Skip to content

Mon - Fri: 10.00 - 5.00

[email protected]

Delana Technologies

Delana Technologies

Delana Technologies delivers expert cybersecurity, cloud, and AI-driven IT strategy solutions. Transform your enterprise securely and intelligently.

  • Home
  • Contact Us
  • About Us
  • Case Studies
  • Workflow Automation & Systems Integration
  • AI Consulting & Agentic AI Solutions
  • Home
  • Contact Us
  • About Us
  • Case Studies
  • Workflow Automation & Systems Integration
  • AI Consulting & Agentic AI Solutions

Mon - Fri: 10.00 - 5.00

[email protected]

Social Engineering Has Evolved — and It’s Outsmarting Tech Defenses

  1. Home   »  
  2. Social Engineering Has Evolved — and It’s Outsmarting Tech Defenses

Social Engineering Has Evolved — and It’s Outsmarting Tech Defenses

September 22, 2025September 22, 2026 admincybersecurity

Firewalls, MFA and zero trust architecture have made technical break-ins harder. Attackers have responded by going around the technology entirely. Instead of exploiting software, they exploit people and the business processes those people follow: a convincing voice on the phone, a trusted vendor with too much access, or a password-reset procedure designed for convenience.

The FBI has warned repeatedly through 2025 about exactly this shift. The implication for security leaders is that the perimeter now includes people and process, not just networks and devices. This article looks at the three main ways modern social engineering defeats technical defenses and how to design processes that hold up even when someone is fooled.

Tactic one: tricking employees with AI-grade deception

The classic phishing email with spelling mistakes is fading. Generative AI now produces fluent, personalized messages in any language, and voice cloning can imitate an executive from a few seconds of recorded speech. In May 2025 the FBI warned that criminals were using AI-generated voice messages and texts to impersonate senior US government officials in order to gain access to victims’ accounts. The best-known corporate case remains Arup, where an employee in Hong Kong transferred about $25 million in early 2024 after a video call in which the other participants were deepfakes.

Money is the usual goal. The FBI’s Internet Crime Complaint Center reported that business email compromise cost victims about $2.8 billion in 2024, making it one of the costliest categories of cybercrime it tracks. For more on the AI side of this trend, see AI-powered threats.

Tactic two: exploiting trusted third parties

Your security is only as strong as the weakest organization with access to your data or systems. Attackers target vendors, outsourced support teams and SaaS integrations because they are trusted by default.

In May 2025 Coinbase disclosed that criminals had bribed overseas customer-support contractors to hand over customer data, which was then used to impersonate Coinbase and trick customers into sending funds. The company estimated the cost at $180 million to $400 million. No firewall was bypassed; people with legitimate access were simply paid to misuse it. Similar risk comes from SaaS integrations that hold tokens into core systems, which we cover in SaaS supply chain and OAuth attacks.

Tactic three: abusing business processes

Help desks, customer service lines and finance teams are designed to be helpful and fast. Attackers exploit exactly that. They call in posing as a locked-out executive, a new employee or a supplier with updated bank details, and they use urgency and seniority to rush staff past verification steps. Groups such as Scattered Spider have used this approach to reset passwords and MFA at large enterprises; our article on Scattered Spider walks through a real intrusion.

The common thread in all three tactics is that each step looks legitimate in isolation. The only reliable defense is a process that requires independent verification before anything sensitive happens, regardless of how convincing the request is.

Building a people and process perimeter

Effective programs combine process design, technical support for that process, and training that reinforces it:

  1. Map your high-risk requests. List the actions an attacker would want to trigger: payments and bank detail changes, password and MFA resets, access grants, data exports and gift card purchases. Each needs a defined verification step.
  2. Verify out of band. Confirm requests through a separate, pre-registered channel, such as a callback to a number already on file, never through contact details supplied in the request. For resets, use video verification against an ID on file or manager approval.
  3. Require two people for money movement. Dual approval for payments above a threshold and for any change to supplier bank details stops most business email compromise.
  4. Vet and monitor third parties. Include security requirements in contracts, limit vendor and contractor access to what their role requires, log their activity, and watch for unusual data access by support staff.
  5. Monitor SaaS behavior. Alert on new mailbox forwarding rules, unusual OAuth app consents, mass downloads and sign-ins from new devices after a reset.
  6. Train on scenarios, not slides. Run realistic simulations, including voice calls to the help desk and finance team, and reward staff who follow procedure and report attempts, even when the request turns out to be genuine.

The trade-off is friction. Callbacks slow payments and stricter help-desk checks frustrate executives. The key is leadership support: when the CEO publicly backs staff who delay a request to verify it, employees follow the process under pressure. Our cybersecurity and compliance services include human risk assessments and process design.

Measuring whether the human layer is working

Traditional awareness programs report completion rates, which say almost nothing about risk. Human risk management measures behavior instead. Useful indicators include the percentage of simulated phishing messages that staff report, and how quickly; the share of help-desk resets that followed the full verification script when tested by a mystery caller; the number of payment changes verified by callback; and how many third parties have a named owner and a current access review.

Look for patterns rather than blaming individuals. If one team consistently skips verification, the process may be too slow for their workload, and the fix is often better tooling, such as a one-click callback workflow or a verification app, rather than more training. Share results with leadership each quarter alongside technical metrics, so the board sees people and process as part of the security program rather than a separate human resources issue. Over time, reporting rates should rise and successful simulations should fall; if they do not, change the approach.

Frequently asked questions

Is security awareness training still worth it?

Yes, but its purpose has changed. Rather than teaching people to spot bad grammar, training should teach them the verification procedures and make following them automatic, especially under pressure.

How do we protect against deepfake calls from executives?

Treat the request, not the voice, as the thing to verify. Any unusual request for money, access or data triggers a callback through a known number or a second approver, no matter who appears to be asking.

What should we ask vendors about social engineering?

Ask how their help desk verifies identity, how they vet and monitor staff with access to your data, how quickly they will notify you of an incident, and whether they support phishing-resistant MFA for accounts that access your systems.

Strengthening the human layer

Delana Technologies helps organizations design verification procedures, assess third-party risk and run realistic social-engineering exercises. To review your people and process defenses, call 239.414.5126 or contact us.


Sources: FBI public service announcement on impersonation of senior US officials (May 2025); FBI Internet Crime Complaint Center, 2024 Internet Crime Report; Coinbase SEC Form 8-K and blog disclosure (May 2025); CNN reporting on the Arup deepfake fraud (May 2024); CISA and FBI advisory on Scattered Spider.

Post navigation

Previous: Critical Zero-Days: Legacy Software & Widely-Used Platforms Under Siege
Next: The Rise of AI Video Generators, Autonomous Agents, and Other Trending Innovations

Florida Service Location

  • Cybersecurity, AI Consulting & IT Services in West Palm Beach, Florida
  • Cybersecurity, AI Consulting & IT Services in Sarasota, Florida
  • Cybersecurity, AI Consulting & IT Services in Port St. Lucie, Florida
  • Cybersecurity, AI Consulting & IT Services in Pembroke Pines, Florida
  • Cybersecurity, AI Consulting & IT Services in Naples, Florida
  • Cybersecurity, AI Consulting & IT Services in Miramar, Florida
  • Cybersecurity, AI Consulting & IT Services in Miami, Florida
  • Cybersecurity, AI Consulting & IT Services in Hollywood, Florida
  • Cybersecurity, AI Consulting & IT Services in Hialeah, Florida
  • Cybersecurity, AI Consulting & IT Services in Fort Myers, Florida
  • Cybersecurity, AI Consulting & IT Services in Fort Lauderdale, Florida
  • Cybersecurity, AI Consulting & IT Services in Cape Coral, Florida
  • Cybersecurity, AI Consulting & IT Services in Boca Raton, Florida
  • Cybersecurity, AI Consulting & IT Services in Coral Springs, Florida

Technology Services

  • Cybersecurity Compliance & Regulatory Framework Services
  • Workflow Automation & Systems Integration
  • Cloud Modernization & Technology Innovation Services
  • Fractional CTO & Expert Technical Consultants
  • Data Analytics, BI & Modern Data Platforms
  • Cyber Litigation Support & Digital Forensics
  • Cybersecurity Solutions & Zero Trust Architecture
  • AI Consulting & Agentic AI Solutions
  • Case Studies
  • Home
  • Contact Us
  • Privacy Policy
  • Cybersecurity Compliance & Regulatory Framework Services
  • Workflow Automation & Systems Integration
  • Cloud Modernization & Technology Innovation Services
  • Fractional CTO & Expert Technical Consultants
  • Data Analytics, BI & Modern Data Platforms
  • Cyber Litigation Support & Digital Forensics
  • Cybersecurity Solutions & Zero Trust Architecture
  • AI Consulting & Agentic AI Solutions

© Copyright 2025 Delana Technologies LLC