Skip to content
Social Engineering Detection Moves Into the Live Conversation

Social Engineering Detection Moves Into the Live Conversation

Securityweek •Kevin Townsend • October 6, 2026

Companies are pouring time and dollars into security awareness training, but there is little empirical evidence to suggest it actually works against social engineering. Social engineering remains a primary and successful attack vector. While system vulnerabilities can be patched, social engineering cannot. The most common pseudo ‘patch’ is user awareness training, but this has failed to block the vector. Human defenders should not and cannot be expected to detect trickery designed to manipulate their psychology. And the tricks are becoming better hidden and more sophisticated with the use of AI deep fakery. Successful examples of social engineering include: The Las Vegas casino breaches of 2023, via vishing. Scattered Spider attackers, posing as employees, tricked the casino’s help desk staff to reset passwords and bypass MFA. MGM Resorts was forced to shut down digital operations for ten days at an estimated cost of $100 million in lost revenue and remediation costs. Caesars Entertainment is thought to have paid a $15 million ransom after the attackers demanded $30 million. More recently, the Brinks leak disclosed in August 2026 also involved voice phishing and the enterprise help desk. This time the attacker was ShinyHunters, although the group has a known relationship with Scattered Spider. Here the attacker simply talked a help desk employee through completing a Microsoft Entra authentication step, granting the hacker immediate access. Almost five million customer records and 41 gigabytes of corporate data were subsequently published on a public hacking forum. If human detection of social engineering cannot be assured, other means of detection must be employed – and technology is the pre-eminent option. The use of technology to detect both traditional and newer AI deep faked social engineering is increasing and improving. One example comes from Netarx . The firm’s solution applies a proprietary orchestration layer which it describes as an AI defense meta harness. The harness correlates individual signals detected by more than 40 AI models continuously scanning all communications while they are in progress, analyzing more than 1,000 digital and metadata signals for each interaction. For example, to ensure the physical device delivering a feed belongs to its authorized user, Netarx analyzes device fingerprints, EXIF data, compression signatures, and location mismatches. For AI-generated voice communications from GANs or voice cloners it examines the micro-artifacts undetectable by the human ear, such as unnatural background silencing and electronic compression anomalies. If video is also included, it matches physical lip movements directly against incoming voice signals. For the facial image, it inspects individual video frames for anomalies in micro-expressions, unnatural blinking frequencies, lighting inconsistencies, or warping around hair lines. No single signal is decisive in indicating fraud. However, the collection and recognition of multiple questionable signals can swing the needle between genuine and fake in real time. However, detecting fraud in progress is only half the problem – the detection must also be relayed to the user in an understandable manner, also in real time. The traditional approach, autonomously blocking dangerous situations, is extreme and can cause more problems than it solves. To avoid this, Netarx has developed a color-coded real-time traffic analysis indicator displayed on screen during the communication. Green indicates that the human identity and the device concerned have been verified. Amber declares that the source is unknown, or that suspicious metadata anomalies have been detected. Red indicates that synthetic media or an active deepfake has been identified. (Internally, the company uses the term ‘flurp’ for this traffic light system. Flurp is defined in the Urban Dictionary as the noise a snail makes.) If amber turns to red during the conversation, it is probably time to disengage; but this is the user blocking the sender rather than the system arbitrarily blocking the process. NIK (the Netarx Identity Key) runs on Windows, macOS, Chrome, iOS and Android; and the company also publishes a database (the Impact Database) that catalogs real-world security incidents where human deception played a decisive role in the attack. This Netarx social engineering solution is an early example of technology supplanting human detection. It will not be the last, because social engineering is a growing vector and a serious threat to enterprise security. The entire security stack is bypassed if a single privileged employee invites a social engineering attacker across the MFA threshold. Related : ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing Related : UNC6692 Uses Email Bombing, Social Engineering to Deploy ‘Snow’ Malware Related : Cyber Insights 2026: Social Engineering Related : Going Into the Deep End: Social Engineering and the AI Flood

