Infosecurity Europe
8-10 June 2027
Excel London

The AI-Led Evolution in Social Engineering

The nature of social engineering attacks has been transformed in recent years, largely because of extensive developments in AI technology.

Previously, phishing was the primary technique used to try and gain access to human accounts, steal credentials or infect victims with malware.

These cyber-attacks, while vast in volume, were often clumsy and unsophisticated in nature, displaying indicators such as grammatical errors and suspicious looking email domain names. This meant that informed individuals, when taking care, could identify these malicious emails with relative ease.

Improvements in various AI technologies, from deepfakes to generative AI tools, has enabled even unsophisticated threat actors to vastly improve the way they target identities and develop novel approaches to social engineering campaigns.

The result is that such attacks have become harder for individuals to detect and organisations’ security teams to defend against.

Amid this trend, several studies have highlighted that identity compromise is now the most dominant entry vector for attackers, overtaking vulnerability exploitation.

Security analysts at SentinelOne have even warned that cyber attackers have become so prolific at abusing legitimate enterprise accounts and identity systems to compromise networks that it has become a “mass-marketed impersonation crisis.”

Top AI Social Engineering Threats in 2026

It is critical that security teams are up to speed on how attackers are utilising AI in social engineering and identity compromise and evolve their strategies accordingly to better protect their organisation. Here are some of the most significant trends we are seeing in this space in 2026. 

AI-Facilitated Voice and Video Campaigns

Malicious actors have been utilising AI tools for social engineering attacks for several years now. As AI tools have become more sophisticated, such techniques have grown in prominence.

This includes ‘vishing’ attacks, which involves attackers typically impersonating IT staff through phone calls to bypass high-value employees’ authentication protocols, such as by resetting passwords. AI can make such campaigns significantly more credible and likely to succeed.

Deepfake technology can be used to accurately impersonate an individual’s voice. In addition, AI tools can be used to create messages or scripts that accurately reflect an individual organisation’s terminology, reporting lines, locations and working patterns.

Cybersecurity company CrowdStrike revealed that it had detected a doubling of the number of intrusions involving vishing as the initial access vector in H1 2026 compared to H1 2025.

Fake IT Worker Campaigns 

Fake IT workers campaigns are another threat vector that continues to be effective with significant assistance from AI. This attack class involves malicious actors creating fake personas to apply for remote IT roles in different industries, including technology.

AI is a critical component across multiple stages of the fraudulent applications process, from creating credible CVs to using deepfake voice and video to conducting remote interviews.

This tactic has been primarily the preserve of North Korean state actors in recent years, and have several purposes, ranging from syphoning IT worker salaries to help fund the DPRK regime and using their privileged access to steal sensitive data from employers’ networks.

Some of these operations have escalated to encompass extortion, whereby the IT workers steal sensitive proprietary data and code from their former employers and hold it “hostage” until a ransom demand is met.

Targeted Email Phishing Campaigns

Email phishing is far from a new tactic, but attackers are utilising AI to refine their approaches, making their emails more targeted and effective.

A report by Cofense published in February 2026 found that AI is allowing threat actors to not only increase the scale and speed of campaigns but also make their phishing emails more convincing and personalised.

This includes the ability to compose emails in near-flawless local languages. In addition, AI can make campaigns highly adaptive based on individual users they are targeting, such as allowing threat actors to dynamically alter logos, signatures, wording, URLs and files according to the specific victim.

In a study published in August 2026, Darktrace noted that attackers investing in quality over “noise” for email phishing campaigns. This is likely at least partly as the result of AI assistance.

For example, the cybersecurity firm found that in H1 2026 around two-thirds of phishing emails passed the DMARC email validation protocols, while 39% featured novel social engineering techniques. Additionally, VIP users were targeted in 25% of observed attacks, suggesting that threat actors are increasingly customising attacks to specific targets.

The goal of email phishing is to convince a user to hand over proof of their identity, whether that's passwords, MFA approvals, session tokens, or application permissions, so attackers can impersonate them and gain access to systems and data.



ClickFix Attacks Continue Meteoric Rise

Since 2025, ClickFix social engineering attacks have grown as a potent attack vector. The aim of such attacks is to socially engineer a victim into pasting attacker-supplied commands into trusted system dialogs to gain access to networks and systems.

The pasted command typically bypasses many anti-virus and cyber defense tools, ultimately categorising the action as legitimate. A fake error or verification message is used to manipulate victims into copying and pasting a malicious script and then running it.

The tactic preys on users’ desire to fix problems themselves rather than alerting their IT team or anyone else. Therefore, it is effective at bypassing security protections as the victim infects themselves.

According to analysis by researchers at ReliaQuest, which examined cyber-attacks taking place between March 1 and May 31, 2026, ClickFix has become the leading means of malware delivery.

Threat actors have used AI to enhance ClickFix campaigns and ReliaQuest researchers found that AI-powered website creation tools have been used to generate ClickFix lures, such as fake CAPTCHA pages and full screen fake BSOD/system recovery prompts.

A Barracuda study noted that AI tools have enabled attackers to rapidly develop accurate ClickFix lures at scale, including fake login portals. 

Conclusion 

Social engineering attacks are a rapidly evolving area of cybersecurity, and practitioners must be aware of how threat actors are using AI to enhance their campaigns.

Whether its voice and video impersonation or generating web pages of major brands, AI is making social engineering attacks much harder for individuals and traditional security tools alike to detect.

Security teams must revamp both their technical protections in areas like email, and awareness training programmes to better equip employees to detect such attacks.


ADVERTISEMENT


Enjoyed this article? Make sure to share it!



Looking for something else?


Tags


ADVERTISEMENT


ADVERTISEMENT