Researchers and security practitioners warned that attackers are using widely available AI tools to make social engineering more personalized and scalable. McAfee found that free vision models could infer where travel photos were taken with high accuracy, with Gemma3 27B identifying the correct city and country in 87% of tests and Qwen3 VL 30B reaching 91%, giving scammers enough location context to craft convincing phishing lures from social media posts. Separate reporting also described how public profiles, posted media, and voice samples can be harvested to build believable impersonation campaigns over phone and audio channels.
New research on AI voice phishing found that the effectiveness of scam calls depends more on the script and persuasiveness than on whether a voice sounds perfectly human. In a study of 4,100 U.S. adults, suspicion of AI-generated voices was common but detection accuracy was poor, and familiarity with AI tools did not significantly improve performance; across five scam scenarios, 16.5% of participants said they would comply or might comply, while a fake-relative-in-trouble scenario reached 36.1%. The findings indicate that defenders should emphasize out-of-band verification and stronger identity-proofing rather than relying on users to spot synthetic voice artifacts or other obvious signs of AI use.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Research discussed by Help Net Security found that people are generally poor at distinguishing AI-generated voices from human callers and that familiarity with AI tools does not significantly improve detection. The study of 4,100 U.S. adults concluded that caller persuasiveness was a stronger predictor of scam compliance than whether a voice sounded human.
An OSINT Team article described the growing threat of AI-powered social engineering using cloned voices, deepfake-style impersonation, public profile scraping, and automated outreach. It emphasized that attackers can scale personalized scams by exploiting familiarity and emotional urgency rather than relying on perfect realism.
McAfee researchers warned that freely available AI vision models can infer where photos posted to social media were taken, enabling more targeted social engineering. In McAfee testing, models identified travel photo locations with high accuracy, reducing the reconnaissance effort needed to personalize phishing lures.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourceosintteam.blog
Open sourceblog.knowbe4.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.