By NHI Mgmt Group Editorial TeamDomain: Identity Beyond IAMSource: Knowbe4Published December 16, 2025

TL;DR: AI-crafted phishing, deepfake impersonation, credential theft and MFA bypass are now standard social engineering tools, while IT and SOC teams struggle with alert overload and fragmented visibility, according to Knowbe4’s whitepaper. The core issue is that human-risk controls and incident response still lag attack speed, making identity-centric detection and response essential.


At a glance

What this is: This whitepaper maps nine current email and social engineering challenges, including AI-generated phishing, deepfake impersonation, quishing, and human-risk measurement.

Why it matters: It matters to IAM, SOC, and identity practitioners because social engineering increasingly targets identity itself, turning human trust, credentials, and MFA workflows into the attack surface.

👉 Read Knowbe4’s whitepaper on the nine email and social engineering challenges


Context

Email and social engineering remain identity problems as much as security problems, because attackers are no longer trying only to break technology. They are targeting human trust, credential reuse, MFA fatigue, and the visibility gaps that let risky users or compromised accounts blend into normal activity. In practice, that means the boundary between IAM, SOC, and security awareness has become operational rather than theoretical.

The whitepaper frames this as a collision between faster attack methods and slower defensive workflows. AI-generated lures, impersonation, and credential theft compress the time defenders have to detect abuse, investigate risk, and contain the account or mailbox involved. For identity teams, that shifts the discussion from awareness alone to how identity, email, and response controls work together across the human identity lifecycle.


Key questions

Q: How should security teams reduce password risk when AI can scale phishing and impersonation?

A: Security teams should focus on removing reusable credentials from the identity path, not just adding stronger verification on top of them. That means covering fallback, recovery, remote access, and legacy systems as part of the same programme. If passwords still exist anywhere a user can type, reset, or share them, AI-assisted attacks still have something to target.

Q: Why do social engineering campaigns still succeed in mature enterprises?

A: They succeed because many controls focus on message content while attackers target human trust and business context. A convincing supplier, executive, or support request can bypass suspicion and trigger legitimate action. Mature enterprises still fail when email governance is disconnected from identity verification and downstream approval controls.

Q: What do security teams get wrong about human risk management?

A: They often treat it as a training completion problem instead of a resilience problem. Completion rates do not show whether users can resist realistic lures or report them quickly. The programme should be judged by behavioural signals, especially in roles where a single compromised account can lead to broader access.

Q: How should organisations respond when an incident starts with stolen credentials?

A: Treat it as a containment race. Disable the account, invalidate sessions and tokens, check for privilege escalation, and verify whether the same identity can reach cloud, email, or administrative systems. Where service accounts exist, review them too, because a human compromise often exposes broader access paths.


Technical breakdown

AI-crafted phishing and deepfake impersonation

AI-assisted social engineering improves scale, personalization, and timing. Attackers can generate believable messages, clone executive voice patterns, and adapt lures to role, context, and business process. Deepfakes extend that problem beyond email by adding voice or video impersonation, which can bypass informal verification habits that employees rely on. The technical issue is not only message realism. It is the erosion of trust signals that humans and some workflows still treat as reliable.

Practical implication: strengthen verification steps for high-risk requests and do not rely on sender familiarity or tone as a control.

Credential theft, MFA bypass and identity abuse

Credential theft remains central because it converts social engineering into account takeover. Once an attacker has a password, session token, or MFA workaround, they can often move from inbox abuse to downstream access in SaaS, cloud, or internal applications. MFA helps, but it is not a complete barrier when attackers use adversary-in-the-middle kits, push fatigue, or consent abuse. The identity lesson is that authentication strength and account governance must be evaluated together.

Practical implication: monitor for anomalous authentication patterns, token replay, and suspicious consent or recovery events alongside traditional password controls.

Alert overload and fragmented response workflows

SOC teams lose time when signals are scattered across email gateways, identity systems, EDR, and ticketing platforms. Alert overload creates triage delay, which is exactly what social engineers exploit after initial compromise. If response steps are not tied to account containment, mailbox isolation, and user verification, defenders spend too long debating signal quality instead of limiting blast radius. This is where operational design matters as much as detection content.

Practical implication: build playbooks that link email alerts to identity containment actions and clear ownership for triage, escalation, and recovery.


Threat narrative

Attacker objective: The attacker aims to convert human trust into durable account access that enables fraud, mailbox abuse, and broader identity compromise.

  1. Entry begins with AI-crafted phishing, quishing, or impersonation that convinces the target to click, respond, or disclose credentials.
  2. Escalation follows when the attacker captures credentials, bypasses MFA, or abuses session access to enter the user’s identity perimeter.
  3. Impact occurs when the compromised account is used for business email compromise, fraud, lateral access, or further credential harvesting.

NHI Mgmt Group analysis

Email is becoming an identity governance problem, not just a content-filtering problem. The article reflects a wider shift in which phishing, quishing, and impersonation target the trust layer that IAM, help desks, and users all depend on. That makes human identity control, credential governance, and verification policy part of the same risk surface. Practitioners should treat email abuse as a trigger for identity response, not only mailbox cleanup.

