TL;DR: Social engineering still underpins modern invoice fraud, vishing, and impersonation attacks because attackers exploit human trust rather than technical flaws, according to Abnormal AI’s Vision 2023 session with Rachel Tobac and James Linton. The governance problem is that awareness alone does not close the gap between human decision-making and adversary deception.
At a glance
What this is: This recorded Vision 2023 session examines why social engineering continues to drive invoice fraud and impersonation attacks by exploiting human trust and emotion.
Why it matters: It matters because IAM and security teams still need controls that reduce deception at the decision point, not just training that raises awareness after the fact.
Context
Social engineering is a human identity problem when attackers persuade people to reveal information, approve payments, or bypass normal checks. The weakness is not a broken protocol but the fact that trust, urgency, and authority cues can override intended decision paths.
For identity programmes, that means awareness training is only one layer. The more durable question is how human IAM, approval workflows, and account recovery processes can reduce the chance that a convincing message becomes an authorised action.
Key questions
Q: How should security teams reduce invoice fraud risk in email workflows?
A: Security teams should separate message receipt from business approval. Payment changes, supplier bank updates, and urgent exceptions need an independent verification path, risk-ranked vendor monitoring, and mailbox controls that identify impersonation patterns. The main objective is to stop email from becoming the final authorisation channel for financial action.
Q: Why does social engineering still work even when employees are trained?
A: Because training lowers risk but does not eliminate the human tendency to trust familiar cues, especially when the message is urgent or context-rich. Attackers adapt their pretexts to the organisation, so the real issue is whether business processes force a second check before action. Awareness without workflow friction leaves the final decision exposed.
Q: What are the warning signs that an impersonation attempt may be fraudulent?
A: Urgency, unusual payment instructions, pressure to bypass normal approvers, and requests that rely on insider knowledge are common warning signs. A request that feels specific but asks for exception handling should be treated as higher risk, especially when it touches money, access, or sensitive account changes.
Q: What should organisations do when a suspicious social engineering request is detected?
A: Pause the transaction, verify the request through an independent channel, and preserve the details for follow-up investigation. If the request involves funds, access, or account recovery, treat it as a potential identity event and notify the relevant business owner before any action is taken.
Background and context
Why impersonation works in invoice fraud
Invoice fraud often succeeds because the attacker does not need to compromise a system first. They only need enough context to appear legitimate and enough urgency to push a human into action. Social engineering uses timing, emotion, and authority signals to redirect a user’s normal verification behaviour. In practical terms, the fraud path is built around trust transfer: the target believes the request came from someone entitled to make it. That makes the control problem fundamentally different from malware detection, because the harmful act is often an authorised human action taken under false pretence.
Practical implication: validate payment and account-change requests through an out-of-band approval path that is hard to imitate.
How attackers collect the context they need
Successful social engineering rarely depends on random guessing. Attackers often gather public details about the target, the organisation, and the relationship between people to craft messages that feel routine. The article highlights that hackers can uncover information both about the impersonated victim and the target, which is the raw material for believable pretexting. This is why generic awareness training decays quickly: the attacker adapts the script to the environment. The real architectural issue is that humans are being asked to verify context that the adversary has already engineered to appear familiar.
Practical implication: limit the public exposure of role, contact, and workflow details that make impersonation easier to personalise.
How awareness changes the fraud playbook
As organisations become more aware of social engineering, attackers shift to subtler pretexts rather than disappearing. Awareness raises the cost of simple scams, but it does not remove the underlying asymmetry between an attacker who can iterate messages and a defender who must get every judgment call right. That is why security leaders need to think in terms of decision friction, verification paths, and workflow design. The control objective is not to make every employee perfectly resistant. It is to make fraudulent requests harder to convert into business action.
Practical implication: redesign approval and exception handling so that suspicious requests are slowed, checked, and evidenced before execution.
NHI Mgmt Group analysis
Social engineering is a decision-control problem, not an awareness problem: Training reduces susceptibility, but it does not change the fact that humans can still be induced to authorise unsafe actions under pressure. The better frame is governance over high-risk decisions, especially those that move money, reset access, or override normal workflow. Security leaders should treat these interactions as identity events with business impact.
