AI voice clones push social engineering higher

Bleeping Computer ↗

The gist

AI-powered voice clones and deepfake bots are smashing old security, fueling an unprecedented surge in social engineering attacks that outsmart even multi-factor authentication.

What to know

  • AI-driven phishing and vishing attacks soared by more than 400% in 2025–2026, with voice clones successfully impersonating executives—like the Ferrari CEO spoofing incident—and outmaneuvering human defenders at DEFCON.
  • Sophisticated groups such as ShinyHunters are hijacking SSO platforms (Okta, Microsoft Entra) and registering their own MFA devices, granting themselves persistent, high-privilege access to critical SaaS tools.
  • Classic defenses like voice authentication and legacy MFA are being bypassed, forcing organizations to adopt AI-powered anomaly detection, phish-resistant MFA (FIDO2), and relentless employee training to keep up.

AI Turns Phishing Industrial

Cybercriminals now deploy AI-powered voice clones and chatbots to automate thousands of highly convincing attacks, weaponizing trusted brands and exploiting seasonal urgency to overwhelm traditional human defenses.

AI-driven social engineering threats have surged dramatically by 2025, with KnowBe4 reporting a 449% increase in AI-powered vishing attacks and a 67% rise in abuse of legitimate platforms. Cybercriminal groups like Scattered Spider have exploited this trend to breach major retailers such as M&S and Harrods, subsequently launching widespread phishing campaigns that leverage hijacked trusted platforms and time attacks around high-stakes seasonal events like tax deadlines and holidays to maximize impact.

The industrialization of phishing through AI has transformed social engineering from a manual craft into a scalable, automated assault. Large language models now generate thousands of personalized, grammatically flawless lures rapidly, while multi-modal AI capabilities—including deepfake voice snippets and interactive live chats—enable attackers to mimic trusted voices and engage victims in real time, effectively bypassing traditional email security and rendering old phishing detection cues obsolete.

By early 2026, vishing has become a dominant attack vector, with CrowdStrike documenting a 442% increase in 2024 alone, fueled by attackers combining AI voice cloning technology to impersonate executives, as seen in the 2024 Ferrari CEO spoofing incident. DEFCON 2024 showcased AI-powered voice phishing chatbots outperforming humans in eliciting sensitive information, underscoring the urgent need to expand security training beyond email to include phone-based social engineering, and to implement policy-driven verification processes that empower employees to question voice requests—even from senior leaders.

The manufacturing sector exemplifies the escalating scale and complexity of AI-driven identity attacks, where credential leaks have become the primary vector enabling access to supplier portals, VPNs, and cloud services, facilitating business email compromise and invoice fraud. Doppel’s analysis highlights a 47-fold spike in dark web alerts in April 2026 and reveals how interconnected supply chains amplify risk, with a single compromised vendor potentially exposing thousands of downstream organizations. Attackers now orchestrate multi-stage campaigns by combining leaked credentials with trusted hosting platforms, social media, and dark web marketplaces, effectively circumventing traditional defenses.

Sources

Personalized Lures, Multi-Channel Attacks

AI scrapes internal and public data to craft tailored phishing and vishing campaigns that breach collaboration tools and trick users in real time, shifting the threat from broad spam to surgical, high-value exploits.

By late 2025, attackers had harnessed AI to industrialize social engineering, rapidly generating thousands of highly personalized phishing lures that reference internal company details, driving 90% of user interactions according to KnowBe4's Q3 2025 report. These AI-crafted emails often impersonate trusted internal departments like HR and IT, leveraging branded landing pages and domain spoofing of major platforms such as Microsoft, LinkedIn, and Amazon to enhance credibility. This multi-modal approach extends beyond email, incorporating deepfake voice vishing, video impersonations, and interactive chatbots that engage victims in real time, effectively bypassing traditional detection methods as AI mimics organizational communication styles with flawless grammar and contextual accuracy.

Attackers have refined their objectives to focus on high-value outcomes such as credential theft, wire fraud, OAuth over-permissioning, and targeted data exfiltration, employing AI to automate intelligence gathering by scraping public data to build detailed persona graphs that mimic individual communication styles. This enables highly targeted, multi-channel social engineering campaigns that infiltrate collaboration tools like Slack, Teams, Jira, and even calendar invites. Techniques like ChatOps phishing—where victims interact with AI-driven support bots that patiently guide them through compromising actions such as approving MFA prompts—demonstrate the sophisticated, real-time manipulation attackers now wield to circumvent security measures.

By early 2026, targeted campaigns such as the ShinyHunters' Okta SSO voice phishing operation exemplify the shift from broad spray-and-pray tactics to focused assaults on high-value sectors like healthcare, finance, manufacturing, and retail. These campaigns combine AI-enhanced voice phishing, custom phishing kits, and domain spoofing to convincingly impersonate corporate help desks, aiming to register attacker-controlled MFA devices for persistent elevated access. Meanwhile, attackers exploit global events like the FIFA World Cup with large-scale, multilingual phishing waves using thousands of malicious domains, and increasingly weaponize AI chatbots themselves by poisoning recommendations to direct users toward malware-laden downloads, further expanding the attack surface.

