Skip to content

Social Engineering in 2026: The Attacks Are Getting Personal

Social engineering in 2026 looks less like a clumsy email and more like a video call from your CFO

Direct Answer: Social engineering in 2026 looks less like a clumsy email and more like a video call from your CFO. Attackers now use AI-generated voices, faces, and writing styles to impersonate executives, vendors, and trusted colleagues. Defending against it requires layered identity verification, executive-aware training, and a culture that rewards healthy skepticism.

The phishing email is not dead. It just brought reinforcements: an AI-cloned voice of your CFO, a deepfake video of your COO, and a perfectly worded message from a vendor who somehow knows your renewal date. Social engineering in 2026 is precision-targeted, and executives sit at the top of the kill chain.

This is not theoretical. It is happening on weekday afternoons, inside companies that thought they had a strong security posture.

What Is Social Engineering, and Why Has It Changed So Fast?

Social engineering is the practice of manipulating people into taking actions that compromise security: wiring money, sharing credentials, approving access, opening files. It bypasses firewalls because it does not attack the network. It attacks the trust between humans inside the network.

That has always been the case. What changed in 2025 and 2026 is the production cost of a convincing lie.

According to the Verizon 2025 Data Breach Investigations Report, the human element played a role in 60% of breaches over the past year, and pretexting (the impersonation game underneath most business email compromise attacks) now accounts for more than half of all social engineering incidents.1 Generative AI dropped the floor on what it takes to clone someone’s voice or face: industry research cited across cybersecurity analysts shows a usable voice clone can be produced from as little as three seconds of audio.2

Translation: the LinkedIn keynote your CEO posted last quarter is a voice sample. The webinar your CFO did is a face sample. The earnings call is a script.

How Are Attackers Using AI to Impersonate Executives in 2026?

Three vectors are getting most of the attention from organized fraud groups right now. None of them require malware.

  1. Deepfake video calls. In early 2024, the global engineering firm Arup lost $25.6 million when a Hong Kong finance employee joined a video call with what appeared to be the CFO and several colleagues. Every face on the call was AI-generated. The employee approved 15 transactions before discovering the fraud.3 The attack worked because video has long been our trust shortcut. We have to retire that shortcut.
  2. Voice cloning for vishing. Deepfake-enabled voice phishing surged more than 1,600% in the United States between Q4 2024 and Q1 2025.4 Attackers use a brief audio sample to call a controller or executive assistant, sound exactly like the executive, and request an urgent, confidential wire. The hallmarks: speed, authority, and secrecy.
  3. AI-personalized phishing and BEC. Generative AI eliminated the typos, awkward grammar, and cultural tells that used to flag a phishing email. Attackers now scrape LinkedIn, press releases, and earnings transcripts to write messages that mirror an executive’s actual voice, reference real internal projects, and time delivery to known travel windows. The FBI’s 2024 Internet Crime Report logged $2.77 billion in BEC losses across 21,442 reported incidents.5 That is the part that gets reported.

IBM’s 2025 Cost of a Data Breach Report found that AI was used in 16% of breaches, primarily to power phishing campaigns and deepfakes, and that phishing-driven breaches cost an average of $4.8 million.6

Why Are Executives the Target?

Three reasons, and they are uncomfortable.

  • Authority shortcuts review. A request that looks like it came from the CEO bypasses the friction other employees would meet.
  • Public footprint creates training data. The more visible an executive is (and visibility is a job requirement), the more material exists to clone.
  • Speed is the currency. Executives are expected to move fast. Attackers exploit that expectation by manufacturing urgency.

The leaders most exposed are the ones doing their jobs well: visible, decisive, fast. The defense is not to disappear. The defense is to design verification rituals that scale with that visibility.

What Should Leaders Do About It? A Five-Point Plan

This is where most security advice gets generic. It does not have to. Treat the following as a leadership checklist, not an IT chore.

