AI deepfakes supercharge phishing: security experts sound alarm

The gist
AI-powered deepfakes and hyper-personalized phishing are fueling an unprecedented surge in social engineering attacks, leaving even the best-trained employees and security tools scrambling to keep up.
What to know
- AI-driven vishing and phishing attacks skyrocketed 449% by late 2025, with cybercriminals using deepfake voices, video impersonations, and chatbots to outsmart traditional defenses.
- Attackers are exploiting identity features in cloud platforms like Microsoft 365 and Okta, abusing device registration and MFA to maintain stealthy, persistent access.
- Experts warn that classic employee training is failing—organizations must adopt phishing-resistant MFA, continuous behavioral monitoring, and rigorous out-of-band verification to counter these AI-fueled threats.
AI Phishing Gets Personal
Cybercriminals are leveraging multi-modal AI to craft hyper-personalized, context-aware phishing lures that mimic trusted brands and internal departments, making attacks nearly indistinguishable from legitimate communications.
By late 2025, AI-powered social engineering attacks had surged dramatically, with KnowBe4 reporting a 449% increase in AI-driven vishing and a 67% rise in abuse of legitimate platforms to bypass defenses. Cybercriminal groups like Scattered Spider exploited breaches at retailers such as M&S and Harrods to impersonate trusted brands, while attackers timed campaigns around seasonal events like tax deadlines, leveraging AI-generated content to scale and sophisticate their phishing efforts.
AI has industrialized social engineering, enabling attackers to rapidly produce thousands of hyper-personalized phishing lures that reference specific company projects, colleagues, or announcements, making detection exceedingly difficult. KnowBe4's Q3 2025 report highlights that 90% of user interactions stem from emails personalized with company names and internal topics, often impersonating HR or IT departments, while 70% of phishing attempts used branded landing pages spoofing Microsoft, LinkedIn, and Amazon to enhance credibility.
The rise of multi-modal AI-generated content—such as deepfake voice snippets for vishing, video impersonations of executives, and interactive AI chatbots—has transformed phishing into a sophisticated, immersive attack vector. At DEFCON 2024, an AI-powered vishing chatbot outperformed human social engineers by using varied voices and tactics to extract sensitive information, underscoring how traditional red flags like poor grammar or generic messaging no longer suffice as AI crafts perfectly believable, context-aware lures.
By early 2026, voice cloning technology supercharged vishing attacks by convincingly impersonating executives, as seen in a 2024 Ferrari case, while attackers exploited low-tech delivery methods like emails prompting victims to call scam numbers, bypassing advanced email defenses. Experts emphasize that defending against these threats requires layered strategies combining phish-resistant MFA, strict out-of-band verification, and empowering employees to question suspicious requests—even from high-ranking officials—since voice alone can no longer be trusted as authentication.
Identity Exploits Go Multi-Channel
Attackers now combine deepfake voices, spoofed domains, and cross-platform messaging to infiltrate organizations, exploiting identity infrastructure and human trust across email, chat, and voice.
By late 2025, attackers had honed their tactics to leverage AI-driven profiling for highly personalized phishing campaigns, with KnowBe4 reporting that 90% of user interactions stemmed from emails tailored using company names and internal topics. These attacks often impersonated trusted internal departments like HR and IT, significantly boosting their success rates. Moreover, attackers exploited multiple communication channels and well-known brands such as Microsoft, LinkedIn, and Amazon, employing domain spoofing and familiar file types like PDFs to bypass defenses and increase engagement.
In early 2026, the evolution of AI-powered social engineering expanded beyond email into multi-modal assaults across Slack, Teams, Jira, and calendar invites, often combining deepfake voicemails and interactive chatbots to manipulate targets. Campaigns like ShinyHunters’ Okta SSO voice phishing exemplify this trend, where attackers registered hundreds of spoofed domains to steal MFA codes and register persistent devices, enabling prolonged access to enterprise environments. This multi-channel approach, including coordinated live vishing calls that prompt MFA approvals, demonstrates a sophisticated psychological manipulation that circumvents traditional technical defenses.
The increasing focus on identity as the new security perimeter is underscored by high-profile cases where attackers exploited compromised shared mailboxes and internal communications to conduct precise social engineering attacks. For instance, a healthcare payroll heist involved attackers impersonating locked-out physicians to reset credentials and MFA, gaining legitimate access to redirect funds without triggering alarms. This identity-first approach, prevalent across sectors including manufacturing and government, leverages leaked credentials, vishing, and executive impersonation to infiltrate trusted environments, highlighting the critical vulnerability of identity infrastructure and the human element in security.
