Adversaries are increasingly using artificial intelligence to execute social engineering attacks with alarming effectiveness, from AI-generated phishing emails to deepfake audio and video impersonations. Real-world incidents from 2024 demonstrate how these techniques have led to multimillion-dollar losses and unauthorized organizational access.
AI-Powered Social Engineering
One tool that adversaries are using a lot of nowadays is artificial intelligence. It can be used for carrying out social engineering attacks.
I'm on the 2025 Global Threat Report by CrowdStrike, where we have some data here, some real examples of how AI is being used to carry out these social engineering attacks.
One thing that AI is being used for is writing phishing emails. In this report, it talks about human written phishing messages, and that gets a 12% click-through rate. So if you were to send a phishing email that was written by the adversary, there's about a 12% chance that the human on the other side is going to click the link or do something, take some sort of action on it. But if it is AI generated or large language model generated, then that ends up being 54%. That's huge. That's a huge difference between 54% for AI generated messages versus 12% human generated.
In one of the incidents in February of 2024, the victim ended up transferring $25.6 million US. So this social engineering attack ended up compromising the company at $25.6 million US. And what was it? The adversary found some public video of the chief financial officer and some other employees to create a deep fake video, and then used this deep fake video to trick the victim.
In another incident in May of 2024, they deep faked the CEO's voice. So they used the CEO's voice to do a deep fake of the victim and try to trick them.
They also reported many incidents where they would use generative AI and large language models for the interview process, to get through and create all of the LinkedIn profiles and all of the social engineering setup needed to get somebody into the company. In fact, this one hits close to home, because I just talked with somebody yesterday who went through this experience, where somebody applied and this person ended up tricking the recruiter, ended up tricking the initial interview process, ended up getting halfway through the team interview process, where it was discovered that something's off here. Something's not right. And they discovered that there were quite a few red flags throughout this. They went out and looked at the LinkedIn profile and the past companies that this person had worked for, and there were just a lot of red flags that flagged that it was probably some sort of social engineering attack against this company.
So artificial intelligence is playing a huge role in the adversaries and how they attack, and us as security professionals need to be using AI and other tools necessary to attack back, and then also train our employees on how to combat these social engineering attacks, whether it's coming from AI or any other source.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →