Opinions expressed by Digital Journal contributors are their own.
Social engineering is one of the more popular forms of cyber attack out there right now. It’s the idea of finding ways to manipulate people online so they hand over important information, or even money. A common example of this is the classic phishing email in which someone sends a message claiming to be someone that they’re not and asking for money. Current statistics suggest that over 3 billion phishing emails are sent globally every single day. It had a high success rate in the early days of the internet, but people quickly caught on to these threats.
Advancements in email phishing detection technology have also made it harder than ever for the average user to be caught out by a devious email. And yet, phishing, and other forms of social engineering, are still highly prevalent across the world. If anything, social engineering in itself has advanced rapidly, and this creates new concerns.
What’s caused this advancement, and are there specific signs or things to watch out for?
AI is at the heart of everything
There was a very detailed article published by cybersecurity giants Crowdstrike that explained how artificial intelligence has led to more advanced social engineering threats. AI drives innovation across all industries, and the tools available allow cybercriminals to be even smarter at obtaining key information to run social engineering scams.
AI can collect so much data in such a small amount of time. It happens automatically – and users are left in a situation where an attacker has their hands on information that was previously difficult for them to obtain.
Why is this a concern? Because social engineering relies on information:
- Attackers spend time researching their targets by gathering all the information they can from all over the internet. The more data they have on a target, the easier it is for them to manipulate said target.
- Social engineering scams are built around the attacker convincing the target that they’re a real person. If they have all the information on a user’s recent purchasing history with a company, then they can impersonate that business with more accuracy. The same goes for impersonating friends or family; the more information they have, the easier this becomes.
Before, it was much easier to detect these scams because they lacked personalization. Now, with the advancements in AI making it easier for criminals to gather swarms of data, it is difficult to determine if someone is indeed who they claim to be.
In addition to giving criminals a tool to extract data more efficiently, AI makes social engineering more dangerous through two other developments.
Personalized generative AI
Cybercriminals can now create AI-generated emails that have been personalized to suit their targets. Research from Microsoft tracked a phishing campaign in August 2026 and detected over 1 million personalized messages in 3 days that were AI-assisted. The same goes for text messages and other forms of contact, making their messages feel more authentic than ever before. It’s the level of personalization that’s worrying, and the fact that they can generate these messages in seconds and send them to millions of targets at once.
Deepfakes
When AI technology started to become mainstream, everyone was worried about deepfakes. This is a type of generative AI that allows anyone to create videos or audio replicating other people. It can be very accurate, and it’s no surprise to see this move into the cybercrime world.
Criminals can create realistic deepfake videos or audio messages that they send to targets, adding more credibility to their previous messages. It makes the target think that the contact is legitimate, which adds to their urgency. If someone claims to be a colleague or family member in need of money, and they see a video that looks exactly like the person they claim to be, then it is very easy to fall into the trap. The main issue here is that research shows humans can accurately detect deepfake videos just 55.5% of the time. Contextually, this means that almost half of all deepfake scams have the potential to be believed.
As social engineering advances and becomes more problematic than ever before, steps need to be taken to protect against these attacks – particularly for vulnerable users. It all starts at the source: managing how much information remains public online for criminals to access.
While there’s no way to guarantee that every website is secure enough to prevent data extraction from happening, there is an option to remove personal information from websites using specialist tools and services. Many exist, and they go around requesting data deletion from every site that has a user’s personal data.
Unfortunately, it’s not yet possible to remove 100% of your data from every website on the internet, but the goal here is to limit the amount of data a criminal can obtain, even with the help of AI. It makes it harder for them to personalize their attacks or to create convincing messages.
Another idea touches upon something mentioned in the introduction: better email defenses. Upgrade to a better email client with improved phishing detection to avoid seeing these messages altogether.
Most of all, there is another common-sense idea, and it’s to avoid taking direct action immediately. If an email or text message encourages a user to provide information, click a link, or send money, it is always worth double-check before doing anything. If it looks like a message from a bank, contact the bank to see if they actually made this request. Call any family members or friends who supposedly need the information instead of replying directly to the message.
Taking that extra step just to double-check can be all that’s needed to avoid falling for a social engineering scam. The sad reality is that these scams and threats will continue to exist, and they will develop again as people figure out how to prevent them. It’s an endless cycle that’s becoming more worrying with AI, but the flip side is that AI does help cybersecurity companies react to these threats and improve their defenses. In a world that looks increasingly at risk of social engineering scams, the best thing to do is to remain vigilant.