By mid-2026, attackers had refined their multi-modal social engineering campaigns to target high-value assets such as credentials, wire fraud opportunities, and enterprise cloud environments using AI-enhanced techniques. Notable incidents include the Helix group’s vishing and MFA abuse to exfiltrate SharePoint data, and sophisticated Business Email Compromise (BEC) operations that combine organizational profiling with pressure tactics across email, call centers, and SaaS accounts. These campaigns exploit trusted infrastructure like Microsoft 365 and Google Workspace, leveraging domain authentication and legitimate cloud services to evade detection, while also localizing phishing content with native language styles and exploiting global events like the FIFA World Cup to maximize impact.
Cloud Identity Under Siege
Sophisticated adversaries abuse device registration, OAuth flows, and SSO platforms like Okta to gain persistent, stealthy access, blending malicious activity with legitimate business operations.
Attackers have increasingly exploited identity features within cloud environments like Microsoft 365 and Google Workspace to maintain long-term persistence and evade detection. Techniques such as device registration abuse allow adversaries to bypass multi-factor authentication (MFA) even after password resets, effectively turning trusted devices into persistent footholds. Additionally, attackers leverage legitimate business workflows—like ServiceNow ticket escalations and Exchange inbox forwarding rules—to blend seamlessly into normal operations, making their activities appear legitimate and thus bypassing traditional security controls.
The rise of OAuth device code phishing and malicious OAuth applications has exposed critical vulnerabilities in cloud authentication flows, with state-sponsored groups and sophisticated threat actors exploiting these mechanisms to gain full account access. Proofpoint and other researchers have documented surges in these attacks since late 2025, where phishing emails containing QR codes or links trick users into granting access tokens on legitimate Microsoft login pages. These attacks highlight the inadequacy of perimeter and signature-based defenses, as attackers exploit legitimate authentication flows and man-in-the-middle phishing kits—like the Tycoon kit—to capture MFA tokens and session cookies in real time.
Single sign-on (SSO) services such as Okta represent a high-value target due to their role as a consolidated access point across enterprise applications. Attackers employ targeted voice phishing campaigns combined with custom phishing domains that mimic legitimate help desk portals to steal MFA codes and register their own authentication devices, effectively gaining 'keys to the kingdom.' This sophisticated approach enables lateral movement, privilege escalation, and data exfiltration, underscoring the critical risk posed by identity compromise in cloud environments and the limitations of conventional security measures.
Traditional perimeter and signature-based defenses are increasingly inadequate against modern cloud threats, as attackers exploit legitimate infrastructure, digitally signed remote management tools, and trusted business workflows to evade detection. Netscope Threat Labs warns that adversaries use signed remote monitoring software disguised as mandatory updates to blend into normal corporate traffic, while attackers also leverage trusted-cloud phishing within services like Microsoft 365, Google Workspace, and Adobe to host malicious workflows without triggering reputation-based controls. Consequently, defenders must adopt dynamic analysis techniques, behavioral baselining, and identity context to detect subtle deviations in business processes and relationships that signal compromise.
Defending the Identity Perimeter
Security leaders are shifting to layered, identity-centric defenses—combining phishing-resistant MFA, continuous behavioral monitoring, and strict verification—to counteract AI-fueled social engineering.
By late 2025, cybersecurity experts emphasized a fundamental shift toward identity as the new security perimeter, advocating for a layered defense strategy that integrates people, processes, and technology to combat AI-driven social engineering. This approach includes phishing-resistant MFA methods like FIDO2/passkeys tied to specific domains, which effectively neutralize fake login attempts, alongside process innovations such as mandatory out-of-band verification for critical requests and user-friendly phishing reporting mechanisms that transform employees into active sensors. Behavioral anomaly detection focusing on identity and access patterns—such as impossible travel or unusual forwarding rules—has become indispensable, as traditional static text analysis fails against dynamic AI phishing campaigns.
By November 2025, the defense posture against sophisticated identity attacks, exemplified by threat groups like Scattered Spider, had evolved to prioritize comprehensive identity visibility and continuous threat detection. CISOs were urged to discover and classify all identities—human, machine, API keys, AI, and vendors—across diverse environments, stitching them into unified risk and access views. This identity posture hardening involves continuous configuration audits to reduce excessive privileges and eliminate privilege creep, while behavior-based threat detection leverages runtime anomaly detection and cross-system telemetry correlation to identify malicious activity. Additionally, organizations hardened operational processes by validating voice and video interactions to counter vishing and other social engineering tactics.
Entering 2026, the rising sophistication of identity-based attacks, including AI-driven impersonation and multi-channel campaigns, underscored the necessity of continuous identity verification and layered operational controls. Industry leaders like Kavitha Mariapan from Rubrik highlighted that 90% of security professionals view identity attacks as their greatest threat, driving adoption of phishing-resistant MFA and behavioral analysis to detect subtle anomalies in trusted workflows. Attackers increasingly mimic legitimate business applications such as Adobe or DocuSign, prompting organizations to enforce strict payment controls and out-of-band verification to mitigate risks. Platforms like Doppel emerged as AI-native defenders, dismantling cross-channel social engineering attacks and enhancing team resilience.
