September 21, 2026
How to help employees spot a social engineering attack before it’s too late
An employee’s phone rings. The caller says they’re from IT. They know the employee’s name, where they work, and enough about their role to sound legitimate. There’s a problem with their account, and they need them to approve an authentication request.
Would your employees know whether they were talking to a colleague or an attacker?
Social engineering has long relied on manipulating people rather than exploiting technology. What’s changing is how convincing those attacks can be. AI is helping attackers create more credible messages and impersonations, while information available online or through compromised data can give them the context they need to sound legitimate.
Recent incidents show the scale of this problem. Healthcare organizations have warned patients about phishing campaigns impersonating MyChart, while the ShinyHunters group claimed voice phishing was used to compromise employee single sign-on accounts in an incident involving McKesson.
Impersonating trusted identities is becoming much easier and more convincing, giving attackers another way around security controls. Instead of breaking in, they can manipulate an employee, service desk worker, contractor, or other trusted user into letting them in.
IT and security leaders need to help users recognize suspicious interactions, while putting controls in place that prevent a successful deception from becoming a major security incident.
What is a social engineering attack?
A social engineering attack manipulates someone into revealing information or taking an action that benefits an attacker. That might mean clicking a malicious link, sharing credentials, approving an authentication request, resetting an account, or granting access.
Attackers often manufacture urgency or impersonate someone the target trusts. In mission-critical environments, where employees routinely make time-sensitive decisions and need rapid access to critical systems, those tactics can be particularly effective.
AI makes these attacks easier to create, personalize, and scale. AI-powered phishing, deepfakes, and attacks targeting identity recovery processes are among the emerging identity-based threats organizations need to prepare for.
What are the most common types of social engineering attacks?
Social engineering can take several forms. Security awareness programs should prepare employees to recognize all of them.
Phishing uses fraudulent emails or websites to trick someone into disclosing information or taking an unsafe action. Spear phishing targets a specific individual, often using information about their job, colleagues, or organization to make the message credible.
Smishing uses similar tactics through text messages, while vishing, or voice phishing, uses phone calls or other voice communications.
Attackers can also impersonate trusted brands, employees, executives, vendors, or IT staff. Service desks and account recovery processes are attractive targets because attackers may try to persuade employees to reset credentials or authentication methods on their behalf.
How is AI making social engineering harder to detect?
Some of the clues employees have traditionally used to identify fraud are becoming less reliable. AI can generate polished, contextual messages, while publicly available or compromised information can give attackers the details they need to create a believable story.
Vishing, or voice phishing, is a key example. AI-powered voice technologies are making impersonation more convincing and scalable. A caller posing as IT, a colleague, or a vendor may already know an employee’s name, role, manager, or other details, then use that familiarity to request credentials, MFA approvals, account changes, or access.
Security awareness training needs to evolve with these tactics. Employees should be taught that familiarity isn’t proof of identity and to focus on the behavior behind a request. Unexpected urgency, attempts to bypass established processes, requests for sensitive information, or authentication actions they didn’t initiate should all warrant additional scrutiny and independent verification.
What warning signs should organizations teach employees to recognize?
There may not be one obvious clue, so employees should be trained to recognize combinations of suspicious behaviors.
Unexpected urgency, pressure to bypass normal procedures, or requests for passwords, authentication codes, account resets, or changes to authentication methods should warrant scrutiny. Employees should also never approve an MFA request they didn’t initiate.
Resistance to independent verification is another warning sign. Someone may sound credible, but legitimate users should still be able to follow established identity verification processes. Regular training, realistic simulations, and clear escalation procedures can reinforce these behaviors and ensure employees know how to respond when something seems suspicious.
What should employees do if they suspect a social engineering attack?
Organizations should give employees a simple, repeatable response: stop, verify, and report.
Employees should:
- Stop the interaction before providing information or taking the requested action.
- Verify the person or organization reaching out using a known internal channel or trusted source.
- Report the attempt to the appropriate team or contact.
Making these procedures easy to follow matters. In high-pressure environments, complicated security processes can make it harder for employees to respond consistently.
How can organizations reduce the risk of social engineering attacks?
Training is important, but organizations shouldn’t depend on every employee recognizing every sophisticated attack. A layered approach combines user education with identity and access controls designed to make successful impersonation harder to translate into unauthorized access.
Phishing-resistant MFA and passwordless authentication reduce exposure to credentials that attackers can steal or persuade someone to disclose. Strong identity verification protects high-risk workflows such as help desk authentication and password resets. Risk-based authentication adds scrutiny when risk is elevated, while least-privilege access controls limit what a compromised identity can do.
Organizations should also examine potential weaknesses across the identity lifecycle, including how users are verified, accounts are recovered, authentication methods are changed, privileged and third-party access is secured, and how access activity is monitored for risky behavior.
The goal is defense in depth. Employees should have the knowledge and processes to recognize and report suspicious interactions, while technical controls provide additional protection when human judgment falls short.
Learn how to prepare for the next generation of identity-based threats.