Modern call centers use a mix of human agents and AI. Attackers often need to navigate through both, or exploit the handoff between them. These scenarios reflect real-world attack patterns.
Scenario: The AI-to-Human Handoff Exploit
An attacker manipulates the AI agent to set up a favorable context before being transferred to a human.
Attacker
I need to speak with a human agent about a complex billing issue.
Requesting transfer — the real attack is what happens before transfer
Scenario: Multi-Channel Coordinated Attack
An attacker uses email, phone, and the AI chatbot simultaneously to create a convincing narrative.
Attacker
(Sends spoofed email to target company from '[email protected]') 'I'll be calling in about account #5521. Please assist my assistant with the wire transfer as discussed in our meeting.'
Step 1: Plant email evidence before the phone call
Attack Pattern: The Escalation Ladder
Most successful social engineering attacks follow a predictable escalation pattern. Understanding these steps helps defenders recognize an attack in progress — not just after it succeeds.
1
Reconnaissance
Gather info from social media, LinkedIn, data breaches, company website. Learn names, titles, processes.
2
Pretext Development
Build a believable story. Get a spoofed phone number, prepare PII, research the target's systems.
3
Initial Contact
Establish rapport. Sound normal, professional, credible. Make a small, reasonable request.
4
Trust Building
Demonstrate knowledge. Reference real details. Be patient. Build comfort over minutes or multiple calls.
5
The Ask
Once trust is established, make the actual request. Account access, wire transfer, password reset, data extraction.
6
Cover Tracks
Ensure the target feels good about helping. Reduce likelihood of them reporting the interaction as suspicious.
Check Your Understanding
Question 1 / 3
Why is a multi-channel coordinated attack (phone + email) more convincing than a single-channel attack?