Artificial Intelligence

Social Engineering Detection Moves Into the Live Conversation

Companies are pouring time and dollars into security awareness training, but little evidence shows it actually works against social engineering.

Deepfake detection

Companies are pouring time and dollars into security awareness training, but there is little empirical evidence to suggest it actually works against social engineering.

Social engineering remains a primary and successful attack vector. While system vulnerabilities can be patched, social engineering cannot. The most common pseudo ‘patch’ is user awareness training, but this has failed to block the vector. Human defenders should not and cannot be expected to detect trickery designed to manipulate their psychology. And the tricks are becoming better hidden and more sophisticated with the use of AI deep fakery.

Successful examples of social engineering include:

The Las Vegas casino breaches of 2023, via vishing. Scattered Spider attackers, posing as employees, tricked the casino’s help desk staff to reset passwords and bypass MFA. MGM Resorts was forced to shut down digital operations for ten days at an estimated cost of $100 million in lost revenue and remediation costs. Caesars Entertainment is thought to have paid a $15 million ransom after the attackers demanded $30 million.

More recently, the Brinks Home leak disclosed in August 2026 also involved voice phishing and the enterprise help desk. This time the attacker was ShinyHunters, although the group has a known relationship with Scattered Spider. Here the attacker simply talked a help desk employee through completing a Microsoft Entra authentication step, granting the hacker immediate access. Almost five million customer records and 41 gigabytes of corporate data were subsequently published on a public hacking forum.

If human detection of social engineering cannot be assured, other means of detection must be employed – and technology is the pre-eminent option. The use of technology to detect both traditional and newer AI deep faked social engineering is increasing and improving. One example comes from Netarx.

Advertisement. Scroll to continue reading.

The firm’s solution applies a proprietary orchestration layer which it describes as an AI defense meta harness. The harness correlates individual signals detected by more than 40 AI models continuously scanning all communications while they are in progress, analyzing more than 1,000 digital and metadata signals for each interaction.

For example, to ensure the physical device delivering a feed belongs to its authorized user, Netarx analyzes device fingerprints, EXIF data, compression signatures, and location mismatches. For AI-generated voice communications from GANs or voice cloners it examines the micro-artifacts undetectable by the human ear, such as unnatural background silencing and electronic compression anomalies.

If video is also included, it matches physical lip movements directly against incoming voice signals. For the facial image, it inspects individual video frames for anomalies in micro-expressions, unnatural blinking frequencies, lighting inconsistencies, or warping around hair lines.

No single signal is decisive in indicating fraud. However, the collection and recognition of multiple questionable signals can swing the needle between genuine and fake in real time. However, detecting fraud in progress is only half the problem – the detection must also be relayed to the user in an understandable manner, also in real time. The traditional approach, autonomously blocking dangerous situations, is extreme and can cause more problems than it solves.

To avoid this, Netarx has developed a color-coded real-time traffic analysis indicator displayed on screen during the communication. Green indicates that the human identity and the device concerned have been verified. Amber declares that the source is unknown, or that suspicious metadata anomalies have been detected. Red indicates that synthetic media or an active deepfake has been identified. (Internally, the company uses the term ‘flurp’ for this traffic light system. Flurp is defined in the Urban Dictionary as the noise a snail makes.) If amber turns to red during the conversation, it is probably time to disengage; but this is the user blocking the sender rather than the system arbitrarily blocking the process. 

NIK (the Netarx Identity Key) runs on Windows, macOS, Chrome, iOS and Android; and the company also publishes a database (the Impact Database) that catalogs real-world security incidents where human deception played a decisive role in the attack.

This Netarx social engineering solution is an early example of technology supplanting human detection. It will not be the last, because social engineering is a growing vector and a serious threat to enterprise security. The entire security stack is bypassed if a single privileged employee invites a social engineering attacker across the MFA threshold.

Related: ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing

Related: UNC6692 Uses Email Bombing, Social Engineering to Deploy ‘Snow’ Malware

Related: Cyber Insights 2026: Social Engineering

Related: Going Into the Deep End: Social Engineering and the AI Flood

Related Content

Phishing

Analysis of 2.47 million simulated attacks shows why organizations should measure credential leaks and reporting, not just clicks.

Artificial Intelligence

Atalanta's Argo product is now being used to prove the resilience of Viasat’s satellite communications network.

Endpoint Security

The cybersecurity companies patched critical and high-severity vulnerabilities in some of their products.

Artificial Intelligence

The stocks of major cybersecurity companies have fallen sharply over fears that AI is disrupting the industry.

Artificial Intelligence

isVerified provides Android and iOS mobile applications designed to protect enterprise communications. 

Cybercrime

AI can be used by extremist groups to pump out propaganda or deepfakes at scale, widening their reach and expanding their influence.

Cybersecurity Funding

The cybersecurity startup detects impersonation risk in real-time, across video, phone, and chat communication.

ICS/OT

Radiflow360 provides enhanced visibility, risk management, and incident response capabilities for mid-sized industrial enterprises. 

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version