AI Tech Emerges to Combat Live Social Engineering and Deepfake Attacks
Share
The increasing sophistication of social engineering and the rise of AI-powered deepfakes are prompting a shift from traditional security awareness training towards real-time technological detection in live conversations. While companies invest heavily in user training, empirical evidence suggests it often fails to protect against psychological manipulation, making human defenders unreliable against advanced trickery.
Social engineering remains a highly successful attack vector, frequently bypassing system vulnerabilities and multi-factor authentication (MFA) thresholds through human interaction. Recent high-profile incidents demonstrate this persistent challenge.
In 2023, the Las Vegas casino breaches, affecting MGM Resorts and Caesars Entertainment, involved attackers using vishing—voice phishing—to trick help desk staff into resetting passwords and bypassing MFA. MGM Resorts reportedly faced an estimated $100 million in lost revenue and remediation costs, while Caesars Entertainment is believed to have paid a $15 million ransom.
More recently, the Brinks Home leak in August 2026 saw the ShinyHunters group, linked to the Scattered Spider threat actor, leverage voice phishing to gain access through the enterprise help desk. An attacker simply talked an employee through a Microsoft Entra authentication step, leading to the public release of almost five million customer records and 41 gigabytes of corporate data.
These incidents highlight the urgent need for automated detection mechanisms. Technology is now stepping in to identify both conventional social engineering tactics and newer threats involving AI deep fakery.
Real-Time Detection Technologies
One emerging solution comes from Netarx, which employs a proprietary “AI defense meta harness.” This system continuously scans all communications in progress, correlating individual signals from over 40 AI models. It analyses more than 1,000 digital and metadata signals for each interaction to detect anomalies undetectable by the human ear or eye.
For instance, Netarx scrutinises device fingerprints, EXIF data, compression signatures, and location mismatches to verify the physical device’s authenticity. For AI-generated voice communications, it examines micro-artefacts like unnatural background silencing and electronic compression anomalies. If video is present, the system matches physical lip movements directly against incoming voice signals and inspects individual frames for micro-expression anomalies, unnatural blinking frequencies, lighting inconsistencies, or facial warping.
No single signal is definitive, but the aggregation and recognition of multiple questionable indicators can flag potential fraud in real-time. Netarx also addresses the challenge of effectively relaying detection to users. Instead of automatically blocking potentially dangerous situations, which can cause disruption, the company developed a colour-coded on-screen indicator displayed during the communication.
A green indicator confirms verified human identity and device. Amber indicates an unknown source or suspicious metadata anomalies. Red signifies that synthetic media or an active deepfake has been identified. This system, which Netarx internally calls “flurp,” empowers users to disengage from a conversation if an amber warning escalates to red, rather than the system arbitrarily terminating the process. The Netarx Identity Key (NIK) runs across Windows, macOS, Chrome, iOS, and Android. The company also maintains the Impact Database, cataloguing real-world security incidents where human deception was central to the attack.
As social engineering continues to grow as a severe threat to enterprise security, bypassing entire security stacks when privileged employees are manipulated, technological solutions are becoming essential to augment—and in some cases, supplant—human detection capabilities.




Leave a Reply