Defending against AI-fueled social engineering AI is sharpening social engineering attacks, with 86% of phishing attacks analyzed in 2026 being AI-driven and people up to 40% more likely to fall for text or phone scams than email, according to Verizon's 2026 Data Breach Investigations Report. The article argues that legacy detection methods are outdated and recommends behavioral analytics, agentic investigation, and transparent AI to defend against these evolving threats. Defending against AI-fueled social engineering Social engineering has always been the softest edge of enterprise defense, and AI is sharpening adversaries’ attacks. Phishing, business email compromise, and impersonation still dominate the initial-access playbook, but AI has stripped out the cost, time, and skill barriers that once forced attackers to choose between reach and precision. Today, a single operator with a handful of prompts can run spear phishing campaigns at the scale of commodity spam but with an unsettling level of personalization. The attack types AI is accelerating Three attack techniques stand out for how AI-fueled adversaries have evolved. Spear phishing at scale: Attackers no longer trade sophistication for volume. An AI-equipped operator can pull together an org chart, helpdesk staffing, public code repositories, and employee social footprints and then generate personalized messages to hundreds of targets at once. As much as 86% of the phishing attacks analyzed in 2026 were AI-driven.1 Smishing: SMS phishing catches victims through an unassuming format. Text messages lack the authentication infrastructure email has, so there are fewer built-in signals warning recipients that something's off. Verizon's 2026 Data Breach Investigations Report shows people are up to 40% more likely to fall for social engineering carried out by text or phone than by email.2 Deepfakes: Creating a convincing fake once required advanced editing skills. Now, it takes only a few seconds of audio or video. Deepfakes tend to appear at the final step right when a suspicious employee reaches out to verify a payment request and gets a familiar voice on the other end. The common thread? Identity, not malware, is where most of these attacks actually land. A fake helpdesk request built from real internal knowledge is tough to flag, even for trained experts. Why legacy detection can't keep up Legacy detection made one big assumption: that adversary output was limited by human effort. Signature-based email filters, rule-based fraud engines, and static awareness training all count on attacker patterns changing slowly enough for defenders to catch up. AI broke that assumption. When attackers regenerate lures, domains, and payloads at machine speed, matching known artifacts is a losing game. Defenders need detection that reasons over behavior, not one that waits for a pattern it has seen before. It's a hard pivot for teams built around signatures and playbooks, but this is also where the opportunity lives. Rebuilding defense to adapt Stopping AI-fueled social engineering isn't a single-product problem. It's an operating-model shift, and a few capabilities make it possible: Behavioral analytics grounded in unified telemetry: When identity events, endpoint activity, email signals, and cloud sign-ins live in one data model, the platform can spot a legitimate-looking login followed by an unusual OAuth consent grant, which is a known early indicator of compromise. Agentic investigation and response: Instead of drowning analysts in hundreds of loosely related alerts, generative AI correlates signals into prioritized attack narratives. With this AI assistance, analysts are able to elevate their role by reading the summarized case, verifying the reasoning, and approving the response. Transparent, model-agnostic AI: When AI makes judgment calls on identity-based attacks, your team should be able to see the prompts and reasoning behind every decision. If you can't audit it, you can't defend it. Put these together, and your team stops chasing individual phishing incidents and starts disrupting the campaigns behind them. Defense against AI threats The economics of social engineering have flipped. Reconnaissance, personalization, and impersonation are now cheap, fast, and available to any adversary. The defenses built for a slower era are in desperate need of an update. Check out our guide on defending against AI-fueled social engineering https://www.elastic.co/resources/article/defending-against-ai-fueled-social-engineering for the complete breakdown of detection priorities security teams should act on now and how to defend effectively against AI-powered social engineering attacks. Sources: 1BusinessWire, "KnowBe4 Research Finds 86% of Phishing Attacks are AI Driven," April 2026. 2Verizon, "2026 Data Breach Investigations Report," 2026. The release and timing of any features or functionality described in this post remain at Elastic's sole discretion. Any features or functionality not currently available may not be delivered on time or at all. In this blog post, we may have used or referred to third party generative AI tools, which are owned and operated by their respective owners. Elastic does not have any control over the third party tools and we have no responsibility or liability for their content, operation or use, nor for any loss or damage that may arise from your use of such tools. Please exercise caution when using AI tools with personal, sensitive or confidential information. Any data you submit may be used for AI training or other purposes. There is no guarantee that information you provide will be kept secure or confidential. You should familiarize yourself with the privacy practices and terms of use of any generative AI tools prior to use. Elastic, Elasticsearch, and associated marks are trademarks, logos or registered trademarks of elasticsearch B.V. in the United States and other countries. All other company and product names are trademarks, logos or registered trademarks of their respective owners.