AI-powered hackers shift gears: social engineering and supply chain attacks spark billion-dollar breaches

The gist
AI-powered hackers have unleashed a tidal wave of hyper-personalized social engineering and supply chain attacks, fueling billion-dollar breaches and leaving traditional defenses in the dust.
What to know
- By late 2025, AI-driven vishing, deepfake voices, and phishing surged 449%, with groups like Scattered Spider targeting retail giants such as M&S and Harrods.
- Attackers combined AI-powered social engineering with multi-vector supply chain exploits—including a $1.4B Bybit breach and hijacked developer tools like GitHub Desktop to steal signing keys.
- Despite new defenses like FIDO2 MFA and behavior-based detection, by mid-2026 AI-enhanced social engineering and supply chain attacks dominated, exploiting AI system flaws and causing billion-dollar losses.
AI Supercharges Social Scams
Attackers now deploy deepfake voices, hyper-personalized phishing, and real-time AI chatbots across trusted platforms, erasing traditional red flags and overwhelming human intuition.
By late 2025, AI-driven social engineering attacks surged dramatically, with KnowBe4 reporting a staggering 449% increase in AI-powered vishing attacks and a 67% rise in abuse of legitimate platforms. Cybercriminal groups like Scattered Spider exploited this momentum, breaching high-profile retailers such as M&S and Harrods to launch convincing phishing campaigns that leveraged trusted brand impersonations, highlighting a strategic shift toward sophisticated, targeted exploitation of established digital trust.
The integration of large language models and multi-modal AI capabilities revolutionized social engineering by enabling attackers to generate thousands of hyper-personalized, grammatically flawless phishing lures at scale, while also deploying deepfake voice snippets and interactive chatbots. This evolution rendered traditional phishing indicators obsolete, as AI-crafted messages seamlessly mimic individual communication styles and organizational context, effectively bypassing human intuition and conventional detection methods.
AI-powered attacks expanded beyond email to infiltrate trusted communication channels like Slack, Teams, Jira, and even calendar invites, employing coordinated, context-aware tactics such as live vishing calls paired with MFA push notifications to outmaneuver user defenses. Notably, the emergence of 'ChatOps Phishing'—where victims engage in real-time with AI bots impersonating IT support—exemplifies the sophisticated, multi-layered manipulation now possible, as attackers blend deepfake voicemails, emails, and interactive chatbots to maximize compromise success.
By early 2026, real-world incidents underscored the potency of AI-driven social engineering: CrowdStrike documented a 442% rise in vishing attacks in 2024, fueled by voice cloning technology that enabled scammers to convincingly impersonate executives, as seen in a high-profile Ferrari CEO voice spoof. Meanwhile, targeted campaigns like ShinyHunters’ Okta SSO voice phishing exploited MFA weaknesses through custom phishing kits and domain spoofing, illustrating a shift from broad spray-and-pray tactics to precise, AI-enhanced intrusions that grant attackers 'keys to the kingdom' across corporate networks.
Supply Chains: The New Battleground
Cybercriminals are hijacking developer tools and software updates, merging AI-powered social engineering with multi-vector supply chain exploits that cripple core infrastructure and drain billions.
Throughout 2025 and into 2026, attackers significantly escalated the complexity of their operations by merging AI-driven social engineering with sophisticated supply chain exploits, targeting trusted developer environments and critical infrastructure. Notably, the ClickFix supply chain attacks exemplified this trend by tricking users into executing multi-step malicious commands, while the February 2025 Bybit incident alone caused approximately $1.4 billion in losses by infiltrating third-party multi-sig wallet providers to bypass multi-approval security mechanisms. This strategic shift from attacking individual protocols to compromising core service providers and developer tools underscored the disproportionate financial impact of supply chain attacks, which, despite their rarity, accounted for nearly half of the total Web3 sector losses that year.
By early 2026, threat actors refined their multi-vector attack methodologies by hijacking trusted software distribution channels and developer tools to stealthily deliver malware. Campaigns like ClickFix evolved to deploy fake update installers and scripted payloads disguised as legitimate Windows updates or IT service tools, while others hijacked GitHub Desktop repositories to inject backdoors into CI/CD pipelines, stealing signing keys and compromising build environments. The Shiny Hunters group further advanced this approach by combining voice phishing with custom phishing kits targeting Okta SSO services, registering approximately 150 domains to mimic MFA sites and maintain persistent network access through attacker-registered MFA devices, illustrating a sophisticated blend of social engineering and supply chain exploitation.
