Join our Newsletter — 33% off our NHI Course

Social engineering and invoice fraud: what security teams need to know

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Social engineering still underpins modern invoice fraud, vishing, and impersonation attacks because attackers exploit human trust rather than technical flaws, according to Abnormal AI’s Vision 2023 session with Rachel Tobac and James Linton. The governance problem is that awareness alone does not close the gap between human decision-making and adversary deception.

Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “Hacking with Hackers: Uncovering the Human Element of Cybercrime”.

Key questions

Q: How should security teams reduce invoice fraud risk in email workflows?

A: Security teams should separate message receipt from business approval.

Q: Why does social engineering still work even when employees are trained?

A: Because training lowers risk but does not eliminate the human tendency to trust familiar cues, especially when the message is urgent or context-rich.

Practitioner guidance

  • Harden payment approval paths Require independent verification for invoice changes, urgent payments, and beneficiary updates before any funds move.
  • Reduce public impersonation signals Review what job titles, reporting lines, contact paths, and process details are exposed externally, because attackers use that material to make fraud requests look routine.
  • Add friction to exception handling Build delay, evidence capture, and call-back verification into exception workflows so that urgent requests cannot bypass normal review simply by sounding authoritative.

Bottom line: Social engineering remains effective because attackers target human judgement, not just technical systems.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 3 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21474
 

Social engineering is a decision-control problem, not an awareness problem: Training reduces susceptibility, but it does not change the fact that humans can still be induced to authorise unsafe actions under pressure. The better frame is governance over high-risk decisions, especially those that move money, reset access, or override normal workflow. Security leaders should treat these interactions as identity events with business impact.

A few things that frame the scale:

  • 74% of all breaches included the human element, through error, privilege misuse, stolen credentials or social engineering, according to Verizon's 2023 Data Breach Investigations Report.

A question worth separating out:

Q: What should organisations do when a suspicious social engineering request is detected?

A: Pause the transaction, verify the request through an independent channel, and preserve the details for follow-up investigation. If the request involves funds, access, or account recovery, treat it as a potential identity event and notify the relevant business owner before any action is taken.

👉 Read our full editorial: Social engineering remains the present and future fraud threat


This post was modified 3 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.