  1. Establish out-of-band verification for every wire, vendor change, and credential reset. If a request arrives by email or video call, verification happens by phone or in person, using a number not provided in the original message. No exceptions for urgent.
  2. Train executives, finance, HR, and EAs as a unit. General security awareness is not enough for high-target roles. These teams need scenario-based training on deepfake calls, voice cloning, and BEC patterns. Run live drills. Reward catches publicly. Sentry’s guide to building a human firewall walks through the program design.
  3. Restrict the public material that fuels the clones. This is not about going silent. It is about being deliberate. Long-form executive video, voice samples, and signature templates should be reviewed with security in mind, not only marketing.
  4. Publish an internal code phrase for sensitive financial requests. A pre-agreed verification phrase, rotated periodically, that no AI can guess from public material. Simple, manual, effective.
  5. Move up the Technology Maturity Model. Sentry’s TMM frames defense in four stages: Operate (the basics work), Secure (the right controls and culture exist), Integrate (security is woven into business workflows), and Innovate (you stay ahead of evolving threats). Most companies hit by social engineering are still living in Operate. The companies that survive 2026 live in Secure or beyond. If your cyber posture is closer to good enough, that is the gap.

How Sentry Helps

We help executive teams build the verification rituals, train the human firewall, harden identity and email, and run the incident playbook on the day something does get through. We have spent years walking SMB and mid-market clients up the TMM, and the cyber chapter of that journey now has a deepfake clause in it. For a candid view of where most leaders are still getting it wrong, see Cybersecurity Confessions: What Business Leaders Get Wrong.

Trusted. Secure. Connected.

If your team has not pressure-tested itself against an AI-driven impersonation attempt in the last 12 months, the gap is bigger than you think. We can help you find it before someone else does.

Ready to talk? Visit sentryitsolutions.com to schedule a security conversation.

Frequently Asked Questions

What is the difference between phishing and social engineering?

Phishing is one type of social engineering. Social engineering is the broader category of human-targeted manipulation, which also includes pretexting, voice phishing (vishing), SMS phishing (smishing), and deepfake impersonation across video, voice, and email.

Are deepfake attacks really common, or just headline-grabbing?

Both. The Arup case made headlines, but US deepfake-related fraud losses reached approximately $1.1 billion in 2025, roughly triple the prior year, according to industry analyst summaries of FinCEN and Treasury data.7 The high-dollar incidents are the visible edge of a much larger pattern.

What is the single most effective control against business email compromise?

Out-of-band verification of payment details, paired with a rule that no wire is approved on urgency alone. This single control, consistently enforced, defeats most BEC attempts in the field.

How quickly can my voice be cloned?

As little as three seconds of clean audio is enough to produce a usable clone with most commercially available tools. Public conference appearances, podcasts, and webinars are the most common training material.

How do I know if my company is ready?

Ask your team three questions: Do we have a written wire-verification protocol? Have our executives done a deepfake-aware tabletop exercise in the last year? Could a new finance hire reliably challenge a CEO video call asking for an urgent transfer? If you cannot answer yes to all three, there is room to grow.

References

  1. Verizon, 2025 Data Breach Investigations Report. verizon.com/business/resources/reports/dbir/
  2. Industry analyst summaries of AI voice cloning capability, 2025 (three-second clone benchmark cited across multiple cybersecurity research blogs).
  3. CNN Business, “Arup revealed as victim of $25 million deepfake scam involving Hong Kong employee,” May 16, 2024. cnn.com
  4. DeepStrike, Vishing Statistics 2025, citing US deepfake-enabled vishing growth Q4 2024 to Q1 2025.
  5. Federal Bureau of Investigation, Internet Crime Complaint Center (IC3), 2024 Internet Crime Report. ic3.gov
  6. IBM, Cost of a Data Breach Report 2025. ibm.com/reports/data-breach
  7. DeepStrike, Deepfake Statistics 2025, summarizing US deepfake fraud loss totals.