AI security

What is AI-Powered Social Engineering?

AI now writes flawless phishing, clones voices from seconds of audio and fakes live video calls. Here is how AI-powered social engineering works, the real cases and the one habit that stops it.

Key takeaways
  • AI-powered social engineering uses AI to write convincing messages, clone voices and fake video calls, stripping away the spelling and grammar errors that used to reveal a scam.
  • The UK NCSC judged in January 2024 that AI will almost certainly increase the volume and impact of cyber attacks, with the biggest gain for attackers in social engineering.
  • In a 2024 controlled study, AI-written spear-phishing matched human experts at a 54 percent click-through rate, against 12 percent for generic phishing.
  • Voice cloning needs only a few seconds of audio, and criminals now run real-time deepfake video calls, per FBI warnings.
  • Business email compromise, the executive-impersonation scam AI makes easier, caused 2.77 billion dollars in reported US losses in 2024, per the FBI.
  • A finance worker at Arup paid out about 25 million dollars in 2024 after a video call on which the CFO and colleagues were all deepfakes.
  • A Ferrari executive stopped a voice-clone scam the same year by asking the caller a question only the real CEO could answer.
  • Under Cybersäkerhetslagen, in force since 15 January 2026, NIS2 makes security awareness training a required measure and holds boards personally accountable.
  • The EU AI Act requires deepfakes to be labelled from 2 August 2026, but criminals will not comply, so the duty protects the information ecosystem rather than your organisation directly.
  • The one control that works is verifying any unusual or high-value request through a second known channel before acting.

The Basics of AI-Powered Social Engineering

AI-powered social engineering is the use of artificial intelligence to manipulate people into handing over money, credentials or access. Attackers use generative AI to write convincing messages, clone voices and fake video calls so the old warning signs of a scam mostly disappear. It is social engineering made cheaper, faster and far more believable.

Social engineering itself is not new. What is new is the tooling. The UK National Cyber Security Centre (NCSC) judged in January 2024 that AI will almost certainly increase the volume and heighten the impact of cyber attacks and that the biggest gain for attackers is in social engineering. In plain terms, a trick that once needed a skilled fraudster and several days now takes minutes and reads perfectly.

How AI Changes Social Engineering

Older scams often gave themselves away. Clumsy grammar, an odd greeting or a translation error was usually enough to make someone pause. Generative AI removes those tells. The NCSC notes that AI can produce fluent and personalised lures without the spelling and grammatical mistakes that used to reveal phishing.

How AI Changes Social Engineering

It also changes the economics of an attack. In a controlled study published in 2024, researchers led by Fred Heiding at Harvard found that fully AI-automated spear-phishing emails achieved a 54 percent click-through rate, matching human experts and far above the 12 percent rate for generic mass phishing. The AI did the background research and wrote each message at a fraction of the usual cost.

The same leap has reached audio and video. The FBI warns that criminals can clone a usable voice from a short audio clip and can run real-time video calls that impersonate an executive. Current research shows as little as a few seconds of recorded speech can be enough. An AI chatbot can also hold a convincing conversation for weeks which is what powers long-running romance and investment scams.

Types of AI-Powered Social Engineering Attacks

AI-powered social engineering takes several forms. These are the main ones to know.

  • AI phishing and spear-phishing: Mass emails and targeted messages written by AI to look personal and legitimate at a scale no human team could match.
  • Voice cloning and vishing: A cloned voice built from a short audio sample used in calls or voicemails to impersonate a manager, a colleague or a family member.
  • Deepfake video: A faked live video call or recording that puts a trusted face, often a senior executive, behind a fraudulent request.
  • AI chatbots for long cons: Automated chat that sounds human and sustains romance or investment scams over weeks, building trust before the ask.
  • Synthetic identity and verification bypass: AI-generated faces, voices and documents used to pass identity checks and open accounts or reset access.

The Business Impact

The money at stake is large and well documented. In its 2024 Internet Crime Report the FBI found that business email compromise, the executive-impersonation scam that AI now makes easier caused 2.77 billion dollars in reported losses in the United States alone. Phishing and spoofing were the single most reported crime of the year.

