.
- The median time to click a malicious link is just 21 seconds after receiving the email.
- 71% of users admit to engaging in risky security actions they know to be dangerous.
- 60% of successful social engineering attacks result in data leaks.
- 98% of cyberattacks involve social engineering in some form.
These figures make the case for moving beyond human-centric trust models toward technical architectures that treat identity compromise as a baseline assumption rather than an edge case.
Defensive frameworks for an AI-threat landscape
The engineering challenge is not simply detecting individual attacks - it is redesigning organizational trust architectures from the ground up. Security practitioners and threat intelligence vendors have converged on several high-confidence countermeasures for the current environment.
Zero Trust identity architecture treats every user, device, and service as a potential threat, requiring continuous verification based on behavioral context rather than network location or a familiar voice. As deepfake technology makes audio and visual verification increasingly unreliable, identity assurance must shift toward behavioral biometrics, device posture assessment, and contextual access controls that adapt in real time.
Out-of-band verification protocols for high-value financial transactions and access escalations - requiring confirmation through a second, entirely unrelated channel - remain among the most effective procedural controls against vishing and BEC. Given the 21-second median time-to-click, process controls must be deliberately designed to slow authorization, inserting friction specifically at the moments attackers depend on urgency and trust.
AI-driven behavioral monitoring shifts detection from content analysis - which AI-generated attacks can defeat - to anomalous activity patterns: unusual login times, atypical data access volumes, unexpected MFA resets, or credential usage from unfamiliar device profiles. The financial differential is measurable: IBM's 2024 data shows organizations deploying security AI and automation incurred average breach costs of $3.84 million, compared to $5.72 million for those that did not - a $1.88 million gap that makes the business case straightforwardly.
Security awareness training calibrated to modern attack techniques - including deepfake audio and video demonstrations, ClickFix simulations, and live vishing exercises - closes the gap that traditional, email-focused training leaves open. Organizations running monthly simulations with immediate feedback report 70-80% improvement in phishing susceptibility rates within six months.
The asymmetry between AI-assisted offense and human-dependent defense is the defining security challenge of the current decade. Closing it requires automated detection systems capable of matching the speed and sophistication of AI-driven deception - a problem that is technical, organizational, and behavioral in equal measure. The organizations best positioned for 2026 and beyond are those that have already stopped treating social engineering as a training problem and started treating it as an architectural one.
Key takeaways
- Voice phishing (vishing) is now the primary initial access vector for cloud-related compromises in 2025, accounting for 23% of cloud intrusions - ahead of third-party compromise (17%), stolen credentials (16%), and email phishing (15%) (Mandiant M-Trends 2026).
- Vishing surged to 11% of all confirmed global intrusions in 2025, overtaking email phishing, which fell to just 6% - down from 22% in 2022 (Mandiant M-Trends 2026).
- AI-generated spear-phishing emails achieve a 54% click-through rate, matching expert human-crafted attacks and outperforming mass-phishing control emails (12%) - at roughly 30 times lower cost (Harvard Kennedy School, 2024).
- 82.6% of phishing emails analyzed between September 2024 and February 2025 utilized generative AI components - a 53.5% year-on-year increase.
- ClickFix attacks surged 517% between H2 2024 and H1 2025, making it the second most common attack vector after phishing, accounting for nearly 8% of all blocked attacks (ESET H1 2025 Threat Report).
- Reported cybercrime losses reached $16.6 billion in 2024 - a 33% year-on-year increase - driven by investment fraud, BEC, and ransomware (FBI IC3 Annual Report 2024).
- Business Email Compromise (BEC) alone generated $2.77 billion in reported losses from 21,442 complaints in 2024 (FBI IC3 Annual Report 2024).
- Voice cloning technology can produce a usable vocal replica of a target from as little as 10 seconds of captured audio.
- The global average cost of a data breach reached $4.88 million in 2024, the largest year-on-year increase since the pandemic; the US average stood at $9.36 million - the highest of any country surveyed (IBM Cost of a Data Breach Report 2024).
- Deepfake-related fraud incidents in Q1 2025 alone surpassed the total recorded across all of 2024.
- Humans correctly identify AI-generated audio only approximately 60% of the time; fewer than one in a thousand can perfectly distinguish synthetic from authentic media across all formats (iProov, 2025).
- The median time for a user to click a phishing link is just 21 seconds after receiving the email (Verizon DBIR 2025).
- 98.4% of the top 10 most-clicked phishing simulation templates in Q2 2025 impersonated internal communications, with HR-themed emails driving 42.5% of all clicks (KnowBe4 Q2 2025 Phishing Simulation Roundup).
- Organizations deploying security AI and automation incur average breach costs of $3.84 million, compared to $5.72 million for those that do not - a $1.88 million gap (IBM Cost of a Data Breach Report 2024).
Sources
- FBI Internet Crime Complaint Center - 2024 Annual Report https://www.ic3.gov/AnnualReport/Reports/2024_IC3Report.pdf
- IBM Cost of a Data Breach Report 2024 https://www.ibm.com/think/insights/whats-new-2024-cost-of-a-data-breach-report
- Mandiant M-Trends 2026 (Google Cloud) https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026/
- ESET H1 2025 Threat Report (via Infosecurity Magazine) https://www.infosecurity-magazine.com/news/clickfix-attacks-surge-2025/
- Zensec - Phishing Statistics 2025-2026 https://zensec.co.uk/blog/2025-phishing-statistics-the-alarming-rise-in-attacks/
- Published 2026-04-23 11:45
- Modified 2026-05-21 12:49

