AI-powered social engineering is the use of generative AI, cloned voices, and deepfake videos to impersonate real employees and manipulate staff into approving payments or sharing confidential information. While enterprise teams have spent the last decade training staff to spot fraud attempts through signs like poor grammar and mismatched sender addresses, those heuristics no longer apply.
For instance, a finance employee at an engineering firm ‘Arup’ authorized transfers worth $25.6 million after a video call in which every other participant was an AI-generated deepfake of a colleague. Cases like this are a mark of emerging cybersecurity threats built to defeat human judgment.
Phishing used to be identifiable by odd phrasing and generic greetings. Large language models now write in the exact tone of an internal memo, referencing project names and reporting lines pulled from LinkedIn and public filings.
The European Union Agency for Cybersecurity reported that AI-supported phishing made up over 80% of observed social engineering activity worldwide in early 2025.
Indonesia illustrates the scale of this shift. The National Cyber and Crypto Agency recorded approximately 5.5 billion cyberattacks in 2025, a significant increase compared with the previous four-year average, with many incidents characterized as behaviour-based and increasingly powered by AI.
Today, cyber threats in Indonesia extend across government portals, banking applications, and healthcare platforms – each creating new opportunities for impersonation, identity exploitation, and digital fraud.
Attackers feed AI models an employee’s public posts, press mentions, and writing samples to produce messages tuned to that person’s role and vocabulary. Detection tools trained on spelling errors and generic templates rarely flag these emails.
A few seconds of audio from a conference recording is enough to clone an executive’s voice. Switzerland’s national cyber authority recorded a rise in CEO fraud cases from 719 to 971 in a single year, with attackers increasingly using deepfake audio in live scam calls.
Security firm KnowBe4 disclosed that it unknowingly hired a North Korean IT operator who used a stolen identity and AI-altered interview footage to pass video interviews and background checks.
Modern attacks span messaging apps, video calls, and email in a single operation, building false trust before requesting a transfer or credentials.
Most security awareness modules still teach employees to check for spelling mistakes and odd domains. Those cues have largely disappeared from AI-generated attacks, leaving staff without the pattern recognition they were trained to rely on for years.
MFA stops many automated credential attacks, but it does little against a live deepfake video call or a cloned voice instructing someone to approve a payment. The manipulation happens after authentication, and no additional factor stops a person from acting on it.
Email filters and endpoint tools scan for malicious links and attachments. A request from an impersonated CFO to expedite a wire transfer contains neither, which is why effective cyber security now depends as much on verification habits as it does on software.
When Ferrari and advertising group WPP both faced attempted deepfake calls impersonating their chief executives, staff broke the attack by verifying the request through a separate, pre-agreed channel rather than trusting the call itself.
Security teams can watch for patterns such as:
Running simulated deepfake calls and cloned-voice tests against finance and IT help staff expose gaps that standard phishing simulations miss.
As enterprises adopt AI agents for internal workflows, clear rules on what those agents can approve without human sign-off close a growing avenue for these emerging cybersecurity threats.
Security leaders can apply the following controls immediately, without waiting on new tooling or budget approval.
Require a callback to a verified phone number before resetting credentials or restoring account access for anyone claiming urgency – regardless of their title, authority, or apparent familiarity.
Implement a mandatory second approval, conducted through an independent channel, for any new payee setup or changes to payment instructions above a predefined threshold.
Executives should be mindful of the amount of unscripted video and audio content they make publicly available, as attackers can use these materials to create increasingly convincing voice and video clones.
Additionally, participating in a cybersecurity conference with peers navigating similar threats in Indonesia can help leadership teams exchange lessons and identify verification measures that are effective in real-world scenarios.
For leadership teams navigating these risks, IndoSec serves as a crucial platform for knowledge exchange and strategic collaboration. Taking place on 15–16 September at The Ritz-Carlton Jakarta, Pacific Place, IndoSec brings together more than 2,000 cybersecurity professionals, CISOs, and officials from the National Cyber and Crypto Agency and the Ministry of Communications and Digital Affairs.
Discussions on identity, access management, fraud prevention, and other governance priorities will help organizations strengthen verification processes and prepare for increasingly sophisticated impersonation attempts. With sessions spanning zero trust adoption, cloud security, and digital forensics, the agenda is built for organizations still working out where these controls fit into daily operations.
Don’t miss out. Register today!
What makes AI-powered social engineering different from traditional phishing?
It removes grammar errors and generic templates, replacing them with cloned voices, deepfake videos, and messages that match an employee’s tone.
Can multi-factor authentication stop deepfake fraud?
No, MFA only secures login. A cloned voice or deepfake video call manipulates a person after authentication.
How common are deepfake attacks on businesses?
Gartner surveyed 302 organizations and found that 62% had experienced a deepfake-related social engineering attack in the prior 12 months.
What is out-of-band verification?
It means confirming an unusual or urgent request through a separate, pre-agreed channel rather than trusting the original message received.
Why should security leaders attend IndoSec 2026?
It offers direct access to case studies, regulators, and CISO peers building verification practices against the same emerging fraud patterns.