Subscribe to the Non-Human & AI Identity Journal

Social Engineering Phishing

A phishing approach that relies primarily on persuasion, urgency, and trust rather than malicious attachments or obvious malware. In AI-assisted campaigns, the attacker uses generated text and tailored pretexts to increase credibility and move the target into credential submission or other unsafe actions.

Expanded Definition

social engineering phishing is a deception technique that persuades a target to disclose credentials, approve access, or take another unsafe action by exploiting urgency, authority, familiarity, or fear. It differs from broad social engineering because the attacker typically uses a message-based lure, often delivered by email, SMS, collaboration tools, or voice follow-up, to push the victim into a specific response. The core risk is not only the message content but the behavioural manipulation that makes a legitimate action feel routine. In AI-assisted campaigns, attackers can scale pretexting and personalise language, timing, and tone, which makes the lure harder to dismiss and easier to trust. NIST frames identity assurance and authenticator handling in the NIST SP 800-63 Digital Identity Guidelines, while security control expectations for awareness and verification map well to NIST SP 800-53 Rev 5 Security and Privacy Controls. The most common misapplication is treating phishing as only a malicious-link problem, which occurs when organisations ignore credential harvesting, consent abuse, and follow-on account takeover.

Examples and Use Cases

Implementing phishing defence rigorously often introduces friction for users and support teams, requiring organisations to weigh faster workflows against stronger verification steps.

  • A finance employee receives a message that appears to come from a chief executive asking for urgent payment approval, then is redirected to a fake login page that harvests credentials.
  • A cloud administrator gets a chat message that mimics an internal support team and requests an MFA reset, creating an opening for account takeover and persistence.
  • A contractor receives a seemingly routine document-share notification and is persuaded to authorise a malicious OAuth consent prompt instead of entering a password.
  • A help desk agent is targeted by a caller using details from publicly available data and is coached into resetting an account without adequate identity verification.
  • Security teams review patterns described in the ENISA Threat Landscape to understand how phishing blends technical lures with social manipulation across channels.

These use cases show that the attacker does not need malware to succeed; the message itself is the weapon when it pushes a human into bypassing normal caution.

Why It Matters for Security Teams

Social engineering phishing matters because it undermines the trust assumptions that identity, access, and incident response depend on. When users are trained only to spot suspicious attachments, defenders miss the more dangerous pattern: an apparently legitimate request that induces a protected action, such as sharing a one-time code, approving a login, resetting a password, or authorising an app. That failure can defeat MFA, create privileged footholds, and expose identity proofing weaknesses, especially where service desks or self-service portals accept weak signals. Security teams need to align awareness, verification, and response workflows so that people know when to pause and validate rather than comply. This is where identity governance becomes practical: account recovery, step-up checks, and exception handling need explicit controls, not informal judgment. Organisational resilience improves when phishing scenarios are tested as process failures, not just awareness failures, and when controls are mapped back to guidance in NIST SP 800-63 Digital Identity Guidelines and NIST SP 800-53 Rev 5 Security and Privacy Controls. Organisations typically encounter the full cost only after a successful impersonation leads to account compromise, at which point phishing becomes operationally unavoidable to contain and investigate.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5, NIST SP 800-63 and NIST AI RMF set the technical controls, while EU AI Act define the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 PR.AT Security awareness and training address human susceptibility to phishing.
NIST SP 800-53 Rev 5 AT-2 AT-2 defines awareness training that reduces successful social engineering.
NIST SP 800-63 IAL/AAL Identity assurance guidance is relevant when phishing targets login and recovery flows.
NIST AI RMF AI RMF is relevant when generated text is used to increase phishing credibility.
EU AI Act The EU AI Act informs governance where AI-generated content is used deceptively at scale.

Assess whether AI-enabled phishing tooling triggers additional governance and transparency duties.