AI/ML, AI benefits/risks

AI usage in social engineering attacks examined

Cyber attack deepfake attack. Vulnerability text in binary system

Artificial intelligence may have enabled more effective audio and video deepfakes for social engineering scams, but has yet to be thoroughly integrated into threat actors' hacking techniques, according to Cybersecurity Dive.

Incorporation of AI in cybercrime has been stifled by computational limitations and the challenges in training and configuring models, a report from Intel 471 showed. Attackers would also rather continue using still effective tactics instead of allocating more time to automate models within their infrastructure and coalescing them with delivery systems while ensuring clandestine operations.

"Although AI is often touted as a game-changer for the social-engineering landscape, in the context of phishing, most threat actors still lean on [phishing-as-a-service] platforms and off-the-shelf kits and use AI primarily for content drafting and localization not for true automation or innovation," said Intel 471 researchers, who also predicted increased deepfake-based impersonation and AI-powered disinformation campaigns.

An In-Depth Guide to AI

Get essential knowledge and practical strategies to use AI to better your security program.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds