Advisory ID: NCC-CSIRT-2026-026
Summary:
NCC-CSIRT is alerting Telecommunications Service Providers to the growing use of AI-powered social engineering attacks, including deepfake voice calls, phishing emails, and impersonation scams. As these threats become more convincing, organizations are increasingly adopting awareness programmes to identify psychological manipulation tactics used by threat actors. A recent incident involving Bayer, a German multinational pharmaceutical and biotechnology company, demonstrated the effectiveness of this approach, as employees successfully detected and thwarted a deepfake voice-phishing attack targeting a senior executive.
Damage: High
Probability: High
Description:
ybercriminals are increasingly leveraging Artificial Intelligence tools to enhance the effectiveness of social engineering attacks. These technologies enable attackers to generate realistic emails, messages, audio recordings, and other forms of communication that closely resemble legitimate interactions.
Of particular concern is the growing use of deepfake technology to impersonate senior executives, government officials, regulators, and trusted business contacts. Such attacks often exploit human psychology by creating a sense of urgency, authority, fear, or trust to manipulate victims into taking actions that compromise organizational security.
Unlike traditional cyberattacks that exploit software vulnerabilities, these attacks primarily target human decision-making processes. Consequently, organizations that rely solely on technical security controls may remain vulnerable if employees are not adequately prepared to identify and respond to psychological manipulation tactics.
Threat Types:
- AI-Enabled Social Engineering
- Deepfake Voice Impersonation
- Business Email Compromise (BEC)
- Executive Impersonation Fraud
- Spear-Phishing
- Voice Phishing (Vishing)
- AI-Generated Fraudulent Communications
- Identity Deception and Manipulation
Consequences:
Successful exploitation may result in:
- Impersonate regulators, executives, or business partners
- Manipulate staff into disclosing sensitive information
- Initiate fraudulent financial transactions
- Gain unauthorized access to network management systems
- Exploit customer service channels through social engineering
- Conduct AI-generated voice or video impersonation attacks against employees
Solutions/Mitigations:
NCC-CSIRT strongly recommends the following immediate action:
- Enhance cybersecurity awareness programmes to include AI-enabled social engineering and deepfake threats.
- Train employees to recognize psychological manipulation techniques, including urgency, authority pressure, fear, and emotional appeals.
- Implement strict verification procedures for sensitive requests involving financial transactions, account changes, network modifications, or disclosure of confidential information.
- Conduct regular phishing, vishing, and executive impersonation simulation exercises.
- Promote a culture of verification and reporting of suspicious communications.
- Implement multi-factor authentication (MFA) across critical systems and administrative accounts.
- Review and strengthen incident response procedures for social engineering incidents.
- Encourage immediate reporting of suspected deepfakes, impersonation, or social engineering attempts to internal security teams and NCC-CSIRT.
References:
-
https://www.infosecurity-magazine.com/news/bayer-reinvents-security-awareness/
-
https://hawk-eye.io/2026/03/deepfake-driven-social-engineering-how-ai-voice-and-video-are-being-used-to-bypass-security-controls/
-
https://www.crowdstrike.com/en-us/cybersecurity-101/social-engineering/ai-social-engineering/
-
https://www.cyberhaven.com/infosec-essentials/ai-social-engineering