The trend is upward. The FBI’s 2025 report logged over one million complaints, up from 859,532 the year before with AI-related fraud among the costliest categories. Because AI does the hard work, the barrier to entry has dropped. Smaller organisations are now targets alongside large enterprises.

The deeper cost is to trust. When a familiar face or voice can be faked, the usual human checks stop working. Staff can no longer rely on recognising a caller which means verification has to move from instinct to process. Done badly, that shift is where the losses happen.

Real-World Cases

The Arup Deepfake Video Call

In 2024 a finance worker at the Hong Kong office of Arup, the global engineering firm behind the Sydney Opera House, was invited to a video call with the company’s chief financial officer and several colleagues. Every person on that call was an AI deepfake, built from public footage.

The worker had first suspected a phishing email that asked for a secret transaction. Seeing the familiar faces on the call put his doubts to rest and he approved a series of transfers totalling about 25 million dollars. He only discovered the fraud after checking with head office. Hong Kong police disclosed the case in February 2024 and Arup later confirmed it was the firm involved, as CNN reported.

One habit would have stopped it. A call-back to the CFO on a number the worker already held before any money moved, would have exposed the fake.

Real-World Cases

The Ferrari Voice Clone That Failed

In July 2024 an executive at Ferrari received WhatsApp messages from an unknown number claiming to be the chief executive, Benedetto Vigna. A phone call followed using a clone of Vigna’s voice that captured his southern-Italian accent. The caller pushed an urgent and confidential acquisition and an NDA to sign at once.

The executive grew suspicious and asked the caller a question only the real Vigna could answer, about a book he had recently recommended. The call ended abruptly. Ferrari lost nothing. Bloomberg reported the attempt.

AI Voice Memos Impersonating Officials

Not every case targets a company payment. Through 2025 the FBI warned that attackers were sending AI-generated voice memos impersonating senior US officials to reach current and former officials and their contacts.

The aim was to build rapport and then move the target onto a separate encrypted app where access could be harvested. The FBI’s advice is direct. If a known contact reaches you on a new number or platform, confirm it through a channel you have used before.

AI-Powered Social Engineering and Compliance

For Swedish organisations this is now a legal matter, not only a security one. NIS2 is in force in Sweden as Cybersäkerhetslagen (SFS 2025:1506) since 15 January 2026. Article 21 lists security awareness training as a required measure and Article 20 makes the board responsible for approving and overseeing security, with members personally accountable.

If an attack succeeds and disrupts services, the incident-reporting clock starts. Cybersäkerhetslagen follows the NIS2 cascade to MCF (formerly MSB) and the sector authority, a 24-hour early warning, a 72-hour full notification and a final report within one month. Where personal data is exposed, GDPR Article 33 adds a separate 72-hour notification to IMY.

Financial entities have a further duty under DORA Article 17 which governs ICT incident management and is supervised by Finansinspektionen.

The EU AI Act adds a twist. From 2 August 2026 its Article 50 requires deepfakes to be labelled but that duty binds legitimate users of AI. A fraudster will never label a malicious fake so the AI Act supports the wider information ecosystem rather than shielding you from a targeted attack. Your real protection is the training and verification the other rules require.

How to Spot AI-Powered Social Engineering

You cannot reliably spot a modern fake by eye or ear. Real-time voice and video fakes now pass casual inspection so the tells to watch are behavioural, in the context around the request.

  • Urgency and secrecy: A request that cannot wait and must be kept confidential.
  • An unusual channel: A manager or supplier suddenly messaging on WhatsApp, a personal number or a surprise video call.
  • Pressure to skip the process: A push to bypass the normal payment or sign-off steps just this once.
  • A move to another app: An early nudge to continue on a different or encrypted platform.
  • An unexpected money or access request: A change of bank details, a new payee or a request for credentials or codes.

If several of these appear together, treat the request as unverified until you have checked it however familiar the face or voice.

How to Defend Against AI-Powered Social Engineering

The single most effective control is simple. Verify any unusual or high-value request through a second known channel before you act, and never through the channel the request arrived on. This one habit would have stopped the Arup loss and it is what saved Ferrari.

How to Defend Against AI-Powered Social Engineering

Build that verification step into how your organisation actually works.

