Blog

AI Phishing Awareness: A New Era of Social Engineering

A real-time look at how a fake executive recruiter used personalization, patience, and pressure to build a believable phishing campaign.

The Message That Looked Like an Opportunity

Phishing used to be easier to spot when the emails contained awkward grammar, generic greetings, and an urgent request to click a suspicious link. Artificial intelligence has changed that. Today, attackers can quickly produce polished messages, research a target’s professional background, imitate industry language, and sustain a convincing conversation over days or weeks. The result is not simply a better phishing email, but a tailored social-engineering campaign designed to earn trust one small step at a time.

The following real-life example began with an unsolicited message about a senior healthcare cybersecurity role. Across 14 email exchanges, a supposed recruiter and a supposed executive-documentation specialist built an increasingly elaborate story. No single message contained every classic warning sign. Even the most cyberaware readers failed to suspect an issue as the campaign unfolded gradually, making each next request appear like a reasonable continuation of the last.  I engaged in the email exchange in order to see how it would play out.

Stage 1: The Personalized Hook

The first stage consisted of two emails that read like a legitimate recruiter.

Email 1: Researched Not Random

Email 1 was sent to my email and opened with specific, flattering language, “I reviewed your progression from IBM architecture leadership through healthcare IT and into CISO level cybersecurity.” It then presented a “confidential” VP role at Palo Alto Networks with compensation of “$500K–$750K+,” bonus and equity. The details matched my field and career history closely enough to feel researched rather than random.

Email 2: From Curiosity to Collection

Email 2 followed with a professional-looking job description for “VP, Healthcare Cybersecurity & Medical Device Security.” It used credible executive language, like enterprise architecture, technology transformation, medical-device security, and CISO leadership. Then, it instructed me to send a current résumé if interested, moving the interaction from curiosity to information collection.

What Made It Effective

The attacker combined public professional information, a respected company name, a highly compensated role, confidentiality, and language tailored to healthcare cybersecurity. AI can help assemble these elements quickly and turn scattered online details into a message that feels written exclusively for one person.

Stage 2: Creating Authority and a Second Persona

Stage 2 focused on showing experience and providing a contact to appear legitimate.

Email 3: Critique and Polish

Email 3 delivered an unusually detailed critique of the résumé. It recommended stronger “Executive Leadership Positioning,” “Career Progression & Leadership Trajectory,” “Enterprise Scale & Scope,” and “Strategic Business Impact.” It even supplied a proposed executive brand statement. The volume, polish, and specificity made the sender appear invested in the candidate’s success.

Emails 4 and 5: Advancing the Candidate Process

The recruiter then introduced “Elisa Gilmore,” described as an executive documentation specialist. Email 4 praised my “deep understanding of executive cybersecurity leadership, healthcare risk, transformation, and medical device security” and said the recruiting team was working within a “defined timeline.” Email 5 reinforced the handoff by saying, “When you contact her, kindly mention that Jonathan Pirrie referred you.”

What Made It Effective

A second identity created the appearance of a legitimate recruiting ecosystem. One persona acted as the opportunity gatekeeper while the other offered specialized help. Whether both identities were controlled by one person or coordinated actors, the handoff appeared to create social proof, making the process feel more established.

Stage 3: Overcoming Resistance Without Breaking Character

Stage 3 reinforced the persona’s realism and experience to maintain a connection with the target.

Email 6: Continued Contact and Attempted Misdirection

When I asked to verify the process and requested a FaceTime call, the recruiter did not disappear. Email 6 replied: “I won’t be available for a FaceTime call today. I’m currently managing several active executive searches and candidate timelines.” The sender offered a call later, but first encouraged contact with the documentation specialist “to keep the process moving efficiently within the timeline.”

Email 7 and 8: Reinforced Experience

Email 7 had Elisa ask to review the résumé before a discussion. After the recipient questioned why a résumé writer was needed, Email 8 reframed the step as routine executive recruiting by responding, “Jonathan often refers candidates who are being considered at the executive level.” The sender also claimed, “more than 30 years of experience” and promised, “absolutely no fee associated at this stage.”

Email 9:

In Email 9, after I requested a recruiter name and company email for independent verification, the response acknowledged the concern. However, it kept the process inside the same closed loop, stating that the documentation specialist was “the executive documentation specialist I referred you to” and again emphasized “momentum,” “efficiency,” and “the candidate experience.”

What Made It Effective

The responses were calm, validating, and adaptable. Instead of arguing with skepticism, the sender acknowledged it, offered partial reassurance, and redirected attention to the next step. AI-assisted social engineering can excel at conversational flexibility by generating plausible answers instantly while preserving tone and context.

Stage 4: Applying Time Pressure and Moving Off Platform

Stage 4 mimics the interview process, trying to get the target to move offline.

Email 10, Email 11, and Email 12: Creating a Time Crunch

Email 10 promised a brief call the next morning at 8:00 a.m. But Email 11 postponed it: “I’m quite tied up at the moment managing several candidates and active search timelines,” and asked for the recipient’s best phone number instead. Email 12 confirmed the number had been saved, yet again delayed direct contact while urging continued work with Elisa so the recipient would not “miss the timeline or lose momentum.”

Email 13 and Email 14: Moving to a Private Platform

Email 13 tried to move the conversation to WhatsApp. Email 14 switched again, offering Telegram for a “more direct and convenient conversation.” By this stage, the campaign had established two trusted personas, normalized delays, and attempted to move the target away from email systems where security controls, reporting tools, and organizational oversight may be stronger.

What Made It Effective

The different emails applied pressure under the guise of a rapidly moving interview process. As the job market tightens, this urgency combined with the chaotic changes in communications made the accelerated timeline feel credible, increasing the pressure on applicants to respond quickly rather than risk losing the opportunity.

Why AI Phishing Is a New Era of Social Engineering

AI phishing campaigns defy the traditional notion of clicking on a malicious link or downloading a malicious attachment. Generative AI enables attackers to personalize messages and respond to target questions, creating a realistic conversational experience.

As AI becomes increasingly integrated into phishing attacks, it enables malicious actors to improve their processes through:

  • Personalization at scale: Attackers can tailor messages to a person’s career, organization, industry, and interests without spending hours writing each email.
  • Professional-quality language: AI can remove the spelling and grammar mistakes that once made phishing easier to recognize.
  • Persistent conversational memory: The sender can reference earlier questions, objections, and commitments, making a long exchange appear coherent.
  • Multiple believable personas: AI can help maintain different voices and roles—recruiter, résumé expert, executive, vendor, or support representative—within one campaign.
  • Adaptive persuasion: When a target hesitates, the story changes. Calls are delayed, reassurance is added, and urgency is softened or increased as needed.
  • Faster production: Detailed job descriptions, résumé critiques, follow-up messages, and scripts can be generated in minutes.

Warning Signs in This Campaign

As cyber criminals evolve their strategies, organizations must teach their workforce members to identify clues in these new campaigns. For example, in this campaign, some warning signs included:

  • An unsolicited opportunity with unusually high compensation.
  • A recruiter using a consumer email account instead of a verifiable corporate domain.
  • A “confidential” process that discouraged normal verification.
  • Requests for a résumé and phone number before identity was established.
  • A second contact introduced by the first contact, with both relying on consumer email accounts.
  • Repeated promises of a live call that never occurred.
  • Pressure to maintain “momentum” or avoid missing a supposed timeline.
  • Attempts to move the conversation to WhatsApp or Telegram.
  • An email thread and subject line that referenced a well-known company without proof that either sender represented it.

Pause, Verify, and Report

As workforce members move through their inboxes, some steps to mitigate AI phishing risk include:

  1. Pause before responding. Review the message since a polished message is not proof of legitimacy.
  2. Verify independently. Use the company’s official website or a trusted phone number, not contact details supplied in the message.
  3. Check the sender’s domain. Hover over or click on a recognizable display name that can hide an unrelated address.
  4. Do not move to another platform. Be especially cautious when a new contact pushes WhatsApp, Telegram, text messaging, or another private channel.
  5. Limit personal information. Mitigate risk of future impersonation attempts by reducing publicly available information on the internet, like résumés, phone numbers, work histories, and professional contacts.
  6. Report the entire conversation. Inform IT and security about the email and forward it to them since a single email may appear harmless but the pattern across the full thread often reveals the attack.

The Bottom Line

AI has not changed the basic goal of phishing which is to manipulate a person into sharing information, sending money, opening a file, clicking a link, or granting access. What has changed is the quality and persistence of the deception. The safest response is not to ask whether a message looks professional. Ask whether the sender’s identity, authority, and request can be verified through a separate, trusted channel. In the age of AI phishing, trust should be earned through verification, not through polished writing.

Share

Related Articles

CISO Brief October 2026: Cybersecurity Threat Recap & Key Insights

Legacy Medical Devices: Healthcare’s Persistent Security Challenge

Your Biggest Cybersecurity Risk Might Be Your Most Helpful Employee