Social engineering remains a primary and successful attack vector. While system vulnerabilities can be patched, social engineering cannot. The most common pseudo ‘patch’ is user awareness training, but this has failed to block the vector. Human defenders should not and cannot be expected to detect trickery designed to manipulate their psychology. And the tricks are becoming better hidden and more sophisticated with the use of AI deep fakery. Successful examples of social engineering include: The Las Vegas casino breaches of 2023, via vishing. Scattered Spider attackers, posing as employees, tricked the casino’s help desk staff to reset passwords and bypass MFA. MGM Resorts was forced to shut down digital operations for ten days at an estimated cost of $100 million in lost revenue and remediation costs. Caesars Entertainment is thought to have paid a $15 million ransom after the attackers demanded $30 million. More recently, the Brinks leak disclosed in August 2026 also involved voice phishing and the enterprise help desk. This time the attacker was ShinyHunters, although the group has a known relationship with Scattered Spider. Here the attacker simply talked a help desk employee through completing a Microsoft Entra authentication step, granting the hacker immediate access. Almost five million customer records and 41 gigabytes of corporate data were subsequently published on a public hacking forum. If human detection of social engineering cannot be assured, other means of detection must be employed – and technology is the pre-eminent option. The use of technology to detect both traditional and newer AI deep faked social engineering is increasing and improving. One example comes from Netarx . The firm’s solution applies a proprietary orchestration layer which it describes as an AI defense meta harness. The harness correlates individual signals detected by more than 40 AI models continuously scanning all communications while they are in progress, analyzing more than 1,000 digital and metadata signals for each interaction. For example, to ensure the physical device delivering a feed belongs to its authorized user, Netarx analyzes device fingerprints, EXIF data, compression signatures, and location mismatches. For AI-generated voice communications from GANs or voice cloners it examines the micro-artifacts undetectable by the human ear, such as unnatural background silencing and electronic compression anomalies. If video is also included, it matches physical lip movements directly against incoming voice signals. For the facial image, it inspects individual video frames for anomalies in micro-expressions, unnatural blinking frequencies, lighting inconsistencies, or warping around hair lines. No single signal is decisive in indicating fraud. However, the collection and recognition of multiple questionable signals can swing the needle between genuine and fake in real time. However, detecting fraud in progress is only half the problem – the detection must also be relayed to the user in an understandable manner, also in real time. The traditional approach, autonomously blocking dangerous situations, is extreme and can cause more problems than it solves. To avoid this, Netarx has developed a color-coded real-time traffic analysis indicator displayed on screen during the communication. Green indicates that the human identity and the device concerned have been verified. Amber declares that the source is unknown, or that suspicious metadata anomalies have been detected. Red indicates that synthetic media or an active deepfake has been identified. (Internally, the company uses the term ‘flurp’ for this traffic light system. Flurp is defined in the Urban Dictionary as the noise a snail makes.) If amber turns to red during the conversation, it is probably time to disengage; but this is the user blocking the sender rather than the system arbitrarily blocking the process. NIK (the Netarx Identity Key) runs on Windows, macOS, Chrome, iOS and Android; and the company also publishes a database (the Impact Database) that catalogs real-world security incidents where human deception played a decisive role in the attack. This Netarx social engineering solution is an early example of technology supplanting human detection. It will not be the last, because social engineering is a growing vector and a serious threat to enterprise security. The entire security stack is bypassed if a single privileged employee invites a social engineering attacker across the MFA threshold. Related : ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing Related : UNC6692 Uses Email Bombing, Social Engineering to Deploy ‘Snow’ Malware Related : Cyber Insights 2026: Social Engineering Related : Going Into the Deep End: Social Engineering and the AI Flood

