What is AI social engineering?
AI social engineering is the use of artificial intelligence, such as generative text, voice cloning, and deepfake technology, to automate, scale, and personalize attacks that trick people into revealing sensitive data or taking harmful actions.
AI makes familiar social engineering tactics faster, more convincing, and easier to use at scale. Many attackers now treat generative AI like a personal assistant, using it to build fake personas, spin up phishing websites, generate malicious code, and write convincing pretexts in a fraction of the time. Every message becomes more personal, shaped by a target's role, habits, and emotional triggers once an attacker feeds publicly available data into the model. Language barriers disappear, too, since AI generates fluent text in whatever language the target speaks. With that kind of scale, a single attacker can now run thousands of individualized attacks at once without losing quality.
However, not all AI social engineering looks the same. In AI-powered social engineering attacks, a human stays in control. They use AI to draft emails or clone voices, while making the strategic decisions themselves. Fully AI-driven attacks go even further. AI agents handle the entire chain, from target selection to real-time conversation, with minimal human oversight.
AI social engineering vs. traditional social engineering
Social engineering has always relied on deception. AI just makes it quicker, more polished, and easier to run at a scale that wasn't realistic before. That shift is already showing up in the numbers: as of 2025, 82.6% of all phishing emails use some form of AI language model or generator, up from 53.5% the year before. Here's how that plays out across the board:
Factor | Traditional social engineering | AI-powered social engineering |
|---|---|---|
Speed and scale | Manual effort limits attackers to a handful of targets at a time | Thousands of individualized attacks can be launched simultaneously with minimal effort |
Personalization depth | Requires hours of manual research per target; often generic apart from spear phishing | AI scrapes and processes data from social media, company sites, and leaked databases to tailor each message automatically |
Language quality | Often contains grammar mistakes, awkward phrasing, or unnatural tone, especially in languages the attacker doesn’t speak | Near-flawless, natural-sounding output in any language |
Cost per attack | High: each convincing attack demands hours of human research and writing | Low: once a model is set up, the marginal cost per additional target drops close to zero |
Detection difficulty | Trained employees can often spot red flags like poor grammar, generic greetings, or mismatched URLs | Far harder to detect; AI-generated messages mimic real writing patterns, use context-appropriate details, and avoid the usual warning signs |
Real-time deepfake voice/video | Not available; impersonation relies on email spoofing or caller ID manipulation | Attackers can clone voices from short audio samples and generate real-time deepfake video for live calls, making impersonation nearly indistinguishable from reality |
So, how is AI changing social engineering? An attacker can now identify high-value targets, generate personalized pretexts, communicate fluently in the target’s native language, and even impersonate a trusted colleague on a video call. Traditional social engineering never operated at that speed or that level of believability, and the damage is catching up. Americans lost $12.5 billion to phishing and other fraud in 2024 alone, a number likely to grow as AI lowers the bar for running convincing attacks at scale.
Key techniques used in AI-based social engineering attacks
AI-driven social engineering doesn't rely on a single method. Attackers pick from a technique from a growing AI-powered toolkit and often combine several ones in a single campaign. Here's what each one looks like in practice.
AI-generated phishing and spear-phishing emails
Phishing is the most common form of social engineering, and attackers run these campaigns in large batches, counting on at least one person to take the bait. AI makes each batch smarter by adjusting messages on the fly based on how targets respond, generating emails that match a company's tone, and mimicking a specific sender's writing style. Spear phishing goes deeper, as AI collects data on individual targets, replicates their contacts' behavior, and translates messages fluently into their native language to make each attempt feel personal.
In 2024, security firm SlashNext reported a 4,151% increase in phishing messages since the launch of ChatGPT. That spike isn't just about volume. These emails are getting harder to flag because they lack the spelling mistakes, awkward phrasing, and formatting errors that spam filters and employees have been trained to catch.
Deepfake voice cloning and vishing
Voice cloning and deepfake technology can now replicate someone's voice and likeness from just a few seconds of recorded audio or video. Attackers use them in phone-based social engineering (vishing), impersonating CEOs, department heads, or trusted vendors to authorize fraudulent wire transfers, override approval processes, or extract login credentials from employees.
The first known case of an AI voice deepfake scam was used in 2019. The CEO of a UK energy firm received a call that sounded exactly like his German boss, down to the accent and speech melody. He wired €220,000 to what later turned out to be a fraudulent account.
Deepfake video impersonation
Deepfake social engineering isn't limited to audio. Attackers can now generate real-time video of a person's face and expressions during a live call, impersonating someone in a way that's nearly impossible to question at that moment.
In one case, a clerk at a multinational firm in Hong Kong joined a video conference where every participant, including the company's CFO, was a deepfake Believing she was following orders from senior leadership, she made 15 transactions totaling HK$200 million (roughly $25 million) before discovering the entire call was fabricated.
AI-powered business email compromise (BEC)
Business email compromise, one of the most financially damaging forms of social engineering, uses spoofed or hijacked email accounts to impersonate executives, vendors, or partners and trick employees into transferring funds or sharing confidential information.
AI and social engineering makes worse by letting attackers scale campaigns, personalize each message, and imitate internal communication styles down to project names, corporate jargon, and the individual writing quirks of the person they're pretending to be. The FBI's IC3 reports that BEC caused nearly $3 billion in losses in 2023 up 7% from the year before, bringing the total to $14.3 billion since tracking began in 2015.
