For years, organizational security training has taught the same basic principle: if a message feels suspicious, verify it through another channel. If an email requests an urgent payment, call the sender. If a Teams message seems unusual, check it by email or by phone.
The advice has been sound because it has relied on a simple assumption: the attacker controls only one communication channel. In other words, if an email is forged, a phone call will expose the fraud. If a text message is suspicious, the real person can confirm the matter through another channel.
However, this assumption no longer holds as well as it used to, or at least it soon may not.
Generative AI, deepfake technologies, and the vast amount of publicly available personal data are changing the nature of social engineering. Instead of isolated phishing messages, attackers are increasingly building entire “credibility ecosystems” in which several communication channels connected to the scam support one another. Researchers describe this development as a new phase of AI-assisted social engineering, where realism, personalization, and automation combine in unprecedented ways (Gonzaga et al., 2026).
Traditional phishing attacks have often been easy to identify. The message contains spelling mistakes, the sender’s address looks suspicious, or the content does not fit the recipient’s duties or the recipient’s work or personal context at all.
Generative AI has changed this situation. An attacker can easily collect information about the target from LinkedIn, company websites, conference appearances, social media posts, and even public videos. Based on this information, messages can be created that do not even remotely resemble mass scams but instead appear to be genuine work-related communications.
The most significant change is not the quality of a single message or the improvement of that quality. The real change comes from the fact that the story created by the fraudster can be built across several channels at once as a complete narrative chain.
Imagine a situation in which a project manager receives an email from a long-term supplier. The message relates to an ongoing project and contains a completely plausible request. A few hours later, a message about the same matter appears in Teams. The following day, a short video meeting is held, showing someone who appears to be the supplier’s contact person. Everything seems normal. No single event necessarily raises suspicion, but together they form a convincing whole. This is precisely the essence of multichannel social engineering.
In such a situation, the human mind does not necessarily assess trustworthiness in separate parts. Instead, it forms an overall impression from several simultaneous signals. When the same message is repeated in email, instant messaging, a phone call, and even a video conversation, it begins to feel genuine. In other words, in this form of scam, people do not always examine each contact separately but assess the credibility of their shared story. Cybercriminals understand this well. For example, in romance scams, video calls in which the other party is an AI-generated fake persona are already used regularly.
CrowdStrike’s 2025 report found that generative AI is increasingly being used to build convincing social engineering campaigns. According to the report, attackers use AI, for example, to create fictional LinkedIn profiles, deepfake videos, and content that credibly imitates corporate communication. The technology makes it possible to build an entire digital identity with far less effort than before—in other words, quickly and cheaply.
At the same time, this means that organizations’ traditional verification mechanisms and security technologies are losing effectiveness. Previously, an employee might have thought they could verify a suspicious email through another channel. In the future, that second channel may also be part of the same attack.
This is where the strategic strength of multichannel attacks lies. They do not merely seek to deceive technical systems; they seek to manipulate how trust is formed between the attacker and the target. When an attacker controls enough communication channels, they can construct an alternative reality that appears genuine to the target.
The effects of multichannel social engineering extend far beyond traditional phishing. In finance, this may mean convincing payment fraud; in human resources, it may involve harvesting employee data; while in consulting and expert organizations, the targets may be confidential client projects or strategic plans. The more work is based on digital communication and trust, the more attractive the target becomes in the eyes of an attacker.
At the same time, the time span of attacks is becoming longer. A traditional phishing campaign might have lasted a few hours or days. Future operations may continue for weeks or months, with the attacker gradually building trust before the actual strike. In this sense, the most advanced social engineering begins to resemble an intelligence operation more than traditional cybercrime.
It is therefore possible that the most significant social engineering threats of the coming years will not be new technical vulnerabilities, but the systematic exploitation of human trust mechanisms. AI gives attackers more powerful tools than before to exploit people’s personality traits and their weaknesses.
Organizations should therefore begin to move away from the idea that the authenticity of a message can be verified simply by switching communication channels. In the future, it will be more essential to understand that several channels can be manipulated simultaneously. When an attacker can produce credible content for email, instant messages, voice, and video, verifying trust requires new operating models and clear guidance on how to confirm the accuracy of messages (Pedersen et al., 2025).
Multichannel social engineering is no longer a future threat scenario. It is the next logical step in the evolution of social engineering. Technology makes it cheaper, faster, and easier to scale than ever before. That is why it is worth paying attention to it now, before it becomes the new normal.
At Context&, we specialise in applying Microsoft technologies in customer environments, and we also support a human-centred approach through training and the development of operating models. Contact us to find new tactics to protect you organisation
This blog is the third part of a 4-piece blog series on AI assisted frauds and how organizations can protect themselves.
You can read the first part here: Social Engineering Fraud - Not only a private matter
And second part here: What is hyper‑personalised, AI‑driven phishing and how to prevent it?