Successful examples of social engineering include: The Las Vegas casino breaches of 2023, via vishing. Scattered Spider attackers, posing as employees, tricked the casino’s help desk staff to reset passwords and bypass MFA. MGM Resorts was forced to shut down digital operations for ten days at an estimated cost of $100 million in lost revenue and remediation costs. Caesars Entertainment is thought to have paid a $15 million ransom after the attackers demanded $30 million. More recently, the Brinks leak disclosed in August 2026 also involved voice phishing and the enterprise help desk. This time the attacker was ShinyHunters, although the group has a known relationship with Scattered Spider. Here the attacker simply talked a help desk employee through completing a Microsoft Entra authentication step, granting the hacker immediate access. Almost five million customer records and 41 gigabytes of corporate data were subsequently published on a public hacking forum. If human detection of social engineering cannot be assured, other means of detection must be employed – and technology is the pre-eminent option. The use of technology to detect both traditional and newer AI deep faked social engineering is increasing and improving. One example comes from Netarx . The firm’s solution applies a proprietary orchestration layer which it describes as an AI defense meta harness. The harness correlates individual signals detected by more than 40 AI models continuously scanning all communications while they are in progress, analyzing more than 1,000 digital and metadata signals for each interaction. For example, to ensure the physical device delivering a feed belongs to its authorized user, Netarx analyzes device fingerprints, EXIF data, compression signatures, and location mismatches. For AI-generated voice communications from GANs or voice cloners it examines the micro-artifacts undetectable by the human ear, such as unnatural background silencing and electronic compression anomalies. If video is also included, it matches physical lip movements directly against incoming voice signals. For the facial image, it inspects individual video frames for anomalies in micro-expressions, unnatural blinking frequencies, lighting inconsistencies, or warping around hair lines. No single signal is decisive in indicating fraud. However, the collection and recognition of multiple questionable signals can swing the needle between genuine and fake in real time. However, detecting fraud in progress is only half the problem – the detection must also be relayed to the user in an understandable manner, also in real time. The traditional approach, autonomously blocking dangerous situations, is extreme and can cause more problems than it solves. To avoid this, Netarx has developed a color-coded real-time traffic analysis indicator displayed on screen during the communication. Green indicates that the human identity and the device concerned have been verified. Amber declares that the source is unknown, or that suspicious metadata anomalies have been detected. Red indicates that synthetic media or an active deepfake has been identified. (Internally, the company uses the term ‘flurp’ for this traffic light system. Flurp is defined in the Urban Dictionary as the noise a snail makes.) If amber turns to red during the conversation, it is probably time to disengage; but this is the user blocking the sender rather than the system arbitrarily blocking the process. NIK (the Netarx Identity Key) runs on Windows, macOS, Chrome, iOS and Android; and the company also publishes a database (the Impact Database) that catalogs real-world security incidents where human deception played a decisive role in the attack. This Netarx social engineering solution is an early example of technology supplanting human detection. It will not be the last, because social engineering is a growing vector and a serious threat to enterprise security. The entire security stack is bypassed if a single privileged employee invites a social engineering attacker across the MFA threshold. Related : ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing Related : UNC6692 Uses Email Bombing, Social Engineering to Deploy ‘Snow’ Malware Related : Cyber Insights 2026: Social Engineering Related : Going Into the Deep End: Social Engineering and the AI Flood