Smishing and AI chatbots
Attackers use AI-powered chatbots in SMS-based social engineering (smishing) and live chat scams. Instead of sending a single phishing message and waiting for a click, an AI chatbot can continue the conversation, adjust its responses based on what the target says, and build trust before extracting sensitive information. Some impersonate IT help desks, walking employees through fake security checks or password resets to harvest credentials.
Real-world AI social engineering incidents
Here are some of the most notable AI social engineering incidents from recent years.
- Ferrari executive voice clone attempt, 2024 In mid-2024, a Ferrari executive received WhatsApp messages and a phone call from someone impersonating CEO Benedetto Vigna. The cloned voice discussed a confidential acquisition and asked the executive to sign an NDA and arrange a currency hedge transaction. The executive grew suspicious when he noticed subtle mechanical undertones in the voice and asked a personal question only the real Vigna could answer. The caller hung up, and Ferrari launched an internal investigation.
- LastPass AI-generated voice attack, 2024 An employee at password management company LastPass received a series of calls and WhatsApp messages from someone using a deepfake audio clone of CEO Karim Toubba. The employee recognized it as an attack because the communication came through WhatsApp, which fell outside normal business channels, and reported it to the security team. LastPass publicly disclosed the incident to raise awareness.
- South Korean political deepfake, 2022 A supporter of a People Power Party candidate used an AI-generated avatar of President Yoon Suk Yeol to fake an endorsement ahead of local elections. The backlash led South Korea's National Assembly to ban deepfake content in political campaigns within 90 days of an election, with penalties of up to seven years in prison.
How cybercriminals prepare and launch AI social engineering attacks
Every attack starts with reconnaissance, and AI has automated the entire process, from finding targets and profiling them to figuring out what message will land.
AI-powered OSINT (open-source intelligence) tools pull from everything that's publicly available: executive bios, speaking engagements, social media accounts, earnings calls, organization charts, and vendor relationships. In seconds, an attacker can build a detailed profile of a target, covering their role, reporting chain, communication style, and personal interests. Some go further, searching the dark web for previously compromised credentials that give them access to a real user's inbox. From there, they can send messages from a trusted account, making the attack far harder to question.
Yet, not all of this runs on mainstream AI with safety guardrails. Some attackers hack or jailbreak legitimate models like ChatGPT, while others turn to purpose-built alternatives. Tools like WormGPT built on open-source language models and sold behind paywalls on the dark web, have been used extensively for BEC attacks since 2023. FraudGPT goes even further, marketed on dark web forums and Telegram as an "all-in-one solution" for writing malicious code, building phishing pages, and crafting scam messages with "no boundaries."
How to prevent and mitigate AI social engineering attacks
AI has made social engineering attacks harder to spot, but they still depend on human decisions at the point of execution. The right combination of process, technology, and training can close the gaps that attackers rely on.

Verify out-of-band
If a request involves money, credentials, or sensitive data, verify it through a separate channel. Call the person back on another known number, not the one in the message. For high-risk requests like wire transfers or executive approvals, establish internal code words or challenge questions that an attacker wouldn’t know.
Enforce strict approval workflows for wire transfers and credential resets
No single person should be able to authorize a large transfer or reset critical credentials alone. Require multi-person sign-off for financial transactions above a set threshold, and build mandatory waiting periods into urgent requests. Most AI social engineering attacks rely on urgency and pressure, so slowing the process down is one of the most effective defenses.
Deploy phishing-resistant MFA and zero-trust access controls
Attackers can bypass standard SMS or email-based MFA bySIM swapping or phishing pages that capture one-time codes in real time. Switch to phishing-resistant options like hardware security keys (FIDO2/WebAuthn) or passkeys. Pair this with a zero-trust approach zero-trust approach verify every access request based on identity, device health, and context rather than assuming anyone inside the network is trusted.
Run AI-aware security awareness training
Traditional phishing training focused on spotting bad grammar and suspicious links. That doesn’t hold up against the AI impact on social engineering, where messages now are fluent, personalized, and free of the usual red flags. Update training programs to cover deepfake voice and video calls, AI-crafted emails that mimic internal company tone, and pretexts that reference real projects. Run simulations that include these AI-powered scenarios, so employees experience them before a real attack hits.
Use AI-powered detection and email/voice anomaly tooling
Effective AI social engineering defense means fighting AI with AI. Deploy tools that analyze email metadata, writing patterns, and sender behavior to flag anomalies that human reviewers would miss. There are solutions that detect deepfake artifacts like unnatural audio patterns, poor lip synchronization, and inconsistent lighting. Layer these on top of existing email security gateways rather than relying on filters built for older threats.
Incident response
Unfortunately, even with strong AI social engineering prevention measures in place, some attacks may still get through. Have a clear, rehearsed response plan that covers AI-specific scenarios: a deepfaked executive call, a compromised email thread generated by AI, or a credential harvest through a fake chatbot. Make sure employees know exactly who to contact and how to report a suspected attack without hesitation or fear of blame. The faster a compromised request is flagged, the smaller the damage.
Conclusion
AI social engineering threats are already costing organizations billions, and the tools behind them are only getting cheaper, faster, and easier to access. Cloned voices, fabricated video calls, and AI-crafted phishing messages that read as if they came from a colleague are no longer edge cases. Staying ahead means pairing the right technology with trained people and tight processes, so that when a perfectly crafted message lands, the response is a verification call, not a wire transfer.