Human-risk measurement is only useful when it is tied to control action. Measuring susceptibility without linking results to targeted training, access review, or stronger verification creates reporting without reduction. Security teams need metrics that inform who gets stepped-up verification, which roles need tighter approval paths, and where social-engineering exposure is highest. Practitioners should connect human-risk scoring to policy decisions, not just awareness dashboards.

Deepfake-enabled impersonation widens the verification trust gap. The article points to a growing mismatch between how people verify requests and how convincingly attackers can simulate authority. That gap is especially relevant where finance, identity operations, or privileged support workflows still rely on informal callback habits. Practitioners should harden out-of-band verification and reduce reliance on voice or message style as proof of legitimacy.

Alert overload is a governance failure when containment depends on manual correlation. Fragmented tools across email, identity, and SOC workflows slow response to the point where compromised credentials remain usable long enough to do damage. This is where cross-domain identity orchestration matters, because the same account that triggered the alert may also need immediate token revocation, mailbox isolation, and access review. Practitioners should align response ownership across SOC and IAM before the next phishing wave.

Measuring social engineering risk needs a named concept: verification trust gap. That gap is the distance between what users think authenticates a request and what attackers can now fake with AI and stolen credentials. The more that distance grows, the less value traditional awareness alone provides. Practitioners should design controls that verify the request, the requester, and the account state before trust is granted.

What this signals

Verification trust gap: AI-assisted impersonation increases the distance between what users believe is authentic and what attackers can convincingly fake. That gap matters because identity programmes often still assume people can spot fraudulent requests with enough training. Security teams should respond by tightening verification paths, especially where email, voice, and help-desk interactions can trigger privileged action.

Identity teams should expect social engineering to show up as an IAM issue more often, not less. That means account recovery, MFA reset, consent handling, and mailbox rules need the same governance attention as password policy once did. A useful starting point is the Top 10 NHI Issues, which helps frame how identity abuse becomes operational risk.

The operational signal is clear: if phishing outcomes do not change access decisions or containment actions, the programme is measuring exposure without reducing it. Practitioners should also align human identity response with established control structures such as the NIST SP 800-53 Rev 5 Security and Privacy Controls, especially where authentication, audit, and incident response intersect.


For practitioners

  • Strengthen request verification for high-risk actions Require separate verification paths for payment changes, credential resets, mailbox rule changes, and privileged requests so an email alone cannot authorise action. Use call-backs, approvals, or workflow-based confirmation tied to the request type. This is especially important where business email compromise can target finance or identity operations.
  • Connect email alerts to identity containment Ensure suspicious email, phishing click, and account takeover signals trigger account suspension, session revocation, mailbox isolation, and credential reset in one workflow. Map these steps before incidents occur so SOC analysts are not improvising during triage. The goal is to reduce the time a compromised identity remains usable.
  • Use human-risk scores to drive control changes Link phishing simulation outcomes, risky behaviour, and repeat exposure to actual policy changes such as stepped-up authentication, tighter approvals, or role-based training. Human-risk measurement should influence access decisions and verification depth, not sit in a reporting dashboard. That makes the programme actionable rather than descriptive.
  • Harden privileged and help-desk verification Treat help-desk resets, MFA recovery, and privileged support requests as high-risk identity events. Add strict identity proofing, step-up checks, and logging for all exception handling because attackers often use these paths after phishing fails. This reduces the chance that social engineering turns into account takeover.

Key takeaways

  • AI-powered email fraud now targets the trust mechanisms that underpin identity, support, and approval workflows.
  • The article’s core risk is not just better phishing content, but slower response across fragmented tools and teams.
  • Practitioners should tie human-risk measurement to verification, containment, and access governance decisions.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while GDPR define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-1Social engineering abuses authentication and access control paths.
NIST SP 800-53 Rev 5IA-5Credential theft and reset abuse are central to the attack pattern.
GDPRArt.32Human identity and email abuse can expose personal data and account access.

Apply appropriate security of processing controls where identity compromise could expose personal data.


Key terms

  • Business email compromise: A form of social engineering where an attacker impersonates a trusted person or domain to manipulate payment, change banking details, or extract sensitive information. It often succeeds without malware because the attacker targets process trust and human judgement instead of technical controls.
  • Activation Trust Gap: The activation trust gap is the difference between trusting data because it is protected and governing it because it is being reused. It appears when organisations move data from backup or archival systems into AI pipelines without reapplying access, sensitivity, and consumer controls.
  • Human Risk: The likelihood that a person will be persuaded or tricked into enabling an attack. In identity programmes, it is most useful when tied to specific workflows such as approvals, password resets, forwarding rules, and exception handling.

What's in the full article

Knowbe4’s full whitepaper covers the operational detail this post intentionally leaves for the source:

  • Specific breakdowns of the nine social engineering challenges and how each maps to different defensive workflows.
  • Practical guidance on combining Security Awareness Training, Cloud Email Security, and Anti-Phishing Incident Response.
  • Examples of how to detect threats that traditional tools miss without overwhelming IT and SOC teams.
  • The vendor’s approach to quantifying human risk for reporting and decision-making.

👉 The full Knowbe4 whitepaper covers the challenge breakdown, detection themes, and response workflow recommendations.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, secrets management, and identity lifecycle fundamentals. It is designed for practitioners who need to connect identity controls to real-world security operations.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org