Attackers increasingly exploited the trust placed in remote monitoring and management (RMM) tools and AI developer environments to bypass traditional security controls and maintain persistence. Campaigns delivering malware through digitally signed RMM software like Trust Connect leveraged socially engineered lures themed around tax season and official documents to infect tens of thousands of users, while advanced techniques such as BYOVD attacks using signed Huawei audio drivers disabled endpoint detection systems from kernel mode. Simultaneously, supply chain attacks targeting AI coding agents—such as Claude Code and GitHub Copilot—emerged, with attackers registering malicious MCP servers within AI workflows to silently execute code and steal credentials, signaling a shift towards exploiting developer trust in automation rather than conventional vulnerabilities.
The convergence of AI-enhanced social engineering with multi-vector supply chain attacks culminated in campaigns that leveraged diverse trusted platforms and infrastructure to maximize stealth and impact. The GlassWorm campaign, for instance, utilized multiple package repositories like npm and PyPI alongside Solana blockchain dead drops for command and control, combining malware delivery with fake wallet recovery prompts to target crypto users. Similarly, attackers manipulated SEO poisoning to distribute trojanized VPN clients mimicking vendors such as SonicWall and Ivanti, employing digitally signed malware to harvest credentials and evade detection by redirecting victims to legitimate sites post-infection. These operations, documented by Microsoft and JFrog, highlight a 451% surge in malicious npm packages and underscore the critical need for embedding security into development pipelines and architectural design to counteract these sophisticated, multi-vector threats.
Malware Masquerades as Trust
AI-driven malware campaigns weaponize legitimate platforms and software updates, using stealthy infostealers and RATs to automate credential theft and payment fraud at unprecedented scale.
By late 2025, malware campaigns like the ClickFix phishing wave demonstrated a marked increase in complexity and scale by embedding sophisticated infostealers such as Shemos and RATs like PureRAT within trusted platforms like Booking.com partner networks. These campaigns combined advanced social engineering tactics—including instructional videos and countdown timers—with credential theft and data exfiltration, leveraging stolen information on dark web forums such as LolzTeam to perpetuate widespread infection and payment fraud.
Entering 2026, attackers refined their methods by disguising malware payloads as legitimate software updates—ranging from Windows and video driver installers to remote monitoring and management (RMM) tools—deployed through SEO poisoning, malvertising, and phishing campaigns. Notably, campaigns like Storm-2561 and ClickFix exploited user conditioning to 'fix problems with a click,' while hijacking developer tools and supply chains, including spoofed GitHub Desktop installers and AI coding environments, to inject backdoors and steal signing keys, exemplifying the growing sophistication and multi-vector nature of AI-augmented malware.
The integration of AI into malware operations accelerated the scale and stealth of attacks by automating tasks such as phishing, vulnerability analysis, and code modification, while leveraging legitimate platforms like Discord, Cloudflare, and Netlify to stage payloads that evade detection through in-memory execution and runtime mutation. Campaigns increasingly exploited AI-generated social engineering vectors, including fake Zoom calls and AI chatbot poisoning, to distribute RATs and infostealers under the guise of trusted software updates or AI tools, as seen in the IRS phishing attack affecting 29,000 users and the GlassWorm campaign targeting crypto wallets via blockchain dead drops.
By mid-2026, the shift toward exploiting software vulnerabilities outpaced traditional credential theft, with AI-driven attackers leveraging zero-click and network-facing exploits that reduced defenders’ response windows to a median of just five days. Concurrently, malware campaigns employed sophisticated evasion techniques such as layered encryption, fileless execution, and signed driver abuse to disable endpoint detection and maintain persistence through stacked remote access tools. The widespread abuse of legitimate RMM software and commercial cloaking services, combined with multi-vector infection strategies involving SEO poisoning, malvertising, and social engineering lures like ClickFix, underscored the unprecedented complexity and scale of AI-augmented malware operations targeting both corporate and consumer environments.
