• Skip to main content
  • Skip to header right navigation
  • Skip to after header navigation
  • Skip to site footer
MyZA

MyZA

News, Directory, Events and Other Stuff

  • Social Media
  • Sport
  • World News
  • Home
  • Submit News
  • Directory
  • Events
  • Stratlec
  • TFSA
  • News
    • APO
    • Today’s Sport News
    • Todays Social Media and Tech Headlines
    • Today’s World News
    • Today’s SA Financial News
  • Contact
You are here: Home / News / Social Engineering 2.0: When AI Becomes the Ultimate Manipulator

Social Engineering 2.0: When AI Becomes the Ultimate Manipulator

16 June 2025 by Guest
KnowBe4

Once the domain of elite spies and con artists, social engineering is now in the hands of anyone with an internet connection – and AI is the accomplice. Supercharged by generative tools and deepfake technology, today’s social engineering attacks are no longer sloppy phishing attempts. They’re targeted, psychologically precise, and frighteningly scalable.

Welcome to Social Engineering 2.0, where the manipulators don’t need to know you personally. Their AI already does.

Deception at machine levels

Social engineering works because it bypasses firewalls and technical defences. It attacks human trust. From fake bank alerts to long-lost Nigerian princes, these scams have traditionally relied on generic hooks and low-effort deceit. But that’s changed, and continues to.

“AI is augmenting and automating the way social engineering is carried out,” says Anna Collard, SVP of Content Strategy & Evangelist at KnowBe4 Africa. “Traditional phishing markers like spelling errors or bad grammar are a thing of the past. AI can mimic writing styles, generate emotionally resonant messages, and even recreate voices or faces (https://apo-opa.co/409nwPV) – all within minutes.”

The result? Cybercriminals now wield the capabilities of psychological profilers. By scraping publicly available data – from social media to company bios – AI can construct detailed personal dossiers. “Instead of one-size-fits-all lures, AI enables criminals to create bespoke attacks,” Collard explains. “It’s like giving every scammer access to their own digital intelligence agency.”

The new face of manipulation: Deepfakes

One of the most chilling evolutions of AI-powered deception is the rise of deepfakes – synthetic video and audio designed to impersonate real people. “There are documented cases where AI-generated voices have been used to impersonate CEOs and trick staff into wiring millions (https://apo-opa.co/4e4JBVv),” notes Collard.

In South Africa, a recent deepfake video circulating on WhatsApp featured a convincingly faked endorsement by FSCA Commissioner Unathi Kamlana promoting a fraudulent trading platform. Nedbank had to publicly distance itself from the scam (https://apo-opa.co/4e4JCJ3).

“We’ve seen deepfakes used in romance scams, political manipulation, even extortion,” says Collard. One emerging tactic involves simulating a child’s voice to convince a parent they’ve been kidnapped (https://apo-opa.co/3HY5WrR) – complete with background noise, sobs, and a fake abductor demanding money.

“It’s not just deception anymore,” Collard warns. “It’s psychological manipulation at scale.”

The Scattered Spider effect

One cybercrime group exemplifying this threat is Scattered Spider. Known for its fluency in English and deep understanding of Western corporate culture, this group specialises in highly convincing social engineering campaigns. “What makes them so effective,” notes Collard, “is their ability to sound legitimate, form quick rapport, and exploit internal processes – often tricking IT staff or help-desk agents.” Their human-centric approach, amplified by AI tools, such as using audio deepfakes to spoof victims’ voices for obtaining initial access, shows how the combination of cultural familiarity, psychological insight, and automation is redefining what cyber threats look like. It’s not just about technical access – it’s about trust, timing, and manipulation.

Social engineering at scale

What once required skilled con artists days or weeks of interaction – establishing trust, crafting believable pretexts, and subtly nudging behaviour – can now be done by AI in the blink of an eye. “AI has industrialised the tactics of social engineering,” says Collard. “It can perform psychological profiling, identify emotional triggers, and deliver personalised manipulation with unprecedented speed.”

The classic stages – reconnaissance, pretexting, rapport-building – are now automated, scalable, and tireless. Unlike human attackers, AI doesn’t get sloppy or fatigued; it learns, adapts, and improves with every interaction.

The biggest shift? “No one has to be a high-value target anymore,” Collard explains. “A receptionist, an HR intern, or a help-desk agent; all may hold the keys to the kingdom. It’s not about who you are – it’s about what access you have.”   

Building cognitive resilience

In this new terrain, technical solutions alone won’t cut it. “Awareness has to go beyond ‘don’t click the link,’” says Collard. She advocates for building ‘digital mindfulness’ and ‘cognitive resilience’ – the ability to pause, interrogate context, and resist emotional triggers (https://apo-opa.co/3FF6Zwn).