The Las Vegas casino breaches of 2023, via vishing. Scattered Spider attackers, posing as employees, tricked the casino’s help desk staff to reset passwords and bypass MFA. MGM Resorts was forced to shut down digital operations for ten days at an estimated cost of $100 million in lost revenue and remediation costs. Caesars Entertainment is thought to have paid a $15 million ransom after the attackers demanded $30 million. More recently, the Brinks leak disclosed in August 2026 also involved voice phishing and the enterprise help desk. This time the attacker was ShinyHunters, although the group has a known relationship with Scattered Spider. Here the attacker simply talked a help desk employee through completing a Microsoft Entra authentication step, granting the hacker immediate access. Almost five million customer records and 41 gigabytes of corporate data were subsequently published on a public hacking forum. If human detection of social engineering cannot be assured, other means of detection must be employed – and technology is the pre-eminent option. The use of technology to detect both traditional and newer AI deep faked social engineering is increasing and improving. One example comes from Netarx . The firm’s solution applies a proprietary orchestration layer which it describes as an AI defense meta harness. The harness correlates individual signals detected by more than 40 AI models continuously scanning all communications while they are in progress, analyzing more than 1,000 digital and metadata signals for each interaction. For example, to ensure the physical device delivering a feed belongs to its authorized user, Netarx analyzes device fingerprints, EXIF data, compression signatures, and location mismatches. For AI-generated voice communications from GANs or voice cloners it examines the micro-artifacts undetectable by the human ear, such as unnatural background silencing and electronic compression anomalies. If video is also included, it matches physical lip movements directly against incoming voice signals. For the facial image, it inspects individual video frames for anomalies in micro-expressions, unnatural blinking frequencies, lighting inconsistencies, or warping around hair lines. No single signal is decisive in indicating fraud. However, the collection and recognition of multiple questionable signals can swing the needle between genuine and fake in real time. However, detecting fraud in progress is only half the problem – the detection must also be relayed to the user in an understandable manner, also in real time. The traditional approach, autonomously blocking dangerous situations, is extreme and can cause more problems than it solves. To avoid this, Netarx has developed a color-coded real-time traffic analysis indicator displayed on screen during the communication. Green indicates that the human identity and the device concerned have been verified. Amber declares that the source is unknown, or that suspicious metadata anomalies have been detected. Red indicates that synthetic media or an active deepfake has been identified. (Internally, the company uses the term ‘flurp’ for this traffic light system. Flurp is defined in the Urban Dictionary as the noise a snail makes.) If amber turns to red during the conversation, it is probably time to disengage; but this is the user blocking the sender rather than the system arbitrarily blocking the process. NIK (the Netarx Identity Key) runs on Windows, macOS, Chrome, iOS and Android; and the company also publishes a database (the Impact Database) that catalogs real-world security incidents where human deception played a decisive role in the attack. This Netarx social engineering solution is an early example of technology supplanting human detection. It will not be the last, because social engineering is a growing vector and a serious threat to enterprise security. The entire security stack is bypassed if a single privileged employee invites a social engineering attacker across the MFA threshold. Related : ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing Related : UNC6692 Uses Email Bombing, Social Engineering to Deploy ‘Snow’ Malware Related : Cyber Insights 2026: Social Engineering Related : Going Into the Deep End: Social Engineering and the AI Flood

More recently, the Brinks leak disclosed in August 2026 also involved voice phishing and the enterprise help desk. This time the attacker was ShinyHunters, although the group has a known relationship with Scattered Spider. Here the attacker simply talked a help desk employee through completing a Microsoft Entra authentication step, granting the hacker immediate access. Almost five million customer records and 41 gigabytes of corporate data were subsequently published on a public hacking forum. If human detection of social engineering cannot be assured, other means of detection must be employed – and technology is the pre-eminent option. The use of technology to detect both traditional and newer AI deep faked social engineering is increasing and improving. One example comes from Netarx . The firm’s solution applies a proprietary orchestration layer which it describes as an AI defense meta harness. The harness correlates individual signals detected by more than 40 AI models continuously scanning all communications while they are in progress, analyzing more than 1,000 digital and metadata signals for each interaction. For example, to ensure the physical device delivering a feed belongs to its authorized user, Netarx analyzes device fingerprints, EXIF data, compression signatures, and location mismatches. For AI-generated voice communications from GANs or voice cloners it examines the micro-artifacts undetectable by the human ear, such as unnatural background silencing and electronic compression anomalies. If video is also included, it matches physical lip movements directly against incoming voice signals. For the facial image, it inspects individual video frames for anomalies in micro-expressions, unnatural blinking frequencies, lighting inconsistencies, or warping around hair lines. No single signal is decisive in indicating fraud. However, the collection and recognition of multiple questionable signals can swing the needle between genuine and fake in real time. However, detecting fraud in progress is only half the problem – the detection must also be relayed to the user in an understandable manner, also in real time. The traditional approach, autonomously blocking dangerous situations, is extreme and can cause more problems than it solves. To avoid this, Netarx has developed a color-coded real-time traffic analysis indicator displayed on screen during the communication. Green indicates that the human identity and the device concerned have been verified. Amber declares that the source is unknown, or that suspicious metadata anomalies have been detected. Red indicates that synthetic media or an active deepfake has been identified. (Internally, the company uses the term ‘flurp’ for this traffic light system. Flurp is defined in the Urban Dictionary as the noise a snail makes.) If amber turns to red during the conversation, it is probably time to disengage; but this is the user blocking the sender rather than the system arbitrarily blocking the process. NIK (the Netarx Identity Key) runs on Windows, macOS, Chrome, iOS and Android; and the company also publishes a database (the Impact Database) that catalogs real-world security incidents where human deception played a decisive role in the attack. This Netarx social engineering solution is an early example of technology supplanting human detection. It will not be the last, because social engineering is a growing vector and a serious threat to enterprise security. The entire security stack is bypassed if a single privileged employee invites a social engineering attacker across the MFA threshold. Related : ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing Related : UNC6692 Uses Email Bombing, Social Engineering to Deploy ‘Snow’ Malware Related : Cyber Insights 2026: Social Engineering Related : Going Into the Deep End: Social Engineering and the AI Flood

