AI Did Not Invent Social Engineering But It Did Industrialize It.

Erich Kron | Aug 6, 2026

Erich Kron, CISO Advisor at KnowBe4This year National Social Engineering Day falls on Aug. 6. This day is designed to give us an opportunity to remind people that cybercriminals do not always need sophisticated malware, an undisclosed vulnerability or a dark room filled with glowing monitors, sometimes, all they need is a good story.

Social engineering existed long before computers. Confidence tricks, impersonation, false authority and appeals to greed or fear have been used for centuries. It is important to remember that technology did not create these tactics. Email, social media, smartphones and collaboration platforms simply gave attackers new ways to deliver them.

Artificial intelligence is now taking things a step further by turning social engineering into an industrial-scale operation. Doing more with less has never been truer.

The Same Old Tricks

Despite all the fancy technical terminology surrounding modern cybercrime, most social engineering attacks still rely on some very familiar psychological triggers:

  • Authority: “The CEO needs this handled immediately.”
  • Urgency: “Your account will be disabled in 30 minutes.”
  • Fear: “We detected suspicious activity.”
  • Helpfulness: “Can you quickly take care of this for me?”
  • Curiosity: “You were mentioned in this document.”
  • Scarcity: “This offer expires today.”
  • Familiarity: “It’s me. I’m calling from a different number.”

None of these approaches are new, but they work because people are naturally inclined to trust familiar names, respond to authority, help their coworkers and move quickly when something appears urgent. These are behaviors that help organizations operate effectively, but social engineers know how to turn them against us.

Attackers’ success is not related to employees not being intelligent. Anyone can fall for a social engineering attack, especially if it gets to someone who is busy, highly stressed, distracted, helpful or afraid of delaying an important request. That pretty much describes nearly everyone at some point during the workday.

Because most organizations want to protect their reputation, many social engineering incidents go unreported, such as attempted fraud, successful attacks or embarrassing mistakes, so it can be difficult to quantify exactly how big the problem is, but it is estimated that anywhere from 70%-90% of breaches start with a social engineering attack.

From the Confidence Trick to the Phishing Kit

Social engineering has evolved alongside the ways we communicate. Early confidence schemes (a.k.a. cons) usually required the criminal to interact directly with the victim. The attacker needed time, charisma, research and often physical proximity. Then the telephone removed the proximity requirement, and criminals could suddenly impersonate bank representatives, government officials, technical-support agents or family members without ever being in the same room as the target.

Then email turned social engineering into a numbers game. An attacker could now send thousands of messages at almost no cost. The emails did not even need to be particularly convincing. When the volume was high enough, the criminal only needed a very small percentage of recipients to respond. As far back as 2018, Dark Reading reported that there were about 6.4 billion fake emails sent each day. I really do not think that number has decreased.

Next, social media gave attackers something even more valuable: an enormous reconnaissance database. Quickly, job titles, employers, coworkers, conferences, vendors, family members, political affiliations, travel plans and personal interests became easy to find. Criminals could use this information to create far more convincing stories. Now, instead of sending the same generic email to everyone, they could build a pretext around real people, real relationships and real events.

Now Artificial intelligence (AI) has taken this evolution another step forward.

AI Changes the Economics of Deception

AI does not need to discover a new psychological weakness. People already come with plenty of those preinstalled, what AI changes is the cost of exploiting them.

A criminal can use generative AI to:

  • Research a target and summarize publicly available information
  • Draft messages using terminology from a specific industry
  • Rewrite an email to imitate a particular tone or writing style
  • Translate attacks into multiple languages
  • Create dozens of variations designed to evade filtering
  • Generate fictitious social-media accounts and personas
  • Maintain extended conversations with potential victims
  • Produce convincing voices, images and videos
  • Build credential-harvesting pages and the content needed to support them

We know that adversaries are using generative AI to improve phishing and Business Email Compromise campaigns, create synthetic social-media personas and produce deepfake content. Researchers also found that large language models could generate phishing messages and credential-harvesting websites at least as effectively as human operators and far more efficiently. The implications are significant.

Traditional spear phishing required a meaningful investment of time. An attacker needed to research the target, understand the organization, write a credible message and communicate convincingly if the victim responded, but now AI can help with every one of these steps. This does not mean every phishing email is being created and delivered by a fully autonomous criminal-minded supercomputer, but it does mean one criminal can now accomplish work that once required a larger team or a lot more time.

The result is not simply better phishing, it is more believable phishing, delivered to more people, across more channels, at a much lower cost. That is industrialization at its finest.

