RSS Amplifier

Morning Grok · Jul 21, 2026

How AI Changes Social Engineering and Customer Manipulation

0
Sign in to vote or save

Dave Daugherty · Morning Grok

In the last post, I discussed why synthetic identity is becoming harder for banks to detect—fraudsters are no longer just assembling fake identities from stolen data but creating complete, believable digital personas. This post turns to the human side of the same problem: how AI changes social engineering and customer manipulation.

Social engineering has always been part of banking fraud. A customer is tricked into sharing credentials. A call center representative is pressured into resetting access. A branch employee is persuaded to make an exception. A wire team receives a convincing email from what appears to be a trusted executive or vendor. What’s new is the speed, personalization, realism, and scale that AI brings to these attacks.

AI does not replace social engineering. It industrializes it.

Traditional social engineering required time, research, language skill, confidence, and repetition. A fraudster had to know enough about the target to sound credible, write a believable email, make a convincing phone call, and improvise when the victim asked questions. That limited the number of attacks a single person or group could execute.

AI changes that equation. A fraudster can now generate persuasive emails, text messages, scripts, fake customer-service interactions, synthetic voices, fake documents, and plausible backstories at very low cost.[1] The language can be cleaned up, the tone tailored, and the message adapted to the customer, the bank, the branch, the region, or the specific transaction. The old phishing email often looked suspicious because it was poorly written. The AI-generated version may be grammatically correct, emotionally calibrated, and contextually believable.[2]

The most important change is not that AI makes fraud messages more polished—it’s that AI makes manipulation personal.

A customer may receive a text message that references a recent transaction, a local branch, a familiar merchant, or a bank security alert. A small-business owner may receive an email that appears to come from a vendor, attorney, or payroll provider, with language matching the expected business context and timing around an invoice or wire deadline. A branch employee may receive a call that sounds like a frustrated customer, a senior banker, or a fraud analyst—the voice may be synthetic, the urgency manufactured.[3]

The fraudster’s goal is often not to defeat the bank’s technology directly but to persuade a human being to help defeat it.

Banking depends on trust bounded by process. Customers trust the bank. Employees trust internal systems. Branches trust call centers. Operations teams trust documents, workflows, and approvals. Social engineering attacks look for gaps in that trust structure, and AI compresses the trust window.

A customer may be manipulated while already logged into digital banking. A fraudster may be on the phone with the customer, guiding them through a transaction in real time. A fake bank alert may arrive at the exact moment the customer is worried about account security. A synthetic voice may tell a customer that funds must be moved immediately to a “safe” account.

In that moment, the customer may not think of himself as being defrauded. He may believe he is cooperating with the bank. AI-enabled customer manipulation is dangerous precisely because it does not always look like unauthorized access—sometimes it looks like an authorized customer making a bad decision under fraudulent influence.

From the bank’s perspective, that creates a difficult question: Was this a legitimate customer action, or was the customer being actively manipulated? That question cannot always be answered by authentication alone.

Banks have invested heavily in authentication, device intelligence, behavioral analytics, fraud scoring, transaction monitoring, and customer education. These controls remain necessary, but AI-enabled manipulation exposes a critical limitation: a customer can pass authentication and still be under attack. An employee can follow procedures and still be nudged into making the wrong exception. A transaction can originate from a known device and still be the result of live coercion. A voice can sound familiar and still be fake. A document can look professional and still be fabricated.

This is why banks need to think beyond identity verification as a one-time gate. The risk increasingly sits inside the session, inside the conversation, and inside the decision path. The bank must ask not only “Is this the customer?” but also: Is this behavior consistent with the customer’s normal intent? Is the transaction consistent with the surrounding context? Is there evidence of coaching, urgency, confusion, remote access, or abnormal sequencing? Is the employee being asked to override controls in a way that should trigger escalation? Is this exception becoming part of a broader pattern across branches, channels, or customer segments?

These are live-session governance questions.

For several years, bank security discussions have been dominated by digital channels—mobile banking, online account opening, account takeover, credential stuffing, payment fraud, and API risk. But AI brings the human channel back into the center of the security perimeter.

The contact center becomes a target because it is designed to help customers regain access, resolve exceptions, and move through friction. The branch becomes a target because it still carries human judgment, local relationships, customer trust, and the ability to handle unusual situations. Fraudsters understand this. They do not need to defeat every control—they need to find the point where human helpfulness, customer urgency, and operational complexity intersect.

That may be a call center representative trying to help an upset customer, a branch employee trying to serve someone who appears legitimate, an operations team processing an exception late in the day, or a customer who has been convinced that the bank’s normal warning signs are part of the emergency. AI makes these moments easier to manufacture and harder to recognize.