If human detection of social engineering cannot be assured, other means of detection must be employed – and technology is the pre-eminent option. The use of technology to detect both traditional and newer AI deep faked social engineering is increasing and improving. One example comes from Netarx . The firm’s solution applies a proprietary orchestration layer which it describes as an AI defense meta harness. The harness correlates individual signals detected by more than 40 AI models continuously scanning all communications while they are in progress, analyzing more than 1,000 digital and metadata signals for each interaction. For example, to ensure the physical device delivering a feed belongs to its authorized user, Netarx analyzes device fingerprints, EXIF data, compression signatures, and location mismatches. For AI-generated voice communications from GANs or voice cloners it examines the micro-artifacts undetectable by the human ear, such as unnatural background silencing and electronic compression anomalies. If video is also included, it matches physical lip movements directly against incoming voice signals. For the facial image, it inspects individual video frames for anomalies in micro-expressions, unnatural blinking frequencies, lighting inconsistencies, or warping around hair lines. No single signal is decisive in indicating fraud. However, the collection and recognition of multiple questionable signals can swing the needle between genuine and fake in real time. However, detecting fraud in progress is only half the problem – the detection must also be relayed to the user in an understandable manner, also in real time. The traditional approach, autonomously blocking dangerous situations, is extreme and can cause more problems than it solves. To avoid this, Netarx has developed a color-coded real-time traffic analysis indicator displayed on screen during the communication. Green indicates that the human identity and the device concerned have been verified. Amber declares that the source is unknown, or that suspicious metadata anomalies have been detected. Red indicates that synthetic media or an active deepfake has been identified. (Internally, the company uses the term ‘flurp’ for this traffic light system. Flurp is defined in the Urban Dictionary as the noise a snail makes.) If amber turns to red during the conversation, it is probably time to disengage; but this is the user blocking the sender rather than the system arbitrarily blocking the process. NIK (the Netarx Identity Key) runs on Windows, macOS, Chrome, iOS and Android; and the company also publishes a database (the Impact Database) that catalogs real-world security incidents where human deception played a decisive role in the attack. This Netarx social engineering solution is an early example of technology supplanting human detection. It will not be the last, because social engineering is a growing vector and a serious threat to enterprise security. The entire security stack is bypassed if a single privileged employee invites a social engineering attacker across the MFA threshold. Related : ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing Related : UNC6692 Uses Email Bombing, Social Engineering to Deploy ‘Snow’ Malware Related : Cyber Insights 2026: Social Engineering Related : Going Into the Deep End: Social Engineering and the AI Flood

