The impact of artificial intelligence on social engineering attacks

Feb 14, 2023 | Trends

Read the original in Spanish →

The impact of artificial intelligence on social engineering attacks

Social engineering is a set of techniques used by cybercriminals to trick people into divulging sensitive information or taking harmful actions. In this post, we will discuss the most common types of social engineering attacks and how artificial intelligence is being used to improve their effectiveness.

Phishing attacks are one of the most common types of social engineering attacks. These attacks involve the use of fake emails, social media messages, or other electronic communication methods to trick individuals into disclosing personal and sensitive information. The attacker can use information collected from public resources, especially social media, to create a credible fake message that appears to come from a known person or organization. These attacks can take different forms such as email phishing, malware, spear phishing, whaling, smishing or vishing.

Pretexting attacks involve creating fake, credible scenarios to obtain victims’ personal data. The attacker relies on pretexts that make the victim believe and trust the attacker. The attack is usually carried out by telephone, email or physical means. The pretext may be an offer to provide services or find employment, request personal information, help a friend access something, or win the lottery.

Baiting attacks (baiting) involve luring individuals into a trap. These attacks can take the form of a malicious attachment with a catchy name, a message indicating that you have won a prize, or the physical method of spreading malware via infected USB drives left in visible areas.

tailgating or piggybacking involves attackers gaining access to restricted physical areas or information through authorized people, either by accessing behind them without their knowledge or by tricking them into directly allowing them access.

With the use of artificial intelligence in the field of social engineering we can find new tools such as Voice Cloning, Deepfakes or Bots, which can manipulate sound and images to deceive people.

Voice cloning technology is an example of how artificial intelligence is being used in social engineering attacks. Cybercriminals can create a digital copy of someone’s voice in minutes, which can be used to trick people into believing they are talking to someone they are not.

Deepfakes allow the creation of videos and photos manipulated with artificial intelligence that are used to spread misinformation and manipulate people. With the help of deepfakes, scammers can orchestrate social engineering attacks that appear to come from an acquaintance, that is, someone we trust and whose motives do not need to be questioned.

Finally, a novel attack uses chatbots to guide victims through the process and give them more credibility. The chatbot starts a conversation on a legitimate website and takes the victim to a phishing site. A real attack, according to a post by Trustwave, begins with an email warning the victim that their Facebook page has violated community rules and asking them to click the “Appeal Now” button. The victim is directed to a website posing as a Facebook support chat, where they are asked to submit their personal information and account password.

In conclusion, artificial intelligence has improved the effectiveness of social engineering attacks. It is important that businesses and individuals take steps to protect themselves from these attacks, such as verifying the authenticity of emails and phone calls, and taking appropriate security measures. Additionally, it is important for companies to invest in advanced detection and response technology to identify and mitigate social engineering attacks.

← Previous How to protect your online accounts Next → What is Data Security Posture Management (DSPM)?
← Return to blog Back to top ↑