When Chatbots Become Con Artists: How LLMs Are Powering Next-Gen Phishing
From customized spear-phishing to voice deepfakes, generative AI is sharpening social engineering. Security teams are scrambling to turn the tables.
From customized spear-phishing to voice deepfakes, generative AI is sharpening social engineering. Security teams are scrambling to turn the tables.

Illustration by IMF Alpha editorial · Reviewed by Pedro Marini
The new face of social engineering is unnervingly human. Generative language models and voice synthesizers are sharpening a trend that’s been around for years: attackers who can write far better lies. The effect is not just more scams. It’s scams that are harder to spot and that scale with frightening ease.
Email fraud used to require craft. Someone would study an org chart, sweat the tone, and draft a clumsy-but-convincing note. Now an attacker can feed a model a public bio, a few press releases and a persona, and out comes a message that mirrors internal tone and cadence. It’s eerily convincing.
This isn’t theoretical. Security teams are seeing phishing that imitates employee handwriting—metaphorically speaking—or captures an executive’s cadence. And voice synthesis adds a second punch: there are documented cases where a fabricated voice was used to authorize transfers. Hearing a familiar voice can short-circuit the very checks people relied on.
Why businesses should care
A defender playbook — pragmatic, layered, ruthless
A dose of nuance
This is not an unstoppable siege. The same models that help attackers also help defenders triage alerts, summarize impact and automate responses. People still catch scams when they pause. Good UX that makes skepticism easy — and friction that’s purposeful rather than punitive — will beat panic.
A short history check keeps things in perspective. Business email compromise surged in the 2010s because of basic human trust and weak controls. Two decades from now the exact vectors will change, but the core failure will be unchanged: treating trust as binary instead of a process.
What to do now
There is an upside. We already know how to fight social engineering: add friction where it matters, automate verification where you can, and make trust a repeatable process rather than a checkbox. Organizations that move fast will turn this awkward new threat into an operational advantage.

After headline-grabbing data scares, lenders and asset managers are shifting to private, on-prem and confidential-cloud AI. That pivot reshuffles winners, costs, and regulatory risk.

On-device AI is moving from novelty to mainstream. From privacy promises to chip-stock implications, here’s what consumers and investors need to know.

Smartphones are shifting from cloud-first to local inference — faster, more private, and opening new business models for apps and financial services.