The firm’s solution applies a proprietary orchestration layer which it describes as an AI defense meta harness. The harness correlates individual signals detected by more than 40 AI models continuously scanning all communications while they are in progress, analyzing more than 1,000 digital and metadata signals for each interaction. For example, to ensure the physical device delivering a feed belongs to its authorized user, Netarx analyzes device fingerprints, EXIF data, compression signatures, and location mismatches. For AI-generated voice communications from GANs or voice cloners it examines the micro-artifacts undetectable by the human ear, such as unnatural background silencing and electronic compression anomalies. If video is also included, it matches physical lip movements directly against incoming voice signals. For the facial image, it inspects individual video frames for anomalies in micro-expressions, unnatural blinking frequencies, lighting inconsistencies, or warping around hair lines. No single signal is decisive in indicating fraud. However, the collection and recognition of multiple questionable signals can swing the needle between genuine and fake in real time. However, detecting fraud in progress is only half the problem – the detection must also be relayed to the user in an understandable manner, also in real time. The traditional approach, autonomously blocking dangerous situations, is extreme and can cause more problems than it solves. To avoid this, Netarx has developed a color-coded real-time traffic analysis indicator displayed on screen during the communication. Green indicates that the human identity and the device concerned have been verified. Amber declares that the source is unknown, or that suspicious metadata anomalies have been detected. Red indicates that synthetic media or an active deepfake has been identified. (Internally, the company uses the term ‘flurp’ for this traffic light system. Flurp is defined in the Urban Dictionary as the noise a snail makes.) If amber turns to red during the conversation, it is probably time to disengage; but this is the user blocking the sender rather than the system arbitrarily blocking the process. NIK (the Netarx Identity Key) runs on Windows, macOS, Chrome, iOS and Android; and the company also publishes a database (the Impact Database) that catalogs real-world security incidents where human deception played a decisive role in the attack. This Netarx social engineering solution is an early example of technology supplanting human detection. It will not be the last, because social engineering is a growing vector and a serious threat to enterprise security. The entire security stack is bypassed if a single privileged employee invites a social engineering attacker across the MFA threshold. Related : ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing Related : UNC6692 Uses Email Bombing, Social Engineering to Deploy ‘Snow’ Malware Related : Cyber Insights 2026: Social Engineering Related : Going Into the Deep End: Social Engineering and the AI Flood

For example, to ensure the physical device delivering a feed belongs to its authorized user, Netarx analyzes device fingerprints, EXIF data, compression signatures, and location mismatches. For AI-generated voice communications from GANs or voice cloners it examines the micro-artifacts undetectable by the human ear, such as unnatural background silencing and electronic compression anomalies. If video is also included, it matches physical lip movements directly against incoming voice signals. For the facial image, it inspects individual video frames for anomalies in micro-expressions, unnatural blinking frequencies, lighting inconsistencies, or warping around hair lines. No single signal is decisive in indicating fraud. However, the collection and recognition of multiple questionable signals can swing the needle between genuine and fake in real time. However, detecting fraud in progress is only half the problem – the detection must also be relayed to the user in an understandable manner, also in real time. The traditional approach, autonomously blocking dangerous situations, is extreme and can cause more problems than it solves. To avoid this, Netarx has developed a color-coded real-time traffic analysis indicator displayed on screen during the communication. Green indicates that the human identity and the device concerned have been verified. Amber declares that the source is unknown, or that suspicious metadata anomalies have been detected. Red indicates that synthetic media or an active deepfake has been identified. (Internally, the company uses the term ‘flurp’ for this traffic light system. Flurp is defined in the Urban Dictionary as the noise a snail makes.) If amber turns to red during the conversation, it is probably time to disengage; but this is the user blocking the sender rather than the system arbitrarily blocking the process. NIK (the Netarx Identity Key) runs on Windows, macOS, Chrome, iOS and Android; and the company also publishes a database (the Impact Database) that catalogs real-world security incidents where human deception played a decisive role in the attack. This Netarx social engineering solution is an early example of technology supplanting human detection. It will not be the last, because social engineering is a growing vector and a serious threat to enterprise security. The entire security stack is bypassed if a single privileged employee invites a social engineering attacker across the MFA threshold. Related : ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing Related : UNC6692 Uses Email Bombing, Social Engineering to Deploy ‘Snow’ Malware Related : Cyber Insights 2026: Social Engineering Related : Going Into the Deep End: Social Engineering and the AI Flood