This means:

  • Training staff to recognise emotional manipulation, not just suspicious URLs.
  • Running simulations using AI-generated lures, not outdated phishing templates.
  • Rehearsing calm, deliberate decision-making under pressure, to counter panic-based manipulation.

Collard recommends unconventional tactics, too. “Ask HR interviewees to place their hand in front of their face during video calls – it can help spot deepfakes in hiring scams,” she says. Families and teams should also consider pre-agreed code words or secrets for emergency communications, in case AI-generated voices impersonate loved ones.

Defence in depth – human and machine

While attackers now have AI tools, so too do defenders. Behavioural analytics, real-time content scanning, and anomaly detection systems are evolving rapidly. But Collard warns: “Technology will never replace critical thinking. The organisations that win will be the ones combining human insight with machine precision.”

And with AI lures growing more persuasive, the question is no longer whether you’ll be targeted – but whether you’ll be prepared. “This is a race,” Collard concludes. “But I remain hopeful. If we invest in education, in critical thinking and digital mindfulness, in the discipline of questioning what we see and hear – we’ll have a fighting chance.”

Distributed by APO Group on behalf of KnowBe4.

Media files
KnowBe4
Download logo

Once the domain of elite spies and con artists, social engineering is now in the hands of anyone with an internet connection – and AI is the accomplice. Supercharged by generative tools and deepfake technology, today’s social engineering attacks are no longer sloppy phishing attempts. They’re targeted, psychologically precise, and frighteningly scalable.

Welcome to Social Engineering 2.0, where the manipulators don’t need to know you personally. Their AI already does.

Table of Contents

Toggle
  • Deception at machine levels
  • The new face of manipulation Deepfakes
  • The Scattered Spider effect
  • Social engineering at scale
  • Building cognitive resilience
  • Defence in depth – human and machine

Deception at machine levels

Social engineering works because it bypasses firewalls and technical defences. It attacks human trust. From fake bank alerts to long-lost Nigerian princes, these scams have traditionally relied on generic hooks and low-effort deceit. But that’s changed, and continues to.

“AI is augmenting and automating the way social engineering is carried out,” says Anna Collard, SVP of Content Strategy & Evangelist at KnowBe4 Africa. “Traditional phishing markers like spelling errors or bad grammar are a thing of the past. AI can mimic writing styles, generate emotionally resonant messages, and even recreate voices or faces – all within minutes.”

The result? Cybercriminals now wield the capabilities of psychological profilers. By scraping publicly available data – from social media to company bios – AI can construct detailed personal dossiers. “Instead of one-size-fits-all lures, AI enables criminals to create bespoke attacks,” Collard explains. “It’s like giving every scammer access to their own digital intelligence agency.”

The new face of manipulation: Deepfakes

One of the most chilling evolutions of AI-powered deception is the rise of deepfakes – synthetic video and audio designed to impersonate real people. “There are documented cases where AI-generated voices have been used to impersonate CEOs and trick staff into wiring millions,” notes Collard.

In South Africa, a recent deepfake video circulating on WhatsApp featured a convincingly faked endorsement by FSCA Commissioner Unathi Kamlana promoting a fraudulent trading platform. Nedbank had to publicly distance itself from the scam.

“We’ve seen deepfakes used in romance scams, political manipulation, even extortion,” says Collard. One emerging tactic involves simulating a child’s voice to convince a parent they’ve been kidnapped – complete with background noise, sobs, and a fake abductor demanding money.

“It’s not just deception anymore,” Collard warns. “It’s psychological manipulation at scale.”

The Scattered Spider effect

One cybercrime group exemplifying this threat is Scattered Spider. Known for its fluency in English and deep understanding of Western corporate culture, this group specialises in highly convincing social engineering campaigns. “What makes them so effective,” notes Collard, “is their ability to sound legitimate, form quick rapport, and exploit internal processes – often tricking IT staff or help-desk agents.” Their human-centric approach, amplified by AI tools, such as using audio deepfakes to spoof victims’ voices for obtaining initial access, shows how the combination of cultural familiarity, psychological insight, and automation is redefining what cyber threats look like. It’s not just about technical access – it’s about trust, timing, and manipulation.

Social engineering at scale

What once required skilled con artists days or weeks of interaction – establishing trust, crafting believable pretexts, and subtly nudging behaviour – can now be done by AI in the blink of an eye. “AI has industrialised the tactics of social engineering,” says Collard. “It can perform psychological profiling, identify emotional triggers, and deliver personalised manipulation with unprecedented speed.”

The classic stages – reconnaissance, pretexting, rapport-building – are now automated, scalable, and tireless. Unlike human attackers, AI doesn’t get sloppy or fatigued; it learns, adapts, and improves with every interaction.

