TechKnowSurge
VideoSecurityFree

AI and Social Engineering

Adversaries are increasingly using artificial intelligence to execute social engineering attacks with alarming effectiveness, from AI-generated phishing emails to deepfake audio and video impersonations. Real-world incidents from 2024 demonstrate how these techniques have led to multimillion-dollar losses and unauthorized organizational access.

Complete this video to capture a CTF flag worth 1 point.

About this video

Artificial intelligence has fundamentally changed the threat landscape for social engineering, giving adversaries tools that make their attacks faster, more convincing, and significantly more effective. Data from CrowdStrike's 2025 Global Threat Report highlights a striking gap in attack success rates: AI-generated phishing emails achieve a 54% click-through rate, compared to just 12% for those written by humans. That gap represents a dramatic force multiplier for threat actors, meaning organizations face a much higher probability of a successful compromise when AI is involved in crafting deceptive communications. Deepfake technology represents another rapidly growing dimension of AI-enabled social engineering. In February 2024, attackers used publicly available video footage of a company's CFO and other employees to construct a convincing deepfake video call, ultimately tricking the victim into transferring $25.6 million. A separate incident in May 2024 involved the cloning of a CEO's voice to manipulate targets over audio. These cases demonstrate that impersonation attacks are no longer limited to text-based deception and can now convincingly replicate the appearance and voice of trusted individuals. Generative AI is also being used to penetrate organizations through the hiring process itself. Threat actors are constructing fully fabricated professional identities, complete with polished LinkedIn profiles and convincing work histories, to pass through recruiter screenings and multiple interview rounds before red flags emerge. This tactic represents a sophisticated long-game approach to gaining insider access. For security teams, these developments reinforce the need to treat AI-powered social engineering as a priority threat, responding with AI-assisted detection capabilities and robust, ongoing employee training that addresses the full spectrum of modern manipulation techniques.

What you'll learn

What's covered

AI-Powered Social Engineering

Key terms

Social Engineering
A manipulation technique that exploits human psychology to trick individuals into revealing confidential information.
Phishing
A social engineering attack that uses deceptive emails or messages to trick users into revealing sensitive information.
Spear Phishing
A targeted phishing attack directed at a specific individual or organization using personalized information.
Threat Actor
An individual or group responsible for a security incident or attack.
Large Language Model
LLM
An AI system trained on vast amounts of text data to generate and analyze human-like language, used by attackers to craft convincing phishing messages and fake personas.
Deepfake
AI-generated synthetic audio or video that realistically impersonates a real person, used in social engineering attacks to deceive victims into transferring funds or sensitive information.
Synthetic Identity Infiltration
The use of AI-generated personas, profiles, and credentials to fraudulently impersonate a job candidate or trusted individual in order to gain access to an organization.

Topics

Social Engineering Artificial Intelligence Phishing Deepfakes Cybersecurity Llm Attacks Identity Impersonation

Transcript

One tool that adversaries are using a lot of nowadays is artificial intelligence. It can be used for carrying out social engineering attacks.

I'm on the 2025 Global Threat Report by CrowdStrike, where we have some data here, some real examples of how AI is being used to carry out these social engineering attacks.

Phishing Emails

One thing that AI is being used for is writing phishing emails. In this report, it talks about human written phishing messages, and that gets a 12% click-through rate. So if you were to send a phishing email that was written by the adversary, there's about a 12% chance that the human on the other side is going to click the link or do something, take some sort of action on it. But if it is AI generated or large language model generated, then that ends up being 54%. That's huge. That's a huge difference between 54% for AI generated messages versus 12% human generated.

Deep Fakes

In one of the incidents in February of 2024, the victim ended up transferring $25.6 million US. So this social engineering attack ended up compromising the company at $25.6 million US. And what was it? The adversary found some public video of the chief financial officer and some other employees to create a deep fake video, and then used this deep fake video to trick the victim.

In another incident in May of 2024, they deep faked the CEO's voice. So they used the CEO's voice to do a deep fake of the victim and try to trick them.

AI in the Hiring Process

They also reported many incidents where they would use generative AI and large language models for the interview process, to get through and create all of the LinkedIn profiles and all of the social engineering setup needed to get somebody into the company. In fact, this one hits close to home, because I just talked with somebody yesterday who went through this experience, where somebody applied and this person ended up tricking the recruiter, ended up tricking the initial interview process, ended up getting halfway through the team interview process, where it was discovered that something's off here. Something's not right. And they discovered that there were quite a few red flags throughout this. They went out and looked at the LinkedIn profile and the past companies that this person had worked for, and there were just a lot of red flags that flagged that it was probably some sort of social engineering attack against this company.

So artificial intelligence is playing a huge role in the adversaries and how they attack, and us as security professionals need to be using AI and other tools necessary to attack back, and then also train our employees on how to combat these social engineering attacks, whether it's coming from AI or any other source.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →