Generative artificial intelligence (GenAI) is no longer just a tool for development and innovation—it is now also fueling increasingly sophisticated social engineering attacks. Instead of manual campaigns based on templates and guesswork, cybercriminals now have technology that automates the entire fraud process – from reconnaissance to message personalization, and recognizing a social engineering attack has become much more difficult
How does GenAI support the most popular social engineering attack methods?
Cybercriminals are actively using AI to generate phishing emails, construct fake websites and create deepfakes, accelerating the pace and scale of attacks. This means that social engineering attacks are no longer the domain of manual campaigns based on intuition – they are becoming automated, highly personalized and difficult to distinguish from real messages.
It is the art of persuasion (influencing people), the aim of which is to obtain confidential information or sensitive data through emotional blackmail and manipulation. Cybercriminals encourage employees to take rash actions that violate the organization’s cybersecurity through various methods of gaining trust. Thanks to this, they conduct successful social engineering attacks, which we later read about in many industry reports and LinkedIn posts.
How is this possible? GenAI enables automation and scaling of social engineering methods in a way never before possible:
- Content created by AI is free from typical linguistic errors that used to allow for quick recognition of a social engineering attack. Instead of broken Polish, we have natural syntax, correct punctuation, and adapted context.
- GenAI cangenerate a personalized phishing campaign in a few minutes. Something that previously took specialists up to several hours.
- Attacks are becoming more and more hyper-personalized and context-specific, which increases the likelihood that the recipient will trust the fraudster, unknowingly disclosing data or performing dangerous actions.
In practice, this means that social engineering is no longer a game of chance, but becomes a sophisticated art of gaining power over minds –automated, scalable and increasingly difficult to detect. Thanks to GenAI tools, cybercriminals can create hyperpersonalized messages that target the specific emotional background of the recipient, strengthening manipulation and weakening vigilance.
The attack not only looks credible, but also effectively bypasses security filters without causing alarm to either the systems or the employee. This is a real threat to system security, which in fractions of a second can lead to data theft, taking over access or losing control over the organization’s resources.
15 key questions for CISOs:
Assess your company’s readiness for AI-powered attacks
Examples of social engineering attacks supported by generative artificial intelligence
Thanks to GenAI, cybercriminals gain the ability to conduct social engineering campaigns on an unprecedented scale and at much lower operational costs. Classic methods such as phishing and vishing have been taken to a new level by AI. It is worth emphasizing that GenAI does not just create new types of attacks. Rather, it strengthens existing techniques, eliminating their existing weaknesses.
Hyperpersonalized AI-generated phishing
Traditional phishing has been based on simple, mass messages sent to random victims for years. However, thanks to GenAI, this model has undergone a real transformation. Today, phishing can be almost indistinguishable from real business communication, both in terms of language and context.
Modern AI models (powered by data from social media or company websites) cancreate personalized messages tailored to the role, language and communication style of a specific person. AI not only knows how to write, but also to whom, when and with what topic to increase the chances of a click.
More and more phishing campaigns resemble “conversational scams”. Instead of a pushy tone, we have a friendly question, and instead of a fake invoice – a subtle reference to the company’s current activities. The attack begins with gaining trust and ends with extorting data or encouraging an unauthorized transfer.
Business Email Compromise (BEC)
One of the most dangerous variants of AI-supported phishing is BEC – fraud based on impersonating directors, managers or business partners. It is a social engineering attack using manipulation based on authority and time pressure. AI helps you write a persuasive message that mimics a specific leader’s communication style by analyzing their public statements, emails or posts.
Spear phishing
Spear phishing is a cyberattack that targets a specific person or group. Thanks to GenAI, cybercriminals can automate the creation of such an attack, for example using historical information about the victim. As a result, a message is created that perfectly hits the topic, context and at the right moment, e.g. a question about a project that a given person is actually involved in, or a request for a comment on an event that has just taken place in the company.
Quishing (QR code phishing)
The popularity of QR codes is growing, e.g. in marketing, payments and authorization. And cybercriminals have found a way to use this format for their own purposes.
Quishing, or QR code-based phishing, is a technique that involves embedding malicious QR codes in emails, posters, or physical objects to direct the user to a fake website once scanned. GenAI enables you to quickly generate thousands of variants of quishing campaigns and quickly design malicious forms and pages to look like your company’s.
Such a social engineering attack bypasses email filters, the malicious link is literally hidden in the image. This means that many classic filtering solutions do not detect the threat, and employees scan the code with full confidence.
Free quishing lesson for your team
Send this graphic to your employees. Those who scan the QR code will receive a lesson about quishing, in which we remind you of key safety rules!

Smishing
Smishing is a social engineering attack carried out via SMS messages, usually containing a link to a fake login page or a request for immediate action, which may, for example, compromise the security of an IT system or steal confidential information (e.g. “Your account will be blocked. Confirm your details”).
Smishing is increasingly an element of hackers’ activities as part of multi-channel attacks: a cybercriminal first sends a phishing email and then “reminds” you to perform the action via SMS, increasing the credibility of the attack and the time pressure. AI helps generate such large-scale coordinated campaigns in less time.
Remind your employees that if they suspect that an SMS may be smishing, they should not click on the link and it is worth reporting the incident to CERT Polska via the form at incydent.cert.pl or by sending a suspicious SMS to 8080.
Cybersecurity Team: How to recognize smishing?
Telephone attacks (vishing) using voice cloning
Vishing (voice phishing) are social engineering attacks conducted through a telephone conversation, the aim of which is to manipulate the victim into taking a specific action (while ignoring the security aspect) – e.g. resetting a password, transferring funds or sharing sensitive data.
Voice cloning is an AI technology that allows you to recreate someone’s voice based on a short recording – e.g. from a webinar, YouTube or a company podcast. Just 30 seconds is enough for the system to learn the intonation, tempo, tone and typical phrases of a given person.
The combination of vishing and voice cloning gives cybercriminals an extremely dangerous tool. They can:
- call with a spoofed number (e.g. “company president”),
- speak in a convincing, familiar voice
- apply time pressure (“I’m traveling, I need help immediately”),
- and force an action, e.g. account reset, transfer, access to systems, disclosure of confidential information.
It is worth remembering that these attacks are often part of a multi-channel campaign (similar to smishing). For example, an email or SMS is sent in advance announcing the conversation. This combination drastically increases the credibility of the attack.
AI-generated deepfake video
Deepfake is a technology that allows you tocreate fake video or audio recordings that look and sound like reals. Thanks to GenAI, a short fragment of a recording is enough to generate a realistic video of someone saying or doing something they have never said or done. For example, we see the president on the screen and in the background we hear his voice (cloned thanks to AI), persuading us to take quick action: approving a transfer, changing access, or installing software.
Cyber criminals use this technique to:
- impersonating organizational leaders in video messages,
- strengthening BEC and spear phishing attacks,
- increasing pressure and authority in social engineering campaigns.
In the era of online meetings and remote work, the video form has gained considerable credibility. If a message appears in “internal” Slack, MS Teams or a company channel, few employees will question it.
Reliable AI profiles (fake persona)
One of the most dangerous methods of social engineering attacks powered by GenAI is the creation of false identities online. Thanks to AI, cybercriminals can instantly generate:
- realistic profile photos,
- false professional CVs (e.g. “Security Manager in a large financial company”),
- industry posts and interactions that build the image of an expert.
Such profiles are used, among others, to establish relationships on LinkedIn with company employees for the purpose of subsequent spear phishing or reconnaissance, spreading disinformation, gaining access to closed groups or communication channels (e.g. Slack, Teams, Discord).
AI enables not only the rapid generation of content, but also its distribution – e.g. by publishing comments, sharing articles, reacting to posts. In this way, the “person” looks credible, builds relationships and gains trust.
Tip: sensitize employees to be cautious about accepting invitations and contacts on professional social media, especially from people without a mutual relationship, with a very general profile or a “too perfect” photo.
How to recognize social engineering attacks powered by GenAI – 3 tips for your team
Modern phishing campaigns, powered by GenAI, are devoid of old, obvious errors. However, even the most polished email has its red flags. Below are the three most important warning signs your team should know, and at the end a free guide for your employees.
Be vigilant towards links (especially those that hide their purpose)
Malicious links remain one of the main vectors of phishing – but today they are masked much more effectively than before. Cybercriminals use external link shorteners (e.g. bit.ly, tinyurl), hyperlinks embedded in the text (“click here”), visually valid but fake domains (e.g. amaz0n.co vs amazon.com).
Good security practices to share with your team:
- Hover your mouse without clicking – the real address will appear in the lower left corner of the screen.
- Avoid shortened links – they hide the real purpose.
- Look for typos and strange domains – e.g. amaz0n.com instead of amazon.com.
Check attachments before opening
Many phishing campaigns are based on documents that are appropriately named (“Invoice_12_2024.doc”), contain macros that run malicious code, and are locked in password-protected archives to bypass scanners.
What to watch out for:
- ZIP/RAR archives with the password provided in the message body.
- Documents with macros: .docm, .xlsm, old .doc/.xls.
- Files .exe, .scr, .bat and double extensions: e.g. “invoice.pdf.exe”.
Rule: You should only open attachments from absolutely trusted sources and should scan them first.
Language errors 2.0
AI-generated content is grammatically correct, free from typos, formal tone and artificial precision. This means that the focus needs to shift from “classic mistakes” to subtle social engineering signals.
What to look out for:
- messages with too many polite forms or formal phrases without personalization (“Dear Customer”)
- strange constructions resulting from machine translation (“please complete the access confirmation procedure”),
- a mixture of languages or borrowed words (“thank you for payment”).
Conclusion: perfect language is NOT a guarantee of authenticity. GenAI can generate content that meets all validity rules but is still fake. A holistic approach is needed: analysis of the language, context, recipient, message structure and metadata.
Cybersecure Team:
8 tips for your employees on how to recognize phishing
How to effectively educate employees? Cybersecurity training vs. Practical Anti-Phishing Training
Phishing is the largest and most costly cyber threat today. In 2024, it was responsible for 39% of all incidents reported to CERT Polska, and the number of attacks exceeded 600,000. According to ENISA, as many as 60% of cyberattacks start with phishing, and the average cost of a data breach is USD 4.88 million (IBM, 2024).
No technical security measures guarantee 100% protection. In critical situations, people remain the last line of defense. Their decisions – click or report? – determine the success of the attack.
Why may traditional cybersecurity training be insufficient?
Gartner research shows that 69% of employees intentionally ignore security policies, and 93% know that their actions are risky – but they still repeat the same mistakes.
This shows that classic training is usually unable to change everyday habits. Why?
- They are too general: they do not take into account the specificity of the industry, roles in the organization or typical company scenarios.
- They are based on the transfer of theory: there is no learning in practice, so knowledge quickly evaporates.
- Detached from reality: not updated as often as cybercriminals’ methods are updated.
- They do not teach defensive behavior: they do not show how to react to a real threat in a dynamic situation.
Practical Anti-Phishing Training – a method of education that shapes safe habits
When no technical tool can guarantee complete protection, an organization’s cyber resilience depends on how its employees behave. It is not the level of security awareness that should determine readiness for cyber threats, but the ability to respond appropriately in practice.
That’s why Practical Anti-Phishing Training was created not as another e-learning or cybersecurity training to be checked off, but as a systematic training process that shapes real defensive reflexes. Instead of a one-time action, we provide a continuous, automated educational program conducted by SECAWA experts – we deal with everything: from preparing phishing simulations to analyzing the results. Designated people in the company (usually the CISO) have access to the proprietary training platform, which provides transparent reports and shows the real progress of the team in the form of accurate but readable statistics.
Why is it worth implementing Practical Anti-Phishing Training in your organization?
Below you will find a comparison table Practical Anti-Phishing Training with traditional cybersecurity training for companies. If you want to learn about SECAWA Practical Anti-Phishing Training and test our original training platform without costs and obligations – make an appointment at Free Phishing Test!