In manufacturing and logistics, the threat landscape has evolved into complex, identity-driven attacks that exploit credential leaks, vishing, and executive impersonation to compromise supplier portals, VPNs, and cloud environments. Reports from Doppel and Black Kite highlight how a single compromised vendor can cascade risk across extensive supply chains, with attackers orchestrating multi-stage campaigns that blend leaked credentials, trusted hosting services, social media, and dark web marketplaces. Sophisticated cargo theft schemes now leverage AI to hijack trucking company email accounts, fraudulently book high-value loads—sometimes worth up to $30 million—and potentially introduce advanced international social engineering tactics domestically, signaling a worrying trend of cross-border tactic adoption.

Sources

Identity Breaches Go Nuclear

Attackers exploit SSO and MFA weaknesses to seize high-privilege access, resulting in massive data leaks, extortion, and reputational damage across healthcare, education, and government sectors.

By early 2026, AI-driven social engineering attacks, particularly voice phishing or vishing, had surged dramatically, with CrowdStrike reporting a 442% increase in 2024 alone. These attacks leveraged advanced voice cloning technology to impersonate high-profile executives, such as Ferrari’s CEO, nearly succeeding in high-stakes scenarios like the DEFCON competition where AI bots outperformed human social engineers by extracting detailed technical and personal information. This evolution underscores the growing sophistication and effectiveness of AI-enabled identity attacks that exploit overlooked vulnerabilities in phone-based verification processes.

The ShinyHunters group exemplifies the real-world impact of identity-centric breaches through highly targeted campaigns exploiting enterprise single sign-on (SSO) systems like Okta and Microsoft Entra. Their tactics include registering hundreds of custom domains to impersonate company help desks, phishing for multifactor authentication codes, and registering their own MFA devices to maintain persistent access and escalate privileges. This approach transforms SSO from a convenience feature into a single point of catastrophic failure, granting attackers 'keys to the kingdom' that enable extensive data exfiltration and extortion across multiple SaaS platforms including Salesforce, Google Workspace, and Microsoft 365.

High-profile breaches across diverse sectors illustrate the severe operational, financial, and reputational consequences of identity attacks. Notably, ShinyHunters’ campaigns compromised over 9 million records at Medtronic, exposing sensitive PII and PHI, and nearly 6 million Carnival customer records including passports and loyalty data, prompting extended credit monitoring and legal actions. Similarly, breaches at over 100 universities via Oracle PeopleSoft servers exposed student and administrative data, while the Council of Europe faced extortion threats after losing 300GB of HR files. These incidents highlight persistent vulnerabilities in enterprise software, third-party vendors, and shared mailboxes, emphasizing that attackers exploit human trust and internal processes to bypass traditional security measures.

The operational fallout from these identity-centric breaches extends beyond data loss to include costly ransom demands, protracted legal battles, and stock market pressures, as seen with Medtronic and 7-Eleven. Despite some organizations reporting no immediate operational disruption, the persistent threat of data leaks and extortion forces companies to invest heavily in forensic investigations, system remediation, and long-term identity protection services. Moreover, these attacks expose critical gaps in incident response, supply-chain security, and human-centric defenses, underscoring the urgent need for adaptive frameworks that address social engineering, credential compromise, and cloud service exploitation to mitigate escalating risks.

Sources
Security IntelligenceN2K NetworksPKREThe Cybersecurity Pulse (TCP)PR Newswire - Business Technology

Voice Clones Bypass Trust

AI-powered vishing and help desk impersonations exploit weak phone verification and internal process gaps, allowing attackers to hijack accounts—even when legacy MFA is in place.

By early 2026, AI-enhanced social engineering attacks, particularly vishing campaigns empowered by voice cloning technologies, have profoundly undermined traditional security measures such as voice authentication and signature-based detection. Incidents like the 2024 Ferrari CEO impersonation at DEFCON demonstrated how attackers convincingly bypass voice-based defenses, exploiting human trust in familiar communication channels like phone calls, which remain less fortified than email. Stephanie’s observation that "it's hard to prevent someone from picking up the phone" underscores how these attacks exploit weak verification processes and insufficient security training, enabling AI-driven chatbots to adaptively extract sensitive information and circumvent multi-factor authentication (MFA) by redirecting victims to phishing sites rather than requesting passwords outright.

