Warning: Social Engineering is a Growing Threat to the Industrial Sector

KnowBe4 Team | Aug 21, 2025

Data Breach Social EngineeringSocial engineering attacks are a growing threat to operational technology (OT) environments, Industrial Cyber reports.

Cyberattacks against these environments can be particularly damaging since they have the potential to cause physical disruptions.

“With the expanding IT/OT footprint, the attack surface is increasingly providing attackers additional opportunities to compromise targets by stealing credentials, impersonating trusted insiders, and moving laterally from one system to another inside the network,” Industrial Cyber says. “AI-driven phishing, voice cloning, and deepfake-enabled pretexting are lowering the barrier to entry, enabling cyber adversaries to deploy powerful tools that have the potential to erode the reliability of human judgment across critical infrastructure installations.”

Paul Smith, Honeywell’s director of operational technology cybersecurity engineering, warned of phishing campaigns targeting disgruntled employees after reduction-in-force (RIF) moves.

“An interesting tactic that I have seen would be internal post-RIF announcements, a spoofed HR email sending out anonymous employee feedback surveys,” Smith told Industrial Cyber. “This exploits the vulnerable nature of the disgruntled employee who wants to be heard. Implementing email security gateways and AI threat detection to filter out email spoofing, lookalike domains, and malicious attachments would be a tooling recommendation. Security awareness training is still paramount, as we are the last line of defense to mitigating ‘click compromises.’”

Marco Pereira, global head of cybersecurity, cloud infrastructure services at Capgemini, added that generative AI-powered social engineering is making it easier for attackers to craft targeted, convincing phishing messages is making it easier for attackers to craft targeted, convincing phishing messages.

“Threat actors are increasingly leveraging AI and generative AI to supercharge social engineering campaigns,” Pereira told the publication. “By analysing vast amounts of publicly available data, such as social media posts, blogs, and YouTube content, they can craft highly personalized and convincing spear phishing messages. These tools also enable the creation of realistic voice and video deepfakes, making impersonation attacks more credible and harder to detect.”

KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 HRM+ platform to strengthen their security culture and reduce human risk.

Industrial Cyber has the story.

Ready to Build a Security Culture That Lasts?

Stop treating training like a checkbox exercise. Using 15+ years of behavioral data, our AI-powered platform personalizes training for every user to significantly reduce human risk and stop attacks before they start.

Get a Quote

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.