Context is now an attack surface: The article’s emphasis on what attackers can uncover about the victim and the target points to a simple truth: the more a request matches normal business context, the more likely it is to succeed. That makes exposed organisational relationships, roles, and process details materially relevant to fraud resistance. Practitioners should assume that public context can be weaponised into believable pretexts.
Humans are the last-mile control in invoice fraud: Technical controls may filter some malicious messages, but the decisive step is often a human approval that turns suspicion into execution. This means the business process itself needs friction where the risk is highest, especially around payments, vendor changes, and exceptions. The implication is clear: if the workflow allows a single persuasive request to become action, the control plane is too weak.
Social engineering will keep evolving because defenders adapt slowly: The article’s future-facing point is right, but the deeper lesson is that attacker creativity outpaces static awareness programmes. Once people are educated, the adversary moves to more personalised, lower-noise lures. That makes continuous governance over user-facing processes more durable than one-time training campaigns.
Identity security must include human trust boundaries: The discipline cannot stop at authentication and access provisioning. When attackers target the human decision itself, the real boundary is whether a request can be converted into authority without independent verification. Teams should treat trust validation as part of identity governance, not as a separate awareness exercise.
From our research library:
- 74% of all breaches included the human element, through error, privilege misuse, stolen credentials or social engineering, according to Verizon's 2023 Data Breach Investigations Report.
What this signals
The programme implication is straightforward: social engineering defence needs to move from broad awareness messaging toward controls embedded in approval, payment, and recovery workflows. The stronger the business process is at forcing independent verification, the less value an attacker gets from persuasive pretexts.
Trust validation gap: The recurring weakness is not message filtering alone but the lack of a reliable step that proves the requester is entitled to the action. Organisations should map which human decisions can still be converted into fraud without a second check and close those paths first.
For practitioners
- Harden payment approval paths Require independent verification for invoice changes, urgent payments, and beneficiary updates before any funds move. Use a separate channel and a second approver for any request that changes payment destination or urgency.
- Reduce public impersonation signals Review what job titles, reporting lines, contact paths, and process details are exposed externally, because attackers use that material to make fraud requests look routine.
- Add friction to exception handling Build delay, evidence capture, and call-back verification into exception workflows so that urgent requests cannot bypass normal review simply by sounding authoritative.
- Test staff with realistic pretexts Use scenario-based exercises for email, voice, and messaging attacks that mimic the organisation’s actual approval chains, not generic phishing templates.
Key takeaways
- Social engineering remains effective because attackers target human judgement, not just technical systems.
- Invoice fraud and impersonation succeed when business workflows allow persuasion to become authority too quickly.
- The practical control is to add independent verification and decision friction at the point where requests become action.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63, NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | SP 800-63B — Authentication | Human verification and trust signals are central to this social engineering article. |
| Recommendation — Strengthen authentication and step-up checks around high-risk human actions and exception requests. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article centres on authorised human actions being induced under false pretence. |
| Recommendation — Tighten authorisation gates for payments, account changes, and other high-risk approvals. | ||
| CIS Controls v8 | CIS-5 — Account Management | Fraudulent impersonation often targets account change and approval processes. |
| Recommendation — Review account change workflows for call-back verification and dual approval on sensitive actions. | ||
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | The article’s risk is people acting on deceptive requests that mimic legitimate identity cues. |
| Recommendation — Apply stronger user authentication and verification around high-risk business processes. | ||
Key terms
- Social Engineering: Social engineering is the use of deception, urgency, and authority to persuade a person to reveal information or take a risky action. It targets human decision-making rather than software defects, and often turns legitimate identity workflows into the attack path.
- Invoice Fraud: Invoice fraud is a business email abuse pattern where attackers redirect payments, alter supplier details, or request exceptions using convincing impersonation. The technical weakness is not only message delivery, but the absence of independent validation before financial action is approved.
- Pretexting: Pretexting is a social engineering technique where an attacker invents a believable story to get information or trigger an action. It often impersonates support staff, vendors, or executives, and succeeds when the target accepts the story without independent verification.
- Out-Of-Band Verification: A confirmation step that uses a different channel or method than the original request. It reduces the chance that a single spoofed email, voice call, or video session can authorize privileged activity or financial transfer.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org