  • Require two people to approve payments and supplier bank-detail changes above a set threshold.
  • Agree a call-back protocol so unusual requests are confirmed on a number already on file.
  • Set a code word or challenge question for sensitive requests, as Ferrari’s executive used.
  • Run regular security awareness training and phishing simulations so staff practise the habit.
  • Turn on multi-factor authentication and email authentication (SPF, DKIM and DMARC) to blunt account takeover and spoofing.
  • Limit how much executive voice and video you publish since that footage is the raw material for a clone.
  • Add AI detection and response that can flag anomalies quickly when a lure does land.

No single tool catches every fake. The organisations that avoid the loss are the ones that made verification a routine step rather than a judgement call under pressure.

Myths & Facts

Myth

I can spot a deepfake or an AI scam if I pay attention.

This only targets big corporations.

A live video or voice call proves the person is real.

AI phishing is easy to spot because scam emails are badly written.

The EU AI Act will stop criminals using deepfakes against us.

Security awareness training is optional.

Fact

Real-time voice and video fakes now pass casual inspection. The people fooled at Arup were looking at familiar faces. Verification through a separate channel, not your eyes or ears, is the control.

AI lowers the cost of each attack, so small and mid-sized organisations are now targets alongside large ones. The FBI logged over a million cybercrime complaints in 2025.

At Arup every colleague on the call was a deepfake. A call is only a channel, and channels can be faked. Confirm the request another way before you act.

That tell is gone. The NCSC notes AI produces fluent and personalised messages, and a 2024 study found AI emails matched human experts for click-through.

The AI Act's labelling duty binds legitimate users of AI. A fraudster will never label a fake, so it does not shield you from a targeted scam.

Under NIS2 and Cybersäkerhetslagen, awareness training is a required security measure and boards can be held personally accountable for failing to oversee it.

Test Yourself

Four real-world scenarios, then six knowledge questions. See how prepared you would be under pressure.

Scenario Simulation

  1. You are in finance. Your CFO joins a video call with two colleagues you recognise and asks you to make an urgent and confidential transfer today.

    What do you do?

    • Make the transfer, since the CFO and colleagues are all on the call.
    • Call the CFO back on the number you already have before moving any money.
    • Reply on the same call to double-check the bank details.
  2. A caller with your CEO's exact voice and accent asks you to arrange a secret acquisition payment and to keep it confidential.

    How do you respond?

    • Ask a question only the real CEO could answer before doing anything.
    • Comply quickly, because the voice is unmistakable.
    • Email the details to the CEO's assistant to arrange it.
  3. A supplier emails that their bank details have changed and asks you to update the payee for the next invoice.

    What is the safe next step?

    • Update the details and pay, since the email is from the usual address.
    • Confirm the change by calling the supplier on a number you already hold.
    • Reply to the email to ask them to confirm the new details.
  4. You receive a well-written message that seems to come from IT, asking you to log in through a link to keep your account active.

    What do you do?

    • Assume it is genuine, because the writing is polished and error-free.
    • Avoid the link and reach IT through a channel you already use.
    • Click the link but do not enter your password.

Knowledge Test

  1. Roughly how much audio can be enough to clone a usable voice, per FBI warnings?

    • A few seconds
    • At least ten minutes
    • A full hour
    • Voices cannot be cloned

    The FBI warns that a few seconds of recorded speech can be enough to clone a voice.

  2. In a 2024 controlled study, how did fully AI-automated spear-phishing compare with human experts?

    • It matched them, at about 54 percent click-through
    • It was far worse than generic phishing
    • It failed to personalise messages
    • It was easy to detect

    AI-automated emails matched human experts at a 54 percent click-through rate, against 12 percent for generic phishing.

  3. What made the Arup video-call fraud succeed?

    • The CFO and colleagues on the call were all deepfakes
    • A stolen password
    • A malware attachment
    • A tapped phone line

    Every participant the finance worker saw was an AI deepfake built from public footage.

  4. Which single habit best defends against deepfake CEO fraud?

    • Verify unusual requests on a second known channel
    • Look closely at the caller's face
    • Trust requests that come by video
    • Reply on the same channel to confirm

    Out-of-band verification on a separate known channel is the control that repeatedly works.

