Attackers have known for decades that it is faster to manipulate a human than to break a firewall. The psychological levers Robert Cialdini documented in 1984 are the same ones driving attacks today. What AI changed is how cheaply and convincingly those levers can now be pulled.
A finance worker at Arup in Hong Kong authorized transfers totaling $25.6 million after attending a video call where every other participant was an AI-generated deepfake of company executives. The employee saw familiar faces, heard familiar voices, and followed what appeared to be genuine instructions. The attack worked entirely through trust, authority, and the social pressure of a group setting, with no software vulnerability required. That case is not an outlier.
According to the Entrust 2026 Identity Fraud Report, deepfakes now account for one in five biometric fraud attempts, with instances of deepfaked selfies increasing 58% in 2025. The production cost of a convincing impersonation has fallen substantially. Understanding why these attacks work at the psychological level is now a prerequisite for defending against them.
Robert Cialdini identified six principles that govern human compliance: authority, urgency (scarcity), social proof, reciprocity, commitment and consistency, and liking. Many social engineering attacks use at least one of them.
According to RansomLeak’s April 2026 social engineering analysis, modern attacks typically stack two or three of these principles into a single pretext to compress the target’s decision window below the threshold for verification.
The principles have not changed because human psychology has not changed, but AI has altered the cost and credibility of delivering them.
People comply with perceived authority figures. Attackers have always impersonated executives, IT staff, regulators, and law enforcement. The tell used to be a slightly wrong email domain, an unusual writing style, or a request that felt off. AI can remove many of those tells.
Research systems have demonstrated high-quality personalized speech synthesis from as little as a three-second voice sample. Therefore, an attacker may contact a CFO using the CEO’s voice sample, a deepfake built from a LinkedIn profile image and wording adapted from the LinkedIn keynote. Scary, right?
Urgency overrides deliberate thinking. When someone believes they must act immediately or face serious consequences, the mental bandwidth available for skepticism narrows sharply. Attackers have always manufactured urgency: “your account will be suspended,” “the wire must go today,” “this needs to happen before the end of business.”
AI improved the targeting. Attackers now use OSINT (Open-Source Intelligence) from the victim’s own social media, company announcements, and public calendars to time their approach to real deadlines. A phishing message that arrives on the day a contract renewal is due, references the contract by name, and comes from an address that matches the counterparty is contextually precise, assembled from publicly available information.
People tend to look at the behavior of others to decide their own. The deepfake video call that convinced Arup’s finance worker succeeded partly because multiple familiar people were all apparently treating the request as normal. When everyone in the meeting appears to agree, the individual’s resistance drops.
Synthetic social proof scales easily. Attackers can fabricate reviews, coordinate deceptive endorsements, and create false testimonials. In a fraud context, this appears as apparent validation from multiple sources simultaneously, with colleagues, managers, and external parties all seeming to confirm the same request at once.
These three principles appear less often in high-value financial fraud targeting but dominate in phishing at scale and longer-horizon social engineering campaigns. Reciprocity: the attacker provides something of apparent value before making the request that carries the payload. Commitment: once someone has agreed to a small initial request, they are more likely to follow through on larger subsequent ones. Liking: people comply more readily with those they find familiar or relatable, which is why attackers invest in building rapport before they ask for anything.
AI-assisted spear phishing weaponizes liking specifically. A message that references a shared colleague, mentions a project the target is actually working on, and uses the tone and vocabulary of someone in the target’s network produces warmth and recognition. That warmth is the liking lever, and it now takes seconds to manufacture from a LinkedIn profile and a few scraped emails.
Security awareness training built over the past decade taught people to look for specific surface-level indicators: spelling errors, unusual sender addresses, generic greetings, requests for credentials via email, suspicious attachments. It’s important to note that those signals reflected the actual quality of attacks at the time.
As SecurityWeek’s Cyber Insights 2026 report notes, AI made attacks cheaper to run and harder to spot, without changing how they work psychologically. The grammar errors and generic phrasing that used to give phishing emails away are gone. A message generated by an AI with access to the target’s emails and LinkedIn profile reads as if it came from a real colleague. There is no obvious red flag to catch.
The same applies to voice. Telling employees to call and verify a suspicious request fails if the attacker can synthesize the voice on the channel they call. In a February 2023 test, Motherboard reporter Joseph Cox used an AI-generated clone of his voice to bypass Lloyds Bank’s Voice ID authentication and access his own account information. The signals security training designated as safe (a familiar voice, a face on video, a message with no errors) are no longer reliable proxies.
Worth keeping in perspective: most breaches still come down to weak identity verification, not AI doing something entirely new. AI makes the deception more convincing and easier to scale, but the gap it exploits is the same one it always was – human judgment under pressure, which is ultimately what defenders need to address.
ClickFix is a social engineering technique that tricks users into executing malicious commands on their own machines by disguising those commands as routine system fixes. The method skips exploits and vulnerabilities entirely. A fake attacker-controlled webpage styled as a CAPTCHA check, browser update notice, or meeting error instructs a visitor to open the Windows Run dialog or macOS Terminal, paste a command, and press Enter. JavaScript on the page has already copied the malicious command to the clipboard before the visitor sees any instructions.
