Social Engineering Detection Moves Into the Live Conversation
New AI-powered technology aims to detect social engineering in live conversations.
Summary
Traditional security awareness training has proven ineffective against social engineering attacks, which continue to succeed using sophisticated methods like AI deepfakes and vishing. Recent breaches at MGM Resorts and Caesars Entertainment highlight the significant financial and data loss from such attacks. Netarx has developed an AI-driven solution that analyzes communication signals in real-time to detect both traditional and AI-generated social engineering attempts, providing users with a color-coded indicator of potential threats.
Full text
Companies are pouring time and dollars into security awareness training, but there is little empirical evidence to suggest it actually works against social engineering. Social engineering remains a primary and successful attack vector. While system vulnerabilities can be patched, social engineering cannot. The most common pseudo ‘patch’ is user awareness training, but this has failed to block the vector. Human defenders should not and cannot be expected to detect trickery designed to manipulate their psychology. And the tricks are becoming better hidden and more sophisticated with the use of AI deep fakery. Successful examples of social engineering include: The Las Vegas casino breaches of 2023, via vishing. Scattered Spider attackers, posing as employees, tricked the casino’s help desk staff to reset passwords and bypass MFA. MGM Resorts was forced to shut down digital operations for ten days at an estimated cost of $100 million in lost revenue and remediation costs. Caesars Entertainment is thought to have paid a $15 million ransom after the attackers demanded $30 million. More recently, the Brinks Home leak disclosed in August 2026 also involved voice phishing and the enterprise help desk. This time the attacker was ShinyHunters, although the group has a known relationship with Scattered Spider. Here the attacker simply talked a help desk employee through completing a Microsoft Entra authentication step, granting the hacker immediate access. Almost five million customer records and 41 gigabytes of corporate data were subsequently published on a public hacking forum. If human detection of social engineering cannot be assured, other means of detection must be employed – and technology is the pre-eminent option. The use of technology to detect both traditional and newer AI deep faked social engineering is increasing and improving. One example comes from Netarx.Advertisement. Scroll to continue reading. The firm’s solution applies a proprietary orchestration layer which it describes as an AI defense meta harness. The harness correlates individual signals detected by more than 40 AI models continuously scanning all communications while they are in progress, analyzing more than 1,000 digital and metadata signals for each interaction. For example, to ensure the physical device delivering a feed belongs to its authorized user, Netarx analyzes device fingerprints, EXIF data, compression signatures, and location mismatches. For AI-generated voice communications from GANs or voice cloners it examines the micro-artifacts undetectable by the human ear, such as unnatural background silencing and electronic compression anomalies. If video is also included, it matches physical lip movements directly against incoming voice signals. For the facial image, it inspects individual video frames for anomalies in micro-expressions, unnatural blinking frequencies, lighting inconsistencies, or warping around hair lines. No single signal is decisive in indicating fraud. However, the collection and recognition of multiple questionable signals can swing the needle between genuine and fake in real time. However, detecting fraud in progress is only half the problem – the detection must also be relayed to the user in an understandable manner, also in real time. The traditional approach, autonomously blocking dangerous situations, is extreme and can cause more problems than it solves. To avoid this, Netarx has developed a color-coded real-time traffic analysis indicator displayed on screen during the communication. Green indicates that the human identity and the device concerned have been verified. Amber declares that the source is unknown, or that suspicious metadata anomalies have been detected. Red indicates that synthetic media or an active deepfake has been identified. (Internally, the company uses the term ‘flurp’ for this traffic light system. Flurp is defined in the Urban Dictionary as the noise a snail makes.) If amber turns to red during the conversation, it is probably time to disengage; but this is the user blocking the sender rather than the system arbitrarily blocking the process. NIK (the Netarx Identity Key) runs on Windows, macOS, Chrome, iOS and Android; and the company also publishes a database (the Impact Database) that catalogs real-world security incidents where human deception played a decisive role in the attack. This Netarx social engineering solution is an early example of technology supplanting human detection. It will not be the last, because social engineering is a growing vector and a serious threat to enterprise security. The entire security stack is bypassed if a single privileged employee invites a social engineering attacker across the MFA threshold. Related: ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing Related: UNC6692 Uses Email Bombing, Social Engineering to Deploy ‘Snow’ Malware Related: Cyber Insights 2026: Social Engineering Related: Going Into the Deep End: Social Engineering and the AI Flood Written By Kevin Townsend Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Kevin Townsend doxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet MisadventuresmacOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD BackdoorZero Trust Creator Says Model Holds Firm Against AI-Assisted AttacksEnterprises Struggle to Prepare for AI and Quantum Threats, PwC SaysHacker Conversations: Rob Juncker, a Knock at the Door and a Moral CompassDARPA Selects Xint to Use AI in Securing Military Messaging AppsRig Security Emerges From Stealth With $12M to Tackle Agentic AI Identity RisksModulate Raises $25 Million to Advance Deepfake Detection Latest News 8.8 Million Impacted by Data Breach at Denmark’s Central Person RegisterGoogle Narrows Open Source Bug Bounty Amid Wave of Invalid Automated ReportsLinux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare FirmsExploitation Hits Rejetto HFS Vulnerability Discovered by AI Senate Passes Bipartisan Bill to Strengthen Healthcare CybersecurityAlleged ShinyHunters Leader Arrested in JordanExploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the MoveChip Wentz has been appointed as SVP & CISO at Keurig Dr Pepper Inc.Lumen Technologies has named Kim Keever as CSO.Quantum Secure Encryption Corp. has appointed Joseph Hall as CIO.More People On The MoveExpert Insights AI Has Changed Attack Speed, Not Security Fundamentals As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals. (Joshua Goldfarb) Four Cyber Threats Harboring Big Plans for the Future - AI, supply-chain exposure, quantum computing and geopolit
Indicators of Compromise
- malware — ShinyHunters