  5. Under NIS2 and Cybersäkerhetslagen, security awareness training is:

    • A required security measure
    • Optional guidance
    • Only for IT staff
    • Banned

    NIS2 lists security awareness training as a required measure, and Cybersäkerhetslagen brings it into Swedish law.

  6. Does the EU AI Act's deepfake-labelling duty stop criminals attacking you?

    • No, it binds legitimate AI users, not attackers
    • Yes, criminals must label deepfakes
    • Yes, it blocks all deepfakes
    • It does not mention deepfakes

    The Article 50 duty applies to legitimate users of AI, and criminals will not label a malicious fake.

Take It with You

Share the Summary PDF with Your Team

A short distilled brief in PDF: key findings, red flags and action steps.

Download summary PDF

Why Training Matters

Technology alone cannot stop an attack aimed at a person. When a request looks and sounds legitimate, the deciding factor is whether the employee in front of it pauses and verifies. That is a trained habit, not a natural instinct.

Under NIS2 and Cybersäkerhetslagen, security awareness training is a required measure and the board is accountable for it. Regular training and realistic phishing simulations give staff safe practice at spotting pressure and checking a request before money or access moves. eBuilder Security provides security awareness and phishing-simulation training built around exactly this verification habit.

Frequently Asked Questions

What is AI-powered social engineering?

AI-powered social engineering is the use of artificial intelligence to trick people into sending money, sharing credentials or granting access. Attackers use generative AI to write convincing messages, clone voices and fake video calls. It makes classic scams cheaper, faster and far harder to detect than older, human-written attempts.

How is AI-powered social engineering different from ordinary phishing?

The difference is quality and scale. Ordinary phishing often gave itself away with clumsy grammar or an odd greeting. Generative AI removes those tells and personalises each message using online research. In a 2024 controlled study, AI-written spear-phishing matched human experts at a 54 percent click-through rate, well above generic phishing.

How much audio does it take to clone someone's voice?

Only a few seconds, according to FBI warnings. Short clips scraped from social media, webinars or voicemail greetings can be enough to build a usable clone. That is why a familiar voice on the phone is no longer proof of identity, and why unusual requests should be verified on a separate known channel.

How can I tell if a video or voice call is a deepfake?

You often cannot tell by watching or listening, because real-time fakes now pass casual inspection. Instead of trusting the face or voice, watch the behaviour, such as urgency, secrecy, an unusual channel or pressure to skip normal checks. Then confirm the request through a channel you already trust before acting.

What is the single best way to stop deepfake CEO fraud?

Verify every unusual or high-value request through a second known channel before you act, and never reply through the channel it arrived on. This one habit would have prevented the 25 million dollar loss at Arup, and it is exactly what saved Ferrari when an executive challenged a voice-clone caller.

Does NIS2 or Cybersäkerhetslagen require us to train staff against this?

Yes. NIS2, in force in Sweden as Cybersäkerhetslagen since 15 January 2026, lists security awareness training as a required measure under Article 21. Article 20 makes the board responsible for overseeing security, with members personally accountable. Training that builds a verification habit is a direct way to meet that duty.

Does the EU AI Act protect us from criminal deepfakes?

Not directly. From 2 August 2026 the EU AI Act requires deepfakes to be labelled and AI-generated content to be marked, but that duty binds legitimate users of AI. Criminals will not label a malicious fake, so the AI Act supports the wider information ecosystem rather than shielding your organisation from a targeted attack.

Are small and mid-sized companies really targets?

Yes. Because AI does the reconnaissance and writing, the cost of each attack has fallen, so criminals can target smaller organisations profitably. The FBI logged over one million cybercrime complaints in 2025, up from 859,532 the year before. Any organisation that moves money or holds useful access is worth targeting.

You Understand the Risk.
Now See Where You Stand.

Book a 30-minute briefing with one of our analysts, or run the free breach check first to find out what attackers already know about your organisation.

Book a 30-Min Briefing
No sales pitch, just a straight assessment

How eBuilder Security Can Help

Awareness is the first layer. These are the services that turn it into measurable protection.