Join our Newsletter — 33% off our NHI Course

What are the signs that an AI impersonation campaign is targeting your organisation?

Common signs include requests sent through unfamiliar channels, urgency tied to sensitive access, inconsistencies in tone or language, and messages that rely on insider jargon, logos, or naming conventions. Multiple contact attempts aimed at the same role, especially via voice and SMS, are also a warning sign. Teams should verify any request that appears unusual before acting on it.

How AI Impersonation Campaigns Usually Show Up Before a Compromise

AI impersonation campaigns tend to reveal themselves through pattern, not perfection. The first warning is often a request that looks operationally plausible but arrives in an unusual channel, at an unusual time, or with a level of urgency that does not fit the role involved. Attackers use generated text, synthetic voice, and copied branding to reduce the friction that normally exposes social engineering. For that reason, the meaningful signal is often the mismatch between the request and the normal business process, not a single obvious spelling mistake or awkward sentence.

The operational risk is that teams over-trust surface realism and under-check context. A convincing voice note, a polished email, or a chat message that references internal jargon can still be part of a broader impersonation sequence designed to push a hurried approval, an urgent payment, or a credential reset. Guidance from NIST SP 800-53 Rev 5 Security and Privacy Controls is useful here because the core issue is not the message format itself, but whether the organisation has controls that force verification before action. In practice, many security teams recognise the campaign only after one channel has already been validated by another channel that was equally compromised.

What to Look For Across Voice, Email, Chat, and SMS

AI impersonation becomes easier to spot when you compare the request against the organisation’s normal communication paths, approval logic, and escalation habits. A single message may not be enough to confirm abuse, but repeated contact attempts, copied executive phrasing, and pressure to bypass normal checks are strong indicators. The same is true when a requester knows enough internal detail to sound credible but gets process details slightly wrong, such as naming the wrong approver, asking for an unusual exception, or pushing a task that would normally require written confirmation.

  • Requests that start in one channel and quickly move to another, especially when the sender discourages call-backs or ticket-based verification.
  • Urgency that is tied to access, payments, identity changes, or confidential data, rather than to a routine business deadline.
  • Voice or video messages that sound consistent at the surface but do not behave like the real person when questioned.
  • Messages that borrow logos, signatures, naming conventions, or insider terms without following the organisation’s usual workflow.
  • Multiple contact attempts aimed at the same role, which is a common pressure tactic when the first attempt does not succeed.

The practical test is whether the request can survive independent verification through a trusted path that the sender did not initiate. If it cannot, the campaign is already showing its hand. This is where teams often need to slow down and treat convenience as a risk factor, because the whole purpose of impersonation is to make a high-friction decision feel routine.

Where this guidance breaks down is in environments that have no stable baseline for who is allowed to ask for what, because without that baseline even a realistic impersonation can look normal.

When a Suspicious Request Is Just Poor Process and When It Is Active Deception

Tighter verification often increases response time, so organisations have to balance speed against trust. Not every odd message is malicious, and not every awkward phrasing choice proves AI involvement. Guidance-vs-consensus matters here: there is broad agreement that the safest approach is to validate unusual requests, but there is less consensus on which surface cues are most reliable because generated content can imitate many of them.

The useful distinction is between accidental process noise and coordinated pressure. A routine internal mistake usually produces one-off confusion, while impersonation campaigns often combine several signals at once: unusual channel, urgency, authority cues, and a demand that bypasses normal review. That combination matters more than whether the language is flawless. Organisations should also be cautious about assuming that familiarity equals authenticity, because AI can reproduce the style of a known leader, supplier, or employee well enough to defeat casual inspection.

In practice, the edge case is a legitimate urgent request that still fails the verification test. That should not be dismissed, but it should be paused until the request is confirmed through a trusted method already known to the organisation. The safest response is to treat the unusual request as untrusted until the requester proves their identity through a path that is independent of the suspicious message itself.

Risk and Threat Considerations

AI impersonation campaigns are dangerous because they compress the time available for human judgment while increasing the apparent credibility of social engineering. The main risk is not just false messaging, but unauthorised access, fraudulent approval, or disclosure triggered by a believable request that exploits role-based trust and weak verification habits.

Failure mechanism: The attacker uses synthetic text, voice, or imagery to mimic a trusted person, then relies on urgency, channel shifting, and process bypass to defeat informal checks. If the organisation lacks a hard out-of-band verification step, the impersonation can succeed even when individual staff members are cautious.

Impact: The result can be credential compromise, payment diversion, sensitive data exposure, or the creation of a false operational decision that is hard to unwind once other teams have acted on it.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATLAS and MITRE ATT&CK address the attack surface, NIST CSF 2.0 and CIS Controls v8 set the technical controls, and ISO/IEC 42001:2023 define the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 PR.AA-01 — Identity Management, Authentication, and Access Control Impersonation targets trust and access decisions.
Recommendation — Require verified identity before approving sensitive requests.
CIS Controls v8 6 — Access Control Management Stops false requests from becoming unauthorized access.
Recommendation — Enforce approval checks before changing privileged access.
MITRE ATLAS AML.T0051 — Impersonation Covers AI-driven impersonation used to mislead targets.
Recommendation — Map impersonation indicators to ATLAS and hunt for coordinated deception.
MITRE ATT&CK T1566 — Phishing AI impersonation often delivers phishing through social engineering.
Recommendation — Treat suspicious outreach as phishing and validate the delivery path.
ISO/IEC 42001:2023 A.6 — AI system lifecycle Supports governance for AI-related misuse and deceptive outputs.
Recommendation — Govern AI misuse risks through lifecycle controls and oversight.

Practitioner Guidance

What to prioritise: Put verification friction around the actions impersonators most want, especially payments, access resets, supplier changes, and executive approvals. If those actions can happen through a single message thread, the control is too weak for an AI-assisted campaign.

What to verify: Confirm that staff know the approved callback, ticketing, or approval route and that they will use it even when the message sounds legitimate. The key test is not whether the content seems convincing, but whether the request survives a second path that the sender does not control.

Practitioner takeaway: The strongest defence is not pattern matching against AI text quality, but forcing suspicious requests through a trusted process that impersonation cannot easily imitate.