Each week we find a new topic for our readers to learn about in our AI Education column.
We are of the generation that started to use the internet before we were old enough to make good decisions—and as a result, we have done a few not-so-great things online.
Luckily, most of those things were back in the 1990s.
In those days we accessed the internet through dial-up internet service providers that offered a nice graphical interface to allow us to enjoy the web, newsgroups, filesharing, email and messaging, all for what was usually a small monthly fee. Certain users, sometimes bad actors, sometimes good, sometimes old fashioned “red hat” hackers, built applications and tools that allowed one to manipulate the interface and to access otherwise unavailable parts of the online experience.
It was through one of these tools that I was introduced to phishing. In these days, phishing was already automated. At the click of a button, the tool would directly private message another user, posing as a manager or customer service representative of the platform, asking them for their information. The most valuable information? Credit card numbers, of course, but scripts and prompts existed for other information, like passwords and accounts.
Of course, while young, I had some sense of right from wrong and never made use of the phishing tool—but I knew it existed. Phishing is a form of social engineering, which is our topic today on AI Education. Social engineering, is a broad category of manipulation in which an attacker persuades, deceives or pressures another person into doing something that compromises security. Rather than defeating a firewall or discovering a software vulnerability, a social engineer might convince an employee to reveal a password, persuade a financial professional to transfer money, impersonate an executive requesting confidential information or direct a consumer to a counterfeit banking website.
What Is Social Engineering?
In cybersecurity, social engineering refers to using psychological manipulation rather than—or in combination with—technical exploitation to persuade someone to compromise security. Cisco describes social engineering fundamentally as the psychology of persuasion: attackers seek to gain a target’s trust and then induce unsafe behavior, such as revealing information, opening an attachment or following a malicious link.
The technique predates computers. Confidence schemes, impersonation and fraudulent solicitations are centuries old. Digital technology simply gave social engineers enormously greater reach. Attackers commonly exploit recognizable aspects of human behavior: trust in authority, fear, curiosity, urgency, greed, helpfulness and reluctance to challenge colleagues or superiors. An attacker pretending to be a senior executive might tell an employee that an acquisition must be completed immediately and confidentially. Another might pose as technical support and ask an employee to provide credentials. A criminal impersonating a financial institution could tell a client that suspicious activity requires immediate verification of an account.
The central insight is that the attacker does not necessarily need to break the organization’s security system. The attacker persuades an authorized user to circumvent it. That distinction matters enormously for financial firms. A perfectly legitimate employee using perfectly legitimate credentials can still initiate a fraudulent transaction. Cybersecurity controls therefore cannot focus exclusively on determining whether a credential is genuine. Organizations increasingly need to ask whether the behavior associated with that credential makes sense.
The FBI describes spoofing and phishing as important components of business email compromise. In spoofing, criminals disguise such things as sender names, email addresses, phone numbers or URLs to make communications appear trustworthy. Phishing then attempts to persuade victims to disclose information or perform some other action beneficial to the attacker.
Social engineering is therefore better understood as an attack strategy than a single attack technology. Phishing, smishing, vishing, quishing and many forms of spoofing are different mechanisms for implementing essentially the same strategy: manufacture trust and then exploit it.
Artificial Intelligence Changes Social Engineering
Generative AI attacks one of the traditional weaknesses of social engineering: labor.
A sophisticated spear-phishing operation once required substantial research. Someone had to learn about a target, understand an organization, determine who communicated with whom and compose credible messages. Conducting that process across thousands of potential victims was expensive. AI radically changes the economics.
IBM has reported experiments in which generative AI produced an effective phishing email in about five minutes, compared with roughly 16 hours for humans performing the research and writing required to produce a comparable message. AI also removes familiar warning signs such as awkward grammar because language models can generate polished communications in many languages. The result is not necessarily an entirely new species of cyberattack. In many cases AI simply industrializes old-fashioned deception.
Attackers can use AI to research organizations and employees, process information scraped from the web and social media, generate personalized messages and rapidly produce variations when security systems begin blocking an existing campaign. Microsoft Threat Intelligence reported in March 2026 that malicious actors were incorporating AI throughout attack workflows, including drafting phishing messages, translating content, summarizing stolen information and producing code and infrastructure.
AI-generated media creates another escalation. Voice cloning can imitate an executive, colleague or family member. Synthetic video can potentially place a recognizable executive into a video conference. AI-generated photographs and documents can strengthen fabricated identities. This has profound implications for financial organizations because familiar authentication heuristics become less reliable. “I recognize the voice” is no longer strong evidence. Neither is “the email sounded exactly like the CEO.”
Attackers are even using enthusiasm for AI itself as bait. Microsoft reported in June that criminals were impersonating brands associated with ChatGPT, Claude, DeepSeek and Microsoft Copilot in phishing and malware campaigns. One ChatGPT-themed phishing campaign sought credit-card information, while a campaign impersonating Anthropic services targeted users across more than 2,000 organizations; Microsoft said financial services represented 8% of targets in that campaign.
AI, however, cuts both ways. Defensive AI can analyze enormous numbers of communications and transactions, identify abnormal identity behavior, examine links and attachments and correlate signals across email, endpoints, cloud applications and authentication systems. Elastic, for example, argues that rapidly changing AI-generated attacks make static signatures increasingly insufficient and increase the importance of behavioral analytics across identity, endpoint, email and cloud telemetry.
Microsoft similarly argues that detection increasingly should emphasize behavioral signals, infrastructure and context instead of relying primarily on static indicators or writing patterns. That may become the defining cybersecurity contest of the AI era: AI makes deception more convincing, while AI security systems attempt to recognize the behavioral inconsistencies underneath that deception.
Phishing: AI Upgrades the Classic Attack
Phishing remains the umbrella term most people associate with social engineering. The Federal Trade Commission describes phishing as communications that appear to originate with a familiar organization—such as a bank or mortgage company—but attempt to obtain identifying information that can subsequently be used for account takeover or other fraud.
The classic phishing email contained recognizable warning signs: misspellings, generic greetings, suspicious URLs and implausible requests. Generative AI weakens many of those signals. An attacker can instruct a language model to write in professional financial-industry terminology, imitate corporate communications and produce multiple variations of the same solicitation. More sophisticated attacks can incorporate information about an individual’s employer, responsibilities or professional relationships.
Recent campaigns demonstrate that phishing itself is simultaneously becoming more technically sophisticated. Microsoft reported that an April 2026 campaign targeting more than 35,000 users across more than 13,000 organizations used multi-stage social engineering and adversary-in-the-middle techniques capable of intercepting authentication traffic and defeating forms of multifactor authentication that are not phishing-resistant. Another 2026 campaign combined AI-driven infrastructure and automation with device-code phishing, allowing criminals to scale account compromise without simply asking users to surrender passwords.
For wealth managers, this means phishing awareness cannot remain centered on the stereotype of the poorly written email from an unfamiliar sender. A modern phishing message might be grammatically perfect, contextually accurate and apparently written by someone the recipient knows.
Spoofing: Artificial Authenticity
Spoofing is closely related to phishing but describes the falsification of identity or origin rather than necessarily the complete fraud scheme. The FBI defines spoofing as disguising such things as an email address, sender name, telephone number or website URL so the victim believes the communication originates from a trusted source. AI makes spoofing particularly potent because identity itself is becoming reproducible.
Traditional spoofing could reproduce an email address or caller ID. Generative AI can reproduce communication style. Voice synthesis can reproduce recognizable speech characteristics. Deepfake video can reproduce appearance. This produces what might be called multimodal spoofing. An attacker is no longer restricted to pretending that a message came from an executive. Potentially, the attacker can sound and look like the executive as well.
The financial consequences are obvious. Consider an employee receiving an apparently urgent wire-transfer request. Previously, the organization might tell employees to telephone the executive for verification. If the attacker can convincingly imitate that executive’s voice, however, a familiar voice becomes weaker authentication. The solution is therefore procedural rather than perceptual. Sensitive financial actions increasingly require independent verification through trusted channels and established workflows rather than subjective judgments about whether a communication “looks real.” That principle becomes increasingly important as AI improves.
Smishing: Social Engineering Moves to the Phone
Smishing combines SMS and phishing. Instead of email, criminals use text messages or messaging applications to persuade victims to reveal information, install malware or transfer money.
IBM notes several reasons SMS is attractive to attackers. Users are accustomed to receiving legitimate text messages from banks and businesses, mobile interfaces make suspicious links more difficult to inspect, and organizations increasingly use personal mobile devices for work. AI gives smishing the same productivity improvements it gives email phishing. Large numbers of personalized text messages can be generated quickly, translated automatically and adapted to particular contexts.
For financial institutions, especially dangerous messages can imitate fraud alerts: “A $4,850 transfer was requested from your account. If this wasn’t you, verify immediately.” That creates urgency and simultaneously exploits the customer’s expectation that a legitimate bank actually might send a security alert.
Defenses therefore require more than telling clients never to use text messages. Financial firms themselves legitimately communicate through SMS. Instead, institutions need clearly defined communications policies, authenticated applications, transaction controls and persistent client education explaining what the institution will and will not request through a text message.
Quishing: Putting the Phish Behind a QR Code
Quishing, or QR-code phishing, replaces or supplements a conventional malicious hyperlink with a QR code. A victim might receive what appears to be an authentication notice, benefits document, parking notice or financial communication containing a QR code. Scanning it transfers the user to a malicious website where credentials or financial information are requested.
The technique is important because QR codes can make malicious destinations less visible to both users and traditional security technologies. Cloudflare has explained that conventional phishing systems frequently analyze URLs and attachments, while QR codes can conceal the URL inside an image, requiring additional computer-vision capabilities to examine it.
The defensive technology is adapting. Trend Micro describes security capabilities that extract and analyze QR codes in email bodies and attachments, including images and PDFs. AI may intensify quishing through automated personalization and campaign generation, while computer vision and machine learning can simultaneously strengthen defensive QR analysis.
For financial firms, quishing illustrates a broader lesson: attackers migrate toward interfaces where trust is high and inspection is inconvenient. A user who would carefully examine an email URL may scan a QR code without knowing where it leads. The security principle should remain constant regardless of format: a QR code is a link. Employees and clients should treat unexpected QR codes with the same skepticism they would apply to an unsolicited hyperlink.
Vishing: When the Scammer Has Someone Else’s Voice
Vishing, short for voice phishing, applies social engineering through telephone calls, voicemail or internet-based voice systems. The FBI identifies vishing as a phishing variation conducted over phone or VoIP communications. AI voice synthesis dramatically increases its potential.
Traditional telephone scammers impersonated bank representatives, government officials, executives or relatives. AI makes it possible to create synthetic voices resembling actual individuals, potentially using audio obtained from speeches, podcasts, videos or social media. For wealth management, this threat deserves particular attention because the industry remains relationship-based. Advisors know clients personally. Assistants recognize executives’ voices. Clients sometimes call financial professionals to request transactions.
Voice cloning undermines the assumption that recognition equals authentication. The logical response is not to abandon telephone communication. It is to separate identity familiarity from transaction authorization. High-risk requests involving money, credentials or account changes should be subject to predetermined verification procedures, especially when accompanied by urgency, secrecy or requests to bypass normal controls.
AI as Defender
The darker side of AI-powered social engineering receives considerable attention, but AI may ultimately be indispensable to defending against it. Machine learning already powers spam filtering, anomaly detection, fraud detection and behavioral analytics. Generative AI can help security personnel summarize incidents, investigate suspicious files, examine identity activity and accelerate threat hunting.
Microsoft’s 2026 research provides a useful glimpse of this AI-versus-AI environment. The company reported detecting a phishing campaign that apparently used AI-generated code to obfuscate malicious behavior. Microsoft Security Copilot was itself used in analyzing the suspicious code. The defensive emphasis increasingly moves from examining isolated messages to examining behavior. Does this employee normally log in from this location? Has the user suddenly authorized an unfamiliar application? Is a legitimate-looking authentication followed by an unusual OAuth permission? Does a transfer request resemble the client’s normal behavior?
For financial institutions, this suggests that AI cybersecurity should be integrated with identity management, fraud monitoring, communications security and transaction surveillance rather than deployed as another isolated cybersecurity product.
The human component remains critical. Organizations should strengthen phishing-resistant authentication, limit privileges, enforce transaction controls, train employees using realistic scenarios and create cultures in which workers are rewarded—not embarrassed—for stopping an unusual request and verifying it. AI should reinforce those controls rather than replace them.
The Other Social Engineering: AI and the Engineering of Society
There is another meaning of “social engineering” that long predates cybersecurity. In political science, the term generally refers to deliberate attempts to influence attitudes, institutions or social behavior on a broad scale. Governments have historically been associated with such projects, although media organizations, private groups and other institutions can also attempt to shape social behavior. The terminology emerged around the turn of the 20th century as industrial societies increasingly applied ideas associated with planning and engineering to social organization.
Artificial intelligence gives this older definition renewed relevance. Recommendation algorithms already influence which information people encounter. Generative AI can produce persuasive political messages, advertisements, images, videos and synthetic personalities at extraordinary scale. Automated systems can potentially divide populations into increasingly granular audiences and tailor messages to the fears, interests and identities of each group.
That begins to blur the distinction between cybersecurity social engineering and political social engineering. Both involve understanding people sufficiently well to influence their behavior. The cybersecurity attacker wants an individual to click a link or transfer money. Political social engineering seeks behavioral or attitudinal changes across populations. AI provides both with increasingly sophisticated tools for profiling, persuasion, personalization and experimentation.
Agentic AI could deepen the issue further. A recent Regulatory Review seminar noted that AI agents can already conduct multi-step activities such as browsing websites and making purchases with limited human oversight, while simultaneously remaining susceptible to adversarial manipulation. The growing autonomy of agents raises difficult questions about authorization, accountability and who—or what—is actually making a decision. Imagine social influence systems that do not merely generate advertisements but continually observe reactions, modify messages, select audiences and optimize persuasion. At sufficient scale, AI-assisted persuasion starts looking less like conventional advertising and more like automated behavioral engineering.
Financial services has reason to watch this broader meaning as well. Financial behavior is social behavior. Markets depend upon confidence. Consumers make investment decisions based partly on information received through social networks and digital media. AI-generated rumors, synthetic executives, fraudulent financial personalities or coordinated persuasive campaigns could affect individual investors and, in extreme cases, markets themselves.
The New Security Principle: Verify the Action, Not the Appearance
Artificial intelligence does not abolish the traditional principles of social engineering. It magnifies them. Criminals still depend on trust, authority, urgency, curiosity and fear. What AI changes is their ability to manufacture the evidence that causes people to trust them.
A polished email is no longer evidence of professionalism. A familiar voice is no longer strong evidence of identity. A realistic video is not necessarily evidence that an event occurred. A message containing accurate personal information does not demonstrate that the sender legitimately knows the recipient. That means cybersecurity education has to evolve beyond “spot the fake.” The more useful question is whether the requested action makes sense.
Should this person be asking for these credentials? Is this how our company changes payment instructions? Does our CEO request emergency wires through this channel? Would our bank ask us to enter credentials through an unsolicited QR code? Can the request be independently verified using contact information already known to be legitimate?
For wealth managers and other financial professionals, the answer increasingly lies in combining human skepticism with technological controls. AI systems can analyze communications and behavior at a scale no human compliance or security team can match. Humans, meanwhile, remain essential for contextual judgment, escalation and independent verification.
The goal should therefore not be to create employees who can reliably distinguish real digital communications from AI-generated ones. Eventually, that may be an unrealistic expectation. The goal is to build organizations in which a convincing deception still cannot easily produce an unauthorized action.
That is the central challenge artificial intelligence introduces to social engineering. AI makes impersonation cheaper, personalization faster and deception more scalable. But it can also make monitoring more intelligent, authentication more contextual and defensive response faster.
Financial institutions that treat the problem merely as another phishing-awareness exercise risk missing the larger change. Social engineering is evolving from a collection of scams into an AI-enabled attack layer aimed directly at human judgment. As synthetic communications become increasingly indistinguishable from legitimate ones, security will depend less on our ability to recognize what is fake—and more on whether the systems surrounding us remain secure even when we cannot.