The biggest shift? “No one has to be a high-value target anymore,” Collard explains. “A receptionist, an HR intern, or a help-desk agent; all may hold the keys to the kingdom. It’s not about who you are – it’s about what access you have.”

Building cognitive resilience

In this new terrain, technical solutions alone won’t cut it. “Awareness has to go beyond ‘don’t click the link,’” says Collard. She advocates for building ‘digital mindfulness’ and ‘cognitive resilience’ – the ability to pause, interrogate context, and resist emotional triggers.

This means:

  • Training staff to recognise emotional manipulation, not just suspicious URLs.
  • Running simulations using AI-generated lures, not outdated phishing templates.
  • Rehearsing calm, deliberate decision-making under pressure, to counter panic-based manipulation.

Collard recommends unconventional tactics, too. “Ask HR interviewees to place their hand in front of their face during video calls – it can help spot deepfakes in hiring scams,” she says. Families and teams should also consider pre-agreed code words or secrets for emergency communications, in case AI-generated voices impersonate loved ones.

Defence in depth – human and machine

While attackers now have AI tools, so too do defenders. Behavioural analytics, real-time content scanning, and anomaly detection systems are evolving rapidly. But Collard warns: “Technology will never replace critical thinking. The organisations that win will be the ones combining human insight with machine precision.”

And with AI lures growing more persuasive, the question is no longer whether you’ll be targeted – but whether you’ll be prepared. “This is a race,” Collard concludes. “But I remain hopeful. If we invest in education, in critical thinking and digital mindfulness, in the discipline of questioning what we see and hear – we’ll have a fighting chance.”

Per Kind Favour of APO

Africa Fact: The palace in the Kenyan city of Gedi contains evidence of piped water controlled by taps. In addition it had bathrooms and indoor toilets.

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook
  • Print (Opens in new window) Print
  • Email a link to a friend (Opens in new window) Email
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Mastodon (Opens in new window) Mastodon
Category: NewsTag: APO, Fraud

If you feel strongly about this article then feel free to send MyZA a ‘Letter to the Editor’ using the submission form below:


Letter to the Editor

This field is for validation purposes and should be left unchanged.
If this is in response to an article please include that article title here or as the lead in for the first paragraph of your Letter below.

Separate tags with commas

Localise your letter by naming the city your words are about. Add relevant words describing your subject. Single comma separated words of no more than 5
Your Name(Required)
Your Name will be linked to the website below.
Your personal, business or social media web site
Choose NO to not set up a user account on MyZA. User Accounts will allow you to submit letters under your own Author Name

3 Latest Letters to the Editor:

  • Fun South African fact

    Dear Editor Fun South African fact: towns like Franschhoek and Stellenbosch are home to world-class wine farms set in stunning, scenic surroundings. Regards Aressa Smith In Response to/From: Luxury Properties Seized in New Lottery Crackdown

    27 January 2026
  • Condolences on the Passing of Lusanda Dumke

    Statement by Leander Kruger MPL – DA Buffalo City Constituency Leader: The Democratic Alliance in Buffalo City Metropolitan Municipality mourns the passing of Springbok Women’s rugby player and Mdantsane trailblazer, Lusanda Dumke, who lost her battle with cancer at the age of 28. South Africa has lost an exceptional athlete, a leader, and a source…

    17 December 2025
  • Rape Kits Delivered, But…

    Statement by Nicholas Gotsell MP – DA NCOP Member on Security & Justice: The DA can confirm that 2 840 rape kits arrived in Cape Town on Monday, following sustained DA oversight and pressure after multiple police stations across the Western Cape were found to be without this critical forensic evidence tool. While this delivery…

    17 December 2025

About Guest

Previous Post:South Africa Condemns Targeting of Civilians, Urges De-escalation Between Iran and Israel
Next Post:South African Citizens in the Islamic Republic of Iran Requested to Ensure They Are Registered With the Embassy

Reader Interactions

Comments

  1. judge

    19 June 2025 at 10:14 pm

    Why is gambling banned in South Africa?

    Because there are too many cheetahs.

  2. 101

    17 June 2025 at 6:44 am

    Fun South African Fact: The waters surrounding the 2,500km long coastline are teeming with life. You’ll find great white sharks, African penguins, dolphins and much much more in South Africa’s oceans. Many travellers visit the coast to watch the annual whale migrations. In Hermanus, in the Western Cape, you can see hundreds of whales from June to late November. Simon’s Town, another coastal Western Cape town, is home to Boulder’s Beach. Here you can swim alongside colonies of African Penguins!

Copyright © 2026 · MyZA · All Rights Reserved · Powered by Reach Trust