Whakataunga 5 Judgement 5

Social engineering, the manipulation of individuals to access networks and systems, is a persistent threat to organisations and businesses

Ko te rāwekeweke pāpori tētahi tuma tūroa ki ngā whakahaere me ngā tāngata

Social engineering is a persistent and effective technique used by malicious actors to gain access to networks, to steal information and to defraud individuals. 

Artificial Intelligence (AI) is making it easier to create and deploy sophisticated social engineering attacks. These attacks include highly convincing deepfakes and the integration of publicly available or stolen data to create more authentic messages to manipulate and persuade targets. 

Why does this matter?

Social engineering attacks are sometimes associated with scams and fraud against individuals, but the targets often include multi-national businesses, government agencies and third-party suppliers. In the past year, social engineering techniques have been used to compromise New Zealand healthcare organisations and breach the security of New Zealand government organisations. 

Because social engineering targets individuals it is a tool that can successfully bypass physical or software defences. The targeting of IT support services and help desks has proven a highly effective vector for cybercriminals seeking a high-leverage low-resistance entry point to corporate networks.

What's the current landscape? 

Social engineering attacks can be meticulously planned and use sophisticated multi-step techniques to obtain credentials and infiltrate networks. The use of AI tools to undertake reconnaissance of individuals or organisations and personalise messages by combining harvested or stolen data with AI impersonation, is another way in which social engineering techniques are becoming more convincing and effective.

Techniques and tactics are evolving with the use of generative AI providing cybercriminals and other malicious actors with new tools to persuade, manipulate and deceive individuals. These include:

  • Generating extremely convincing phishing messages or fake websites 
  • Generating scam phone calls in which you talk with an AI directly
  • Mimicking writing styles, corporate branding, and slang used by particular communities
  • Translating scam messages or voice calls into other languages. 

Social engineering techniques include the impersonation of a trusted person or organisation, the use of emotional language or messages, and pressuring victims to take actions in a short time frame. Social engineering can be done by email, on collaboration platforms such as Microsoft Teams or by using audio or video tools including deepfakes. 

If AI tools ultimately enable stronger cyber defences at the software layer, then social engineering will become a more important vector for criminals and other malicious actors to obtain credentials and breach cyber security.

TechSupportCall1

Case study 5: Targeting IT professionals

Technically literate individuals can fall victim to social engineering techniques, and some social engineering lures are tailored to these victims. 

compagnons rWE7bTqgMJE unsplash

Case study 6: Online collaboration platforms

Online collaboration platforms have become another vector for social engineering compromise if they are not effectively locked down. In a case reported to the NCSC a contractor to New Zealand government organisations received an inauthentic ‘helpdesk’ call via Microsoft Teams. From there, actors socially engineered their access to the contractor’s network and installed software that enabled them to evade malware detection and exfiltrate data.

florian van duyn xVh XtRFENw unsplash

Case study 7: Qantas Airlines

Social engineering and supply chain breaches were among the techniques used to undertake a large-scale cyber attack on Qantas in mid-2025. Cybercriminals used AI enabled voice-phishing to manipulate call centre staff into uploading software for a third-party application that had been modified to enable data exfiltration.

Implications for organisations

Organisations need to support and train their staff to recognise and be resistant to social engineering attacks. This is true for staff across organisations as well as those working in common attack targets such as call centres and IT service desks.

Social engineering attacks against call centres and IT service desks have demonstrated the effectiveness of these tactics in enabling cyber extortion incidents. Cybercriminals target service desks as a high-leverage, low-resistance entry point into corporate networks.

In addition to supporting staff, organisations can mitigate the impact of breaches by ensuring stronger access controls to limit lateral movement in networks and unnecessary access to data. 

Questions leaders should be asking:

  1. Has your organisation’s access governance been reviewed recently? Do you operate a zerotrust architecture or multi-factor authentication? 
  2. Are you training your staff to recognise, report and defend against social engineering attacks? 
  3. Are you confident your organisation’s training is regularly refreshed with 
    up-to-date case studies and real-world examples of phishing, vishing 
    or other techniques?

Resources

For further information, refer to the following guidance:

Key cyber security terms and their definitions can be found in our glossary:

Top