HACK/PROJECT Daily Threat Intelligence
Threat feed live Updated — 24.07.2026 15:36 CET 37 dossiers MITRE ATT&CK mapping

Editorial explainer · official sources (ENISA)medium

Your boss's voice can be fake: social engineering in the age of AI

Social engineering remains the most-used way in, and AI has made it cheaper and more convincing: voice cloning can mimic an executive's voice from a few seconds of audio, and generated phishing text lacks the errors that once gave it away. ENISA places phishing and social engineering at the top of the threats. An explainer on what really changes, and why the defense is cultural and procedural before it is technical.

An explainer, not the attack of the day

This piece doesn't cover a single scam: it covers how an old technique — convincing a person to do something — has become more dangerous because AI lowered its cost and raised its credibility. It's a matter of culture, not product: no software you buy solves it alone, and ignoring it is the most common way to get the door opened from the inside.

The starting figure

The findings from ENISA, the European Union agency for cybersecurity, are blunt: phishing and social engineering remain among the most-used initial-access vectors against EU organizations. That's not new in itself — people have always been the most convenient target — but the novelty is how they're attacked. ENISA notes adversaries increasingly use AI to automate and enhance campaigns: manipulated models, synthetic content, generated text that no longer carries the grammatical errors that once triggered suspicion.

What changed, concretely

Three things, all in the same direction. The first is text quality: the phishing email or message generated by a model is fluent, contextual, personalized. The folk heuristic "if it's badly written it's a scam" no longer works — it was never reliable, and now it's counterproductive.

The second is voice cloning. With a few seconds of audio — a public talk, a voicemail, a social video — it's possible to synthesize a voice that sounds like an executive's. The "urgent" call from the boss asking for an immediate transfer or a system's credentials is no longer a movie premise: it's a documented technique, aimed above all at finance, HR and help desks.

The third is scale. Automation makes it possible to run many more credible conversations at once, lowering the cost per attempt and raising the number of reachable targets. Phishing becomes an industrial service, not a craft.

Why the defense is (mostly) cultural

Because the point under attack is not a system, it is a human decision made under pressure. And the pressures are always the same: urgency ("needed now"), authority ("it's the director"), secrecy ("don't tell anyone"). Recognizing this trio is worth more than any technical course: when a request arrives carrying all three, that's the moment to slow down, not to comply.

The effective defense isn't blaming whoever falls for it — it's removing the attacker's leverage. That means procedures that don't depend on recognizing a voice: an independent-channel confirmation before any sensitive operation (call back the known number, not the one the request came from), a second approval for payments over a threshold, explicit permission to say no to a request "from above" without fear of reprisal. These are rules, not slides.

In one line

AI didn't invent deception, it industrialized its production. The countermeasure isn't a miraculous deepfake detector, but the same one as always, now made non-negotiable: verify identity with something other than voice or tone, and build processes in which no single request, however convincing, is enough on its own to move money or data. For context figures and threat evolution, the reference is ENISA's Threat Landscape.

More dossiers