Social Engineering in the GenAI Era
Executive Brief
Part 1 of 5
Why the Voice Channel is Now the Front Line of Cyber Defense
AI-powered deception is rewriting the rules of cybersecurity.
Part I
EXECUTIVE BRIEF
The 2025 threat landscape has changed. Generative AI (GenAI) has transformed social engineering from a manual art form into an automated science, producing deception that is instant, scalable, and nearly indistinguishable from truth.
Every major research body, including CrowdStrike, Unit 42, ISACA, Proofpoint, and Mimecast, reports the same trend: human-focused attacks now dominate cyber incidents, and the voice channel has become the most exploited path to entry.
While email and network layers have matured, telephony remains largely unprotected. In most enterprises, every inbound call is trusted by default, a design flaw now costing millions.
Special 5-Part Series
Each installment in the Social Engineering in the GenAI Era series will be released weekly on Tuesdays, guiding readers through the evolving threat landscape and the critical role of voice security in modern cybersecurity defense.
This is Part 1.
Key Numbers Behind the Crisis
- 75% of global incidents investigated by Unit 42 involve social engineering; it has overtaken vulnerability exploitation as the top breach vector.
- CrowdStrike reports vishing up 442% in the last six months of 2024, the steepest increase ever recorded.
- Proofpoint confirms that 52% of users disclose sensitive data in simulated voice-phishing (vishing) calls.
- Mimecast’s State of Human Risk shows 94% of CISOs rank human error as their leading concern, yet only 6% of organizations continuously update policy.
- Mutare’s 2024 Voice Threat Survey: 70% of enterprises experienced voice-based attacks; 94% of security leaders agree the voice channel must be part of cyber strategy.
The evidence is overwhelming: AI-assisted social engineering, particularly over voice, is now the most reliable method of initial access.
How GenAI Amplifies Deception
AI accelerates every stage of manipulation:
- Reconnaissance: Models harvest public data to craft personalized pretexts.
- Content generation: Tools like FraudGPT produce flawless, localized scripts.
- Voice cloning: Ten seconds of audio can create a perfect imitation of an executive.
- Adaptive interaction: Real-time sentiment analysis adjusts tone and strategy mid-call.
- Hybrid campaigns: Email or chat lures direct victims to call AI-driven “agents.”
Why Voice Is the Weakest Link
Voice is the most trusted and least inspected medium in enterprise communication.
Help desks, call centers, and executives must answer every call; traditional firewalls and EDR tools can’t analyze voice packets; and STIR/SHAKEN protocols validate caller ID, not caller intent.
Legacy telephony infrastructure creates a blind spot where malicious and legitimate calls look identical. Attackers exploit this to bypass email filters, MFA, and training, reaching humans directly.
The immediacy of unfiltered, human-to-human connection through voice makes it a particularly powerful medium for psychological manipulation.
The Solution: The Voice Firewall
As AI amplifies social engineering, enterprises require more than awareness training, they need a technical control that stops malicious calls before a human answers. The Voice Firewall delivers that protection. It functions as a pre-ring defense layer for the voice channel, analyzing inbound traffic in real time to block spoofing, robocalls, and vishing attempts while allowing legitimate communication to flow freely.
By filtering unwanted voice traffic, the Voice Firewall:
- Reduces risk of fraud and social engineering.
- Restores productivity and call-center efficiency.
- Creates auditable evidence of “reasonable cybersecurity.”
- Integrates with SIEM and XDR platforms to enrich enterprise threat intelligence.
In an era when conversation has become the primary attack vector, the Voice Firewall transforms the voice network from a vulnerability into a verifiable control point, the essential safeguard for modern digital trust.
This 5-Part Series: Social Engineering in the GenAI Era
Generative AI has rewritten the playbook for cyber deception. Social Engineering in the GenAI Era is a five-part Mutare analysis examining how AI, psychology, and unprotected voice channels have converged to create the fastest-growing attack vector in enterprise security. Drawing on research from CrowdStrike, Unit 42, Proofpoint, Mimecast, ISACA, EY, IBM, and Mutare’s own Voice Threat Survey, the series traces the evolution from code exploits to conversational manipulation.
Each installment explores a critical dimension of this new threat landscape. Together, these reports reveal why legacy defenses no longer suffice and why the Voice Firewall has emerged as the essential control for modern, “reasonable” cybersecurity.
