Securityweek Social Engineering Attacks Exploit Help Desks Amid AI Advances
Article Content
- •Social engineering remains a primary attack vector, with significant breaches reported.
- •MGM Resorts lost $100 million due to vishing attacks in 2023.
- •Recent incidents show attackers exploiting help desks using AI deep fakes.
Recent social engineering attacks have targeted help desk operations, leading to significant breaches. Notable incidents include the Las Vegas casino breaches in 2023, where attackers used vishing to manipulate staff into resetting passwords, resulting in a $100 million loss for MGM Resorts. In August 2026, the Brinks leak involved ShinyHunters, who exploited voice phishing to gain access to sensitive data, compromising nearly five million customer records. The increasing sophistication of these attacks, particularly through AI deep fakes, highlights the inadequacy of traditional user awareness training. Companies are now turning to technology solutions, such as those from Netarx, which utilize AI to detect anomalies in communications. This shift underscores the urgent need for effective detection methods to combat evolving social engineering tactics.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track UNC6692, SNOW and Brinks in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What types of attacks are being reported?
How are companies responding to these threats?
What are the implications of AI in these attacks?
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…