The growing reliance on Single Sign-On (SSO) platforms and MFA, while essential, has revealed critical vulnerabilities as attackers leverage AI-enhanced voice phishing and credential harvesting to exploit the single point of failure inherent in these systems. The ShinyHunters campaign targeting Okta and Microsoft Entra accounts exemplifies this trend, where attackers not only capture MFA credentials but also register their own authentication devices to maintain persistent, lateral network access across SaaS platforms like Salesforce, Google Workspace, and Slack. This multi-domain impersonation strategy, supported by approximately 150 custom domains mimicking legitimate help desks, highlights how sophisticated social engineering combined with internal process weaknesses can bypass traditional defenses and security monitoring.

Internal process weaknesses, including the use of shared mailboxes and inconsistent security protections across employees, have become prime targets for AI-driven attackers who exploit these human and procedural gaps to bypass MFA and perimeter defenses. Case studies such as the payroll heist involving impersonation of a locked-out physician reveal how attackers manipulate help desk personnel through urgent calls, leading to password and MFA resets without triggering alarms, as security tools often interpret these actions as legitimate internal user behavior. This vulnerability is exacerbated in complex, distributed environments like manufacturing ecosystems, where credential leaks and multi-channel attacks involving messaging apps and fake digital infrastructure further erode the effectiveness of conventional authentication methods.

The limitations of traditional security approaches are further exposed by the increasing sophistication and scale of AI-driven identity attacks, which have rendered perimeter-based assumptions obsolete amid cloud adoption and hybrid work models. Analysts warn that while MFA remains a critical component, it is no longer sufficient alone; continuous identity verification and behavioral analytics are necessary to counteract attackers who exploit trusted communication channels and AI systems with administrative privileges lacking robust identity checks. High-profile breaches at Carnival Cruise Lines and Charter Communications, alongside Meta’s exploited AI support chatbot, illustrate how attackers bypass conventional controls by targeting frontline employees and leveraging AI to impersonate legitimate users, underscoring the urgent need for policy-driven verification and empowering employees to question even high-ranking executives.

Sources
Security IntelligenceIBM TechnologyN2K NetworksREN2K NetworksHacking Humans

Defense Evolves: Identity Is Core

With signature-based detection failing, organizations now rely on adaptive, behavior-based systems and relentless micro-training to counter AI-driven social engineering and secure the new identity perimeter.

By late 2025, cybersecurity experts emphasized that combating AI-driven social engineering demands a robust, multi-layered defense framework integrating people, processes, and technology. Signature-based detection methods had become obsolete against AI's ability to generate infinite phishing variations, prompting a shift toward behavior-based threat detection that identifies anomalies like impossible travel or unusual email forwarding rules. Complementing this technological shift, organizations adopted continuous, AI-generated micro-training drills with immediate feedback to build a resilient human firewall, replacing ineffective annual training and encouraging proactive suspicion and reporting among employees.

Critical process controls such as out-of-band verification for high-risk actions—financial transactions or access changes—emerged as non-negotiable safeguards, especially as AI-enabled attacks evolved to include sophisticated tactics like ChatOps phishing, where AI chatbots impersonate IT support in real-time. Phish-resistant MFA technologies, notably FIDO2 and passkeys tied to specific domains, provided superior defense by neutralizing credential theft attempts on fake login pages. This combination of hardened processes and advanced authentication technologies formed the backbone of adaptive defense strategies against increasingly interactive and convincing AI-powered social engineering attacks.

As 2026 unfolded, the cybersecurity landscape recognized identity as the new perimeter, necessitating continuous identity verification and comprehensive visibility across all environments—including human, machine, API keys, and AI identities—to effectively map and mitigate risk. Leading frameworks incorporated continuous configuration audits, privilege reduction, and threat-informed risk modeling to harden identity posture, while behavior-based detection systems aggregated telemetry from endpoints, cloud, SaaS, and identity platforms to detect subtle anomalies within trusted environments. This evolution marked a decisive move beyond traditional perimeter defenses toward integrated identity and SaaS posture assessments powered by graph analytics and specialized identity threat detection technologies.

The human element remained pivotal in countering AI-enhanced social engineering, especially as AI voice cloning amplified the threat of vishing by exploiting inherent trust in voice communication. Experts stressed that technical filtering alone was insufficient; organizations must enforce strict policy-driven verification processes that disallow sensitive transactions based solely on voice authorization. Empowering employees to question and independently verify requests—even from executives—became essential, as demonstrated by real-world attacks exploiting shared mailbox credentials and urgent help desk requests to bypass security unnoticed. This holistic approach, combining zero-trust identity principles with continuous training and behavioral monitoring, defines the adaptive defense frameworks best suited to withstand the dynamic and deceptive nature of AI-enabled social engineering.

Sources
ToxSec - AI and CybersecurityCyberWire DailySoftware Analyst Cyber ResearchPackt SecProIBM TechnologyHacking Humans

Part of these trends

Get the stories behind the trends

Deep-dive reporting and the weekly brief, in your inbox.