If video is also included, it matches physical lip movements directly against incoming voice signals. For the facial image, it inspects individual video frames for anomalies in micro-expressions, unnatural blinking frequencies, lighting inconsistencies, or warping around hair lines. No single signal is decisive in indicating fraud. However, the collection and recognition of multiple questionable signals can swing the needle between genuine and fake in real time. However, detecting fraud in progress is only half the problem – the detection must also be relayed to the user in an understandable manner, also in real time. The traditional approach, autonomously blocking dangerous situations, is extreme and can cause more problems than it solves. To avoid this, Netarx has developed a color-coded real-time traffic analysis indicator displayed on screen during the communication. Green indicates that the human identity and the device concerned have been verified. Amber declares that the source is unknown, or that suspicious metadata anomalies have been detected. Red indicates that synthetic media or an active deepfake has been identified. (Internally, the company uses the term ‘flurp’ for this traffic light system. Flurp is defined in the Urban Dictionary as the noise a snail makes.) If amber turns to red during the conversation, it is probably time to disengage; but this is the user blocking the sender rather than the system arbitrarily blocking the process. NIK (the Netarx Identity Key) runs on Windows, macOS, Chrome, iOS and Android; and the company also publishes a database (the Impact Database) that catalogs real-world security incidents where human deception played a decisive role in the attack. This Netarx social engineering solution is an early example of technology supplanting human detection. It will not be the last, because social engineering is a growing vector and a serious threat to enterprise security. The entire security stack is bypassed if a single privileged employee invites a social engineering attacker across the MFA threshold. Related : ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing Related : UNC6692 Uses Email Bombing, Social Engineering to Deploy ‘Snow’ Malware Related : Cyber Insights 2026: Social Engineering Related : Going Into the Deep End: Social Engineering and the AI Flood

No single signal is decisive in indicating fraud. However, the collection and recognition of multiple questionable signals can swing the needle between genuine and fake in real time. However, detecting fraud in progress is only half the problem – the detection must also be relayed to the user in an understandable manner, also in real time. The traditional approach, autonomously blocking dangerous situations, is extreme and can cause more problems than it solves. To avoid this, Netarx has developed a color-coded real-time traffic analysis indicator displayed on screen during the communication. Green indicates that the human identity and the device concerned have been verified. Amber declares that the source is unknown, or that suspicious metadata anomalies have been detected. Red indicates that synthetic media or an active deepfake has been identified. (Internally, the company uses the term ‘flurp’ for this traffic light system. Flurp is defined in the Urban Dictionary as the noise a snail makes.) If amber turns to red during the conversation, it is probably time to disengage; but this is the user blocking the sender rather than the system arbitrarily blocking the process. NIK (the Netarx Identity Key) runs on Windows, macOS, Chrome, iOS and Android; and the company also publishes a database (the Impact Database) that catalogs real-world security incidents where human deception played a decisive role in the attack. This Netarx social engineering solution is an early example of technology supplanting human detection. It will not be the last, because social engineering is a growing vector and a serious threat to enterprise security. The entire security stack is bypassed if a single privileged employee invites a social engineering attacker across the MFA threshold. Related : ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing Related : UNC6692 Uses Email Bombing, Social Engineering to Deploy ‘Snow’ Malware Related : Cyber Insights 2026: Social Engineering Related : Going Into the Deep End: Social Engineering and the AI Flood

To avoid this, Netarx has developed a color-coded real-time traffic analysis indicator displayed on screen during the communication. Green indicates that the human identity and the device concerned have been verified. Amber declares that the source is unknown, or that suspicious metadata anomalies have been detected. Red indicates that synthetic media or an active deepfake has been identified. (Internally, the company uses the term ‘flurp’ for this traffic light system. Flurp is defined in the Urban Dictionary as the noise a snail makes.) If amber turns to red during the conversation, it is probably time to disengage; but this is the user blocking the sender rather than the system arbitrarily blocking the process. NIK (the Netarx Identity Key) runs on Windows, macOS, Chrome, iOS and Android; and the company also publishes a database (the Impact Database) that catalogs real-world security incidents where human deception played a decisive role in the attack. This Netarx social engineering solution is an early example of technology supplanting human detection. It will not be the last, because social engineering is a growing vector and a serious threat to enterprise security. The entire security stack is bypassed if a single privileged employee invites a social engineering attacker across the MFA threshold. Related : ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing Related : UNC6692 Uses Email Bombing, Social Engineering to Deploy ‘Snow’ Malware Related : Cyber Insights 2026: Social Engineering Related : Going Into the Deep End: Social Engineering and the AI Flood

NIK (the Netarx Identity Key) runs on Windows, macOS, Chrome, iOS and Android; and the company also publishes a database (the Impact Database) that catalogs real-world security incidents where human deception played a decisive role in the attack. This Netarx social engineering solution is an early example of technology supplanting human detection. It will not be the last, because social engineering is a growing vector and a serious threat to enterprise security. The entire security stack is bypassed if a single privileged employee invites a social engineering attacker across the MFA threshold. Related : ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing Related : UNC6692 Uses Email Bombing, Social Engineering to Deploy ‘Snow’ Malware Related : Cyber Insights 2026: Social Engineering Related : Going Into the Deep End: Social Engineering and the AI Flood

This Netarx social engineering solution is an early example of technology supplanting human detection. It will not be the last, because social engineering is a growing vector and a serious threat to enterprise security. The entire security stack is bypassed if a single privileged employee invites a social engineering attacker across the MFA threshold. Related : ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing Related : UNC6692 Uses Email Bombing, Social Engineering to Deploy ‘Snow’ Malware Related : Cyber Insights 2026: Social Engineering Related : Going Into the Deep End: Social Engineering and the AI Flood

Related : ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing Related : UNC6692 Uses Email Bombing, Social Engineering to Deploy ‘Snow’ Malware Related : Cyber Insights 2026: Social Engineering Related : Going Into the Deep End: Social Engineering and the AI Flood

Related : UNC6692 Uses Email Bombing, Social Engineering to Deploy ‘Snow’ Malware Related : Cyber Insights 2026: Social Engineering Related : Going Into the Deep End: Social Engineering and the AI Flood

Related : Cyber Insights 2026: Social Engineering Related : Going Into the Deep End: Social Engineering and the AI Flood

Related : Going Into the Deep End: Social Engineering and the AI Flood

Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines.

More from Kevin Townsend

Senate Passes Bipartisan Bill to Strengthen Healthcare Cybersecurity

doxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures

macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor

Zero Trust Creator Says Model Holds Firm Against AI-Assisted Attacks

Enterprises Struggle to Prepare for AI and Quantum Threats, PwC Says

Hacker Conversations: Rob Juncker, a Knock at the Door and a Moral Compass

DARPA Selects Xint to Use AI in Securing Military Messaging Apps

Rig Security Emerges From Stealth With $12M to Tackle Agentic AI Identity Risks

Apple to Tighten Full Disk Access Controls in macOS Amid AI Risks

Cybersecurity M&A Roundup: 39 Deals Announced in September 2026

Long-Running NPM Malware Campaign Accumulates 40,000 Downloads

8.8 Million Impacted by Data Breach at Denmark’s Central Person Register

Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports

Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws

250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms

Exploitation Hits Rejetto HFS Vulnerability Discovered by AI

Flipboard Whatsapp Whatsapp Email

Extracted Entities

APT Groups (1)

Domains (1)

Malware (1)

Tools (1)