The psychology here is habit exploitation. Users are conditioned to complete verification prompts, follow system instructions, and resolve error messages quickly so they can get back to work. ClickFix borrows that conditioned behavior and redirects it toward command execution.
According to Microsoft’s Security Blog analysis of ClickFix, campaigns have been targeting thousands of enterprise and end-user devices globally every day since early 2024. ESET documented a 517% increase in ClickFix detections compared with H2 2024, based on ESET telemetry covering December 2024 through May 2025. ClickFix accounted for nearly 8% of all attacks blocked by ESET during that period, making it the second most common attack vector after phishing. Nation-state groups have incorporated it into their operations. Since the victim executes the command voluntarily, believing they are resolving a technical problem, the attack can bypass controls focused on malicious files, exploits, or attachments.
A newer variant called CrashFix, identified by Huntress and Microsoft Defender Experts in January 2026, takes this a step further by deliberately crashing the victim’s browser first. When someone’s browser suddenly stops working, they want it fixed fast. That moment of frustration is exactly when the fake recovery prompt appears, and compliance goes up because the disruption feels real. The user follows the instructions, pastes the command, and the malware runs. The browser restores. The user gets back to work, unaware that anything happened.
The gap in most security awareness programs is that they teach pattern recognition for indicators that no longer reliably appear. Spelling errors, suspicious links, and unusual sender addresses are 2022-era signals. Training built around them creates a false sense of competence, leaving employees confident in identifying phishing while remaining vulnerable to fluent, personalized, and largely AI-generated attacks.
Effective defense addresses two things: the psychological layer and the procedural layer. Neither alone is sufficient.
The goal of awareness training should shift from “identify the phishing email” to “recognize when you are under emotional pressure and slow down.” The emotional signals of a social engineering attack (urgency, authority, fear, guilt about not helping a colleague) are more consistent across attack types than any surface-level indicator.
Practical training focuses on questions rather than checklists. When someone asks for something unusual, the trained response is:
Those questions hold up against deepfake calls, AI-generated emails, ClickFix prompts, and every other current attack vector. Scenario-based training that puts employees through realistic simulations, including voice and video impersonation scenarios, builds the kind of recognition that reading a policy document does not. The skill being trained is noticing emotional manipulation in real time and knowing what to do next.
Procedural safeguards are controls that remain effective even when the psychological layer fails, and it will fail, because attackers are specifically optimizing to make it fail. The most important control for financial fraud is second-channel verification: any instruction to transfer funds, change payment details, or authorize an unusual transaction must be confirmed through a separately established communication channel.
For instance,if the CFO sends a wire instruction by email, the verification call goes to a phone number already in your contact system. If the instruction arrives by phone, the verification goes by email to a known address. The channel used for verification must be independent of the channel used for the request.
This control is effective against the Arup-style deepfake call because the verification runs over a separately established channel that is harder for the attacker to control at the same time.
Social engineering psychology refers to the use of established principles of human influence (authority, urgency, social proof, reciprocity, commitment, and liking) to manipulate people into taking actions that compromise security. Attackers exploit predictable cognitive responses rather than technical vulnerabilities.
AI reduced the production cost of a convincing deception to near zero. Voice cloning, deepfake video, and AI-generated text have eliminated the surface-level indicators that security training taught people to recognize. The psychological mechanisms of the attacks have not changed. The quality and targeting precision of delivery have increased substantially.
ClickFix is a social engineering technique that tricks users into executing malicious commands by presenting those commands as routine system fixes, such as fake CAPTCHAs, browser errors, or update prompts. Because the users execute the command themselves, the attack bypasses automated controls that look for malicious files or exploits.
You shift the training objective from identifying surface-level indicators to recognizing emotional pressure. Teach employees to ask: is there pressure not to verify this through a separate channel? Am I being asked to act faster than the situation requires? Does this request bypass a normal process? Scenario-based training with realistic simulations produces better recognition than policy documents.
Second-channel verification means confirming any sensitive instruction through a communication channel that is independent of the channel used to deliver the instruction.
If a payment request arrives by email, the confirmation call goes to a number already in your contact system, not one provided in the email. Second-channel verification raises the cost of this attack substantially, because the attacker has to control two independent channels at once rather than one. It is not absolute: an attacker who has compromised the mailbox, the phone number or the contact record can still reach the second channel.
Publicly available information: LinkedIn profiles, company announcements, press releases, social media posts, and public calendars. An attacker can reconstruct a target’s role, current projects, colleagues, and upcoming deadlines from open sources before making contact. The more publicly available an organization’s employee activity is, the more material an attacker has to make a targeted pretext feel credible.
The attacks have not fundamentally changed. Urgency, authority, trust, and the fear of getting something wrong have always been the tools. What changed is that AI made them cheap to deploy at scale and hard to spot on the surface.
Training people to catch typos and suspicious links was never really teaching them to recognize manipulation. It was teaching them to recognize bad execution. The executions are now good, which means the training has to go deeper, toward the feeling of being pressured, the instinct to slow down, the habit of verifying through a channel the attacker does not control.
Get those things right alongside solid procedural controls, and the psychology of the attack stops being the easy win it currently is for most threat actors.