Layered Defenses or Bust
Signature-based security is obsolete—only dynamic, multi-layered defenses combining behavior analytics, strict MFA, and empowered employees can keep pace with AI-crafted attacks.
By late 2025, industry experts emphasized that combating AI-driven social engineering demands a sophisticated, multi-layered defense strategy integrating people, processes, and technology. Signature-based detection methods had become obsolete as AI generates infinite phishing variations, prompting a shift toward dynamic security postures that detect and respond to attack processes rather than static payloads. Key process improvements such as mandatory out-of-band verification for critical requests and streamlined phishing reporting—like one-click 'Phish-to-Report' hotkeys—empower employees to serve as vigilant frontline sensors, reinforcing the human firewall with continuous, AI-generated micro-drills and clear communication policies.
Technological defenses evolved beyond traditional filters to embrace phish-resistant multi-factor authentication standards like FIDO2 and passkeys, alongside strict email authentication protocols (SPF, DKIM, DMARC with reject policies) and behavior-based anomaly detection. These advances are critical to counter sophisticated tactics such as 'ChatOps Phishing,' where AI bots engage victims in real-time interactive chats to bypass conventional safeguards by manipulating MFA approvals or coaxing software installations. This dynamic, layered approach—combining hardened tech, robust processes, and empowered personnel—became the blueprint for resilience against AI-enhanced social engineering.
However, by early 2026, the threat landscape had shifted as AI-driven vulnerability exploits overtook social engineering as the leading attack vector, accounting for 38% of incidents compared to 24% for phishing, according to Rapid7’s Q1 report. The median time from vulnerability disclosure to catalog inclusion shrank to just five days, underscoring the urgent need for adaptive defense strategies that prioritize rapid patching and vulnerability management alongside layered social engineering countermeasures. This evolution highlights the growing complexity organizations face in defending against AI-powered threats across both technical and human domains.
AI Arms Race Escalates
As attackers exploit flaws in AI systems themselves, billion-dollar breaches and persistent vulnerabilities force defenders into a relentless cycle of patching, innovation, and ecosystem-wide coordination.
By mid-2026, AI-enhanced social engineering and supply chain attacks have solidified as dominant and evolving threats within the cybersecurity landscape. Reports from CertiK and Visa reveal a surge in sophisticated phishing campaigns and supply chain exploits targeting critical service providers rather than isolated protocols, exemplified by the $1 billion AI-powered scams flagged by Visa and the $1.4 billion loss from the February 2025 Bybit incident. This shift underscores how attackers leverage AI to craft highly realistic, multilingual phishing websites and wallet popups that evade traditional detection methods, blending on-chain and social media data for precision targeting.
The persistent vulnerabilities in AI systems themselves have become a critical concern, as attackers exploit AI-specific weaknesses alongside conventional malware tactics. CyberWire Daily’s June 2026 report highlights ongoing cycles of patching and mitigation to counteract new malware delivery pathways targeting AI models, while Microsoft’s alerts reveal AI chatbot-driven cryptojacking campaigns that bypass user skepticism and enable persistent unauthorized remote access. These developments illustrate that AI, while a powerful tool for defense, simultaneously expands the attack surface and demands continuous innovation in security approaches.
Despite advances in AI-driven vulnerability discovery, social engineering attacks—particularly voice phishing and AI-assisted lateral movement—remain stubbornly resistant to automated defenses. The Salt Typhoon breaches of major telecoms like AT&T and Verizon in mid-2026, attributed to a Chinese state-backed group, exemplify how critical infrastructure continues to suffer from these gaps. Experts, including those cited by CERT-In, emphasize that AI’s future role in detecting or mitigating such attacks is uncertain, reinforcing the urgent need for adaptive governance, multi-factor authentication, zero trust principles, and ecosystem-wide coordination to build resilience.
The evolving threat landscape has catalyzed a paradigm shift in cybersecurity governance, moving security from a reactive, post-incident response to an integral component of Web3 project design and operation. CertiK’s 2025 report notes regulatory advances across the US, EU, Singapore, and Hong Kong fostering normative security frameworks, while industry leaders call for continuous innovation and coordinated defense strategies. This holistic approach—embedding security into architecture, development, and user experience—is increasingly recognized as essential for projects to withstand AI-enhanced threats and emerge competitive in the rapidly maturing ecosystem.








