Direct Answer: Social engineering in 2026 looks less like a clumsy email and more like a video call from your CFO. Attackers now use AI-generated voices, faces, and writing styles to impersonate executives, vendors, and trusted colleagues. Defending against it requires layered identity verification, executive-aware training, and a culture that rewards healthy skepticism.
The phishing email is not dead. It just brought reinforcements: an AI-cloned voice of your CFO, a deepfake video of your COO, and a perfectly worded message from a vendor who somehow knows your renewal date. Social engineering in 2026 is precision-targeted, and executives sit at the top of the kill chain.
This is not theoretical. It is happening on weekday afternoons, inside companies that thought they had a strong security posture.
Social engineering is the practice of manipulating people into taking actions that compromise security: wiring money, sharing credentials, approving access, opening files. It bypasses firewalls because it does not attack the network. It attacks the trust between humans inside the network.
That has always been the case. What changed in 2025 and 2026 is the production cost of a convincing lie.
According to the Verizon 2025 Data Breach Investigations Report, the human element played a role in 60% of breaches over the past year, and pretexting (the impersonation game underneath most business email compromise attacks) now accounts for more than half of all social engineering incidents.1 Generative AI dropped the floor on what it takes to clone someone’s voice or face: industry research cited across cybersecurity analysts shows a usable voice clone can be produced from as little as three seconds of audio.2
Translation: the LinkedIn keynote your CEO posted last quarter is a voice sample. The webinar your CFO did is a face sample. The earnings call is a script.
Three vectors are getting most of the attention from organized fraud groups right now. None of them require malware.
IBM’s 2025 Cost of a Data Breach Report found that AI was used in 16% of breaches, primarily to power phishing campaigns and deepfakes, and that phishing-driven breaches cost an average of $4.8 million.6
Three reasons, and they are uncomfortable.
The leaders most exposed are the ones doing their jobs well: visible, decisive, fast. The defense is not to disappear. The defense is to design verification rituals that scale with that visibility.
This is where most security advice gets generic. It does not have to. Treat the following as a leadership checklist, not an IT chore.
We help executive teams build the verification rituals, train the human firewall, harden identity and email, and run the incident playbook on the day something does get through. We have spent years walking SMB and mid-market clients up the TMM, and the cyber chapter of that journey now has a deepfake clause in it. For a candid view of where most leaders are still getting it wrong, see Cybersecurity Confessions: What Business Leaders Get Wrong.
Trusted. Secure. Connected.
If your team has not pressure-tested itself against an AI-driven impersonation attempt in the last 12 months, the gap is bigger than you think. We can help you find it before someone else does.
Ready to talk? Visit sentryitsolutions.com to schedule a security conversation.
Phishing is one type of social engineering. Social engineering is the broader category of human-targeted manipulation, which also includes pretexting, voice phishing (vishing), SMS phishing (smishing), and deepfake impersonation across video, voice, and email.
Both. The Arup case made headlines, but US deepfake-related fraud losses reached approximately $1.1 billion in 2025, roughly triple the prior year, according to industry analyst summaries of FinCEN and Treasury data.7 The high-dollar incidents are the visible edge of a much larger pattern.
Out-of-band verification of payment details, paired with a rule that no wire is approved on urgency alone. This single control, consistently enforced, defeats most BEC attempts in the field.
As little as three seconds of clean audio is enough to produce a usable clone with most commercially available tools. Public conference appearances, podcasts, and webinars are the most common training material.
Ask your team three questions: Do we have a written wire-verification protocol? Have our executives done a deepfake-aware tabletop exercise in the last year? Could a new finance hire reliably challenge a CEO video call asking for an urgent transfer? If you cannot answer yes to all three, there is room to grow.