Skip to main content
Whitesec AU
Back to Insights

Threat Intelligence15 November 2025

AI-Driven Social Engineering: The New Frontier

Whitesec Research Team
Executive Summary

Attackers are using generative AI to create hyper-realistic phishing campaigns and deepfakes. Learn the latest indicators of compromise and how to train your team.

The era of spotting phishing emails by looking for typos and poor grammar is over. Generative AI has democratized the ability to create flawless, context-aware social engineering campaigns at scale.

Beyond Text: Deepfake Impersonation

The most concerning trend in late 2025 is the commoditization of real-time deepfakes. We have observed successful attacks where threat actors join video calls posing as C-level executives. Using real-time face swapping and voice cloning, they instruct finance teams to execute urgent wire transfers.

"Seeing is no longer believing. In the age of AI, digital identity must be cryptographically verified, not just visually confirmed."

Defending Against AI Phishing

Traditional security awareness training is struggling to keep up. Organizations need to pivot to new defense strategies:

  • Out-of-Band Verification: Establish a protocol where any unusual request for funds or data must be verified through a secondary communication channel (e.g., a phone call to a known internal number).
  • Challenge Phrases: Implement internal "safe words" or challenge questions that AI models would not know from public data.
  • Behavioral Analytics: AI-driven email security tools can detect subtle shifts in tone or sending patterns that humans might miss.
WS

Written by Whitesec Research Team

Offensive Security Practitioners & ISO 27001 Auditors

Whitesec AU is an accredited Australian cybersecurity firm providing VAPT, Essential Eight gap analysis, CPS 234 compliance, and vCISO governance out of Perth, WA.

Need Technical Verification for Your Security Posture?

Speak with our Perth-based consultants to discuss your audit, tender, or penetration testing requirements.