Company Partners Our Teams Contact Blog
Services
Industries
Talk to an expert

Phishing and social engineering in the AI era: what changed

· 7 min read · Network Secure

Phishing is one of the oldest scams on the internet and remains one of the most common entry points in corporate incidents. What has changed is not the logic — tricking a person into handing over access, data or a payment — but the finish. With generative AI, the message arrives with no spelling mistakes, the right context and, increasingly, the voice of someone the victim knows.

How the scams have evolved

The generic "your account will be suspended" email is still around, but it now shares space with far more polished variations:

  • Spear phishing. Messages aimed at a specific person or team, built from public information — a LinkedIn job title, suppliers, recent company events. They also arrive via a colleague's hijacked WhatsApp account asking for an instant transfer.
  • Impersonated brands. Banks, cloud services, email platforms and password managers are favourite targets, because they lead to money or to many other accounts. A common pattern is the fake maintenance notice asking you to "back up your vault" within 24 hours, which leads to a page that captures the master password.
  • Voice and video deepfakes. Short clips of public audio are enough to generate a convincing synthetic voice. The "fake executive" asking for an urgent transfer now has a version in which the voice really does sound like the executive.
  • Biometric fraud. Photos, videos and masks are used to fool facial recognition when opening accounts or taking out loans in someone else's name. A face posted on social media is not a secret.
  • MFA fatigue. With the password in hand, the attacker fires approval prompts one after another until the person, worn down, taps "approve" — often paired with a call from "IT support".

In December 2024, the FBI issued an IC3 alert describing exactly this shift: criminals use generative AI to write text without the errors that used to give fraud away, to create fake profiles at scale and to generate short audio clips in the voice of someone the victim knows, asking for money urgently.

Why the human factor is still central

Social engineering does not attack the system; it attacks the decision of the person operating it. It exploits predictable emotions — fear, haste, the urge to help, curiosity, deference to hierarchy — to get someone to skip a verification step they would normally take. Email filters reduce what gets through, but they cannot stop an employee from reading out over the phone a code they have just received.

That does not make people the "weak link" to be blamed; it makes them a layer of defence that needs preparation and process. Someone who can recognise the scam, has a simple channel to report it and is not punished for clicking will catch attacks that technology let through.

The warning signs are subtler now. Spelling mistakes and wonky logos used to be good indicators. With AI, the form of the message can be flawless. What still gives the scam away is the request: urgency, an exception to the process and secrecy.

How to recognise the signs

The signs that still work are less about appearance and more about behaviour:

  • Artificial urgency. Short deadlines ("within 24 hours", "before close of business"), threats of lockout or loss of access.
  • A request outside the process. A change to a supplier's bank details, a payment without the usual approval, a password or code sent by email, phone or chat.
  • A request for secrecy. "Don't mention this to anyone, it's a confidential deal" is a classic of CEO fraud.
  • Sender and link that almost match. Look-alike domains, swapped letters, misleading subdomains, URL shorteners. Hover before you click and, when in doubt, type the address yourself.
  • An MFA prompt you didn't request. If you are not trying to sign in, the answer is to deny and report — never to approve "to make it stop".

For voice and video, the practical rule is the same one the FBI recommends to families: verify through another channel. Hang up and call back on a number you already know, confirm through an official internal channel or agree on a code word in advance for sensitive requests. Odd details in the audio help, but they cannot be the main defence: the quality of the fakes is improving quickly.

What the company needs to have

Phishing-resistant MFA

Any second factor is better than a password alone, but not every MFA resists phishing: SMS codes, manually typed codes and push approvals can be relayed to a fake page or extracted through MFA fatigue. NIST SP 800-63B, in revision 4, defines phishing resistance as the protocol's ability to avoid disclosing the secret to an impostor verifier without relying on the user's vigilance — and states that authenticators requiring manual entry of a code do not qualify. In practice: FIDO2/WebAuthn passkeys and security keys, or certificate-based authentication (PKI). CISA recommends prioritising this type of MFA for administrators, executives and accounts with access to critical data and systems and, where push notifications remain, enabling number matching to make approval by fatigue harder.

Continuous training, not annual

One talk a year does not change behaviour. Programmes that work are recurring, short and practical: simulations using the scams actually in circulation, specific content for higher-risk teams (finance, HR, IT, executives) and metrics beyond click rate, such as reporting rate. When leadership takes part, security becomes a value, not an obligation.

A simple reporting channel

A "report phishing" button in the email client, a single address or a channel in the corporate chat, with a quick response from the security team. A single early report makes it possible to pull the same message from every other mailbox and block the domain before anyone else falls for it.

Processes that don't depend on perception

Payments and changes to bank details should require confirmation through a second channel and by a second person, regardless of who is asking. IT support needs an identity verification procedure before resetting a password or MFA. These controls stop the scam even when the voice, the email and the video are perfect.

Monitoring and response

Some scams will get through. AI also serves the defence, through behavioural detection, but what matters most is noticing quickly: sign-ins from unusual locations or devices, MFA approvals in rapid succession, new forwarding rules in a mailbox, consent granted to suspicious OAuth applications, access to unusual volumes of data. A SOC that correlates identity, email and endpoint signals can contain a compromised account before it turns into fraud or lateral movement, and an incident response plan defines the first minutes: revoke sessions, reset credentials, alert finance.

Identity is the new perimeter. Almost every phishing scam ends in a credential, a token or an approval. Protecting, monitoring and being able to revoke identities quickly is what limits the damage.

Frequently asked questions

Is it still worth training employees if AI makes scams flawless?

Yes, but the focus changes. Instead of teaching people to look for spelling mistakes, training should teach them to recognise out-of-process requests, verify through another channel and report quickly. Training and technical controls complement each other.

What is phishing-resistant MFA?

It is authentication in which the secret is bound to the legitimate site and cannot be relayed to a fake page, such as FIDO2/WebAuthn passkeys and security keys or certificate-based authentication. SMS codes, typed codes and push approvals do not meet this definition, according to NIST SP 800-63B.

How can we protect against voice deepfakes in payment requests?

Do not approve anything based on the voice alone. Hang up, call back on a known number and require confirmation through the formal approval workflow.

What should someone do after clicking or typing their password into a fake page?

Report it to the security team immediately, change the password, revoke active sessions and review the account's MFA. The sooner the report, the smaller the attacker's window.

Sources consulted: CISA, NSA, FBI and MS-ISAC, Phishing Guidance: Stopping the Attack Cycle at Phase One (October 2023); CISA, Implementing Phishing-Resistant MFA (fact sheet); NIST SP 800-63B-4, Digital Identity Guidelines: Authentication and Authenticator Management (definition of phishing resistance); FBI IC3, Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud (alert PSA241203, December 2024). This article is educational and does not replace an assessment of each organisation's environment.

Official references

Read next