By mid-2026, the manufacturing sector exemplified the shift from infrastructure-focused to identity-first cyber threats, with credential leaks and vishing surging as primary attack vectors. Attackers exploited complex supply chains and third-party vendors, where 62% of critical suppliers had corporate credentials exposed in stealer logs, amplifying risk across distributed plants and workflows. Multi-stage campaigns combined leaked credentials with trusted hosting services and social media platforms, targeting human-facing workflows like executive impersonation and fraudulent procurement portals. This environment elevated the importance of integrated identity-centric defenses that combine continuous behavioral monitoring, phishing-resistant MFA, and stringent operational controls including auditing international payments and restricting risky login methods such as QR codes.
Training Gaps Fuel Vishing Risk
Traditional security training misses the mark on AI-powered vishing, leaving organizations vulnerable as attackers exploit phone-based psychological manipulation and procedural weaknesses.
By early 2026, it became clear that traditional employee training programs were falling short in preparing staff for the sophisticated nature of AI-driven social engineering attacks, particularly phone-based vishing scams. Stephanie’s observations at DEFCON highlighted that most security training focused narrowly on email and text phishing, neglecting the nuances of voice-based threats, which attackers exploit with alarming success. This gap leaves organizations vulnerable, as evidenced by repeated successful impersonations of employees to reset passwords and bypass weak verification processes, underscoring the urgent need for more comprehensive and scenario-based training that includes phone call scenarios and psychological manipulation tactics.
Human judgment and rigorous internal controls remain indispensable in combating AI-enhanced social engineering, as technology alone cannot fully mitigate these evolving threats. Cases like the Ferrari 2024 vishing attack demonstrate how personalized verification questions can thwart voice-cloning attempts, while experts like Cheryl Wellman stress moving beyond trust-based detective controls to preventative measures. Organizations must implement layered verification protocols—such as secret phrases, segregation of duties, and multi-channel confirmation—to counteract attackers who exploit procedural weaknesses and the inherent trust humans place in voice communications, a vulnerability Ryan aptly describes as ‘lo-fi meeting high-tech.’
Financial institutions play a pivotal role as frontline defenders against AI-driven fraud by combining employee training, behavioral science insights, and stringent operational controls. JPMorgan Chase’s investment in the AARP BankSafe Initiative exemplifies how understanding psychological manipulation tactics enables earlier fraud prevention, shifting focus from reactive detection to proactive intervention. Moreover, training bank tellers to recognize suspicious behaviors—such as customers coached over the phone—empowers human agents to disrupt scams in real time, reinforcing that while technology is vital, human vigilance and institutional responsibility remain the cornerstone of effective fraud prevention.
Cultivating a culture where employees feel empowered to question unusual or urgent requests, regardless of the sender’s perceived authority, is critical to organizational resilience against AI-driven social engineering. Practical guidance from multiple sources emphasizes habits like verifying requests through independent channels, slowing down to resist urgency cues, and establishing strict protocols for payment changes. As one expert advises, ‘Make it safe to question unusual requests… no one will be punished for taking steps to prevent fraud,’ reflecting a shift toward embedding human judgment and skepticism as core defenses alongside technological safeguards.
Banks Face AI-Driven Trust Crisis
Deepfake-enabled fraud and sophisticated payment scams are eroding confidence in authentication, forcing banks to adopt advanced detection methods and face new regulatory scrutiny for institutional failures.
By mid-2026, AI-driven fraud has escalated beyond mere financial loss to become a profound trust crisis for banks, with deepfake-enabled scams and losses surging by triple- to quadruple-digit percentages since 2022. This evolution is epitomized by Authorized Push Payment scams, which cleverly bypass traditional fraud controls by mimicking legitimate transactions initiated by genuine account holders on recognized devices, rendering conventional defenses ineffective.
The traditional reliance on successful authentication as a security benchmark is rapidly eroding, as AI's sophisticated capabilities enable attackers to circumvent these mechanisms at scale. As one expert bluntly states, 'successful authentication can no longer serve as a definitive indicator of safety,' underscoring the urgent need for banks to rethink their security paradigms in an AI-permeated threat landscape.
In response to the complexity of AI-enabled fraud, banks are increasingly adopting graph and network analysis techniques to detect intricate fraud rings and money mule networks that evade detection through isolated transaction reviews. This shift towards relationship-based detection is not only a technological imperative but also a regulatory one, as authorities now hold banks directly accountable for AI-related fraud incidents, framing them as institutional control failures rather than mere user errors, thereby intensifying the demand for robust, adaptive detection and response capabilities.