The Bad-Grammar Safety Net Is Gone

For years, employees were told to watch for spelling mistakes, awkward wording and poor formatting. That advice was never entirely reliable, but it occasionally helped. Generative AI can now create polished and grammatically correct messages in seconds. It can adjust the vocabulary for a lawyer, accountant, salesperson, developer or executive, and can even regionalize communications. It can make the message sound formal, casual, irritated, apologetic or rushed, whatever the attacker wants.

The old “look for typos” advice is quickly becoming the cybersecurity equivalent of identifying a hacker simply because they wear a black hoodie. Employees need to focus less on how polished the message looks and more on what the sender is asking them to do.

  • Is the request unusual?
  • Is someone asking you to bypass a normal process?
  • Has a payment destination suddenly changed?
  • Is an executive asking for gift cards?
  • Is a vendor providing different banking information?
  • Is someone asking the help desk to reset MFA without following the established verification process?

A perfectly written email can still contain a ridiculous request. I mean does the IRS really need iTunes gift cards, or can you pay the fine to law enforcement with Amazon gift cards? Probably not.

Deepfakes Add a Familiar Face

AI-generated text is only part of the issue. Voice cloning and deepfake video are weakening assumptions that organizations have relied on for years. Hearing a familiar voice is no longer enough to prove someone’s identity. Seeing a person appear on a video call may not be enough either. This is especially concerning because attackers often use multiple communication channels to make their story more convincing.

A suspicious email may be followed by a phone call. A message that appears to come from an executive may be reinforced during a video meeting. A fake employee may create a credible LinkedIn profile before contacting the help desk. Each interaction makes the others appear more legitimate. Sadly, the attacker does not always need to create a flawless digital replica. It only needs to be believable for a few minutes, especially when the victim is under pressure, the connection is poor and the request appears urgent.

AI allows criminals to manufacture more than a fake message, it allows them to manufacture an entire environment of synthetic trust.

Defending Against Industrialized Social Engineering

Organizations cannot solve this problem by asking employees to become full-time forensic linguists and deepfake analysts. Training still matters, but the defensive strategy must go beyond simply telling people to “spot the fake.” Employees should be taught to recognize high-risk requests and verify them through trusted methods. Requests involving money, credentials, sensitive information, software installation, access changes or MFA resets should receive additional scrutiny, no matter how convincing the sender appears.

Some key defenses include:

  • Out-of-band verification: Confirm sensitive requests using a known phone number, an established messaging account or another trusted communication channel.
  • Dual authorization: Require two people to approve large payments, changes to banking information and high-risk administrative actions.
  • Defined processes: Make it difficult for an attacker to succeed simply by creating a sense of urgency.
  • Phishing-resistant authentication: Use stronger authentication methods that are more difficult to capture or relay through a fake login page.
  • Limited privileges: Ensure that one compromised account or manipulated employee cannot provide unrestricted access to critical systems or information.
  • Easy reporting: Give employees a quick and obvious way to report suspicious messages and interactions.
  • A blame-free culture: Employees who believe they will be embarrassed or punished are more likely to hide mistakes. Early reporting can turn a serious incident into a manageable one.

The goal is not to eliminate trust from the workplace. Organizations would grind to a halt if every interaction required a criminal investigation, instead the goal is to separate trust from authorization. While you may trust the person who appears to be calling, you should still follow the verification process before transferring money, resetting credentials or providing sensitive information.

Old Tricks, New Production Line

AI has not fundamentally changed why social engineering works. Attackers still exploit authority, fear, urgency, curiosity and helpfulness. They still create stories designed to make people act before they have time to think. They still rely on employees ignoring established procedures because a situation appears to be an exception. What AI really changes is the production line.

It allows criminals to research targets faster, write more persuasively, communicate across languages, create synthetic identities and operate at a scale that was previously too difficult or expensive for many attackers.

On National Social Engineering Day, the lesson is not that people are hopelessly vulnerable or that employees should become suspicious of everyone around them. The lesson is that trust has become easier to manufacture, and our training, security controls and business processes need to evolve accordingly.

Educating the workforce is a critical part of defending against social engineering attacks, but the threat doesn’t end with the workday and impacts families as well. This is why KnowBe4 offers the best employee education available with over 15 years of behavioral data, 70,000 global customers, and millions of people trained, and we have extended our expertise to families through our CAPY (The Cyber Awareness Program for You) program that is free for everyone and has specific education tailored to kids & teens, adults, and senior citizens.

Social engineering is not going away, so we have to prepare to defend ourselves at work and at play.

See KnowBe4 Cloud Email Security in Action

Request a personalized demo today to see how KnowBe4's Cloud Email Security products will enhance your email security.

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.