started · updated
Cybercriminals use AI and vishing to escalate social engineering attacks
Cybercriminals are increasingly utilizing sophisticated social engineering and vishing (voice phishing) tactics to bypass security controls. These attacks rely on manipulating individuals through trust and urgency rather than exploiting technical vulnerabilities alone.
Modern scammers use techniques such as caller ID spoofing to impersonate banks, government agencies, or IT departments. The integration of AI-generated or cloned voices has significantly increased the credibility of these fraudulent calls, making it harder for victims to distinguish between legitimate representatives and attackers.
In corporate environments, attackers target employees by impersonating colleagues or service desk workers to gain access to credentials or authentication requests. Recent examples include phishing campaigns targeting healthcare patients and voice phishing used by the ShinyHunters group to compromise single sign-on accounts at McKesson.