Banks should continue educating customers about how banks will not ask for passwords, one-time codes, remote access, or urgent transfers to “safe” accounts. Customers need to understand that a familiar voice or polished message is no longer proof of authenticity. But education has limits.

A frightened customer does not process risk the same way a calm customer does. A small-business owner under deadline pressure may respond quickly. An elderly customer may be more vulnerable to authority, urgency, or family-based manipulation.[4] A young customer may trust text messages, app prompts, or social media contacts more than traditional phone calls. A well-trained employee may still be placed under pressure by a convincing caller with just enough account information to sound legitimate.

Education matters, but it cannot carry the full burden. The bank needs controls that assume manipulation will occur.

AI also changes social engineering from a single-message problem into a coordinated campaign problem.[5] A customer may receive a text, followed by a phone call, followed by a spoofed email, followed by a fake support page. The same fabricated story continues across channels, nudging the customer step by step until the final transaction appears voluntary.

A business may be targeted through a vendor email, then an invoice change, then a phone confirmation, then a payment instruction—each step looking reasonable by itself. A branch may see several customers presenting similar stories in different locations. A contact center may receive repeated calls using different voices but similar escalation patterns. A fraud team may see a payment pattern but not the customer manipulation that preceded it.

The attack surface is no longer one message or one login. It is the sequence. That means banks need better ways to see patterns across channels, branches, sessions, exceptions, and customer behavior.

Bank boards and executive teams do not need to become AI engineers, but they do need to understand how AI changes the economics and mechanics of manipulation. The operational questions that matter include: Can we detect signs that a customer may be acting under coaching, coercion, or deception? Can our call center identify synthetic voice risk without creating unreasonable friction? Can branch employees escalate suspicious behavior without being punished for slowing down service? Can we see repeated exception patterns across locations and channels? Can we distinguish normal customer urgency from fraud-induced urgency? Can we preserve the audit trail around who made the decision, what signals were present, and why an exception was allowed? Can we learn from social-engineering attempts fast enough to adjust controls?

These questions go directly to how a bank will defend customers when the customer is technically authenticated but behaviorally compromised.

Historically, banks defended the perimeter: credentials, accounts, systems, networks, cards, checks, payments, and access rights. That perimeter still matters. But in the AI era, banks also have to defend the decision environment. They have to protect the customer’s ability to make a clean decision, protect employees from being manipulated into unsafe exceptions, and protect operational workflows from being bent by urgency, familiarity, synthetic trust, or fabricated context.

This is a harder problem than traditional fraud detection. It is not just about whether a transaction is unusual—it is about whether the transaction is being shaped by an adversary in real time.

AI changes social engineering by making it faster, cheaper, more believable, and more personalized. It allows fraudsters to imitate voices, write convincing messages, fabricate documents, tailor emotional pressure, and coordinate attacks across channels. For banks, the response cannot be limited to better warnings and stronger authentication. Those are necessary, but they are not enough.

The next layer of defense must operate inside live customer and employee workflows. It must recognize abnormal sequences, risky exceptions, manipulation signals, and cross-channel patterns. It must help people make better decisions before the loss occurs, not just reconstruct what happened afterward.

The central issue is no longer just whether the bank knows who the customer is. The harder question is whether the bank can tell when a real customer is being manipulated. That question will define a large part of bank security in the age of AI.

[1] Federal Trade Commission, “Scammers are using AI tools to sound just like your loved ones,” March 2023, https://consumer.ftc.gov/consumer-alerts/2023/03/scammers-use-ai-imitate-voices-loved-ones-heres-what-watch-out

[2] CISA, “Phishing Guidance: Stopping the Attack Cycle at Phase One,” https://www.cisa.gov/sites/default/files/publications/Phishing_Guidance-Stopping%20the%20Attack%20Cycle%20at%20Phase%20One.pdf

[3] FBI Internet Crime Complaint Center, “2023 Internet Crime Report,” noting increased use of AI-generated content in business email compromise and tech support scams, https://www.ic3.gov/Media/PDF/AnnualReport/2023_IC3Report.pdf

[4] FinCEN Advisory FIN-2022-A003, “Elder Financial Exploitation,” June 2022, https://www.fincen.gov/sites/default/files/advisory/2022-06-15/FinCEN%20Elder%20Financial%20Exploitation%20Advisory_FINAL_508.pdf

[5] ENISA Threat Landscape 2023, noting AI-enabled phishing and coordinated social engineering campaigns, https://www.enisa.europa.eu/publications/enisa-threat-landscape-2023

No posts

Read the original on morninggrok.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.