TL;DR: Social engineering still underpins modern invoice fraud, vishing, and impersonation attacks because attackers exploit human trust rather than technical flaws, according to Abnormal AI’s Vision 2023 session with Rachel Tobac and James Linton. The governance problem is that awareness alone does not close the gap between human decision-making and adversary deception.
Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “Hacking with Hackers: Uncovering the Human Element of Cybercrime”.
Key questions
Q: How should security teams reduce invoice fraud risk in email workflows?
A: Security teams should separate message receipt from business approval.
Q: Why does social engineering still work even when employees are trained?
A: Because training lowers risk but does not eliminate the human tendency to trust familiar cues, especially when the message is urgent or context-rich.
Practitioner guidance
- Harden payment approval paths Require independent verification for invoice changes, urgent payments, and beneficiary updates before any funds move.
- Reduce public impersonation signals Review what job titles, reporting lines, contact paths, and process details are exposed externally, because attackers use that material to make fraud requests look routine.
- Add friction to exception handling Build delay, evidence capture, and call-back verification into exception workflows so that urgent requests cannot bypass normal review simply by sounding authoritative.
Bottom line: Social engineering remains effective because attackers target human judgement, not just technical systems.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Social engineering is a decision-control problem, not an awareness problem: Training reduces susceptibility, but it does not change the fact that humans can still be induced to authorise unsafe actions under pressure. The better frame is governance over high-risk decisions, especially those that move money, reset access, or override normal workflow. Security leaders should treat these interactions as identity events with business impact.
A few things that frame the scale:
- 74% of all breaches included the human element, through error, privilege misuse, stolen credentials or social engineering, according to Verizon's 2023 Data Breach Investigations Report.
A question worth separating out:
Q: What should organisations do when a suspicious social engineering request is detected?
A: Pause the transaction, verify the request through an independent channel, and preserve the details for follow-up investigation. If the request involves funds, access, or account recovery, treat it as a potential identity event and notify the relevant business owner before any action is taken.
👉 Read our full editorial: Social engineering remains the present and future fraud threat