Social Engineering AI Agents: The New BEC for 2026

Cybersecurity threats just got a whole lot more sophisticated – and insidious. As companies increasingly rely on AI agents to interact with business systems, attackers have found a new way to manipulate them into taking authorized actions, essentially turning these digital assistants into unwitting accomplices in cybercrimes.

The concept is eerily similar to Business Email Compromise (BEC), where an attacker tricks an employee into divulging sensitive information or performing certain actions. But now, instead of targeting humans, attackers are exploiting vulnerabilities in AI agents, which can be tricked into redirecting payments, changing vendor information, or even leaking sensitive data.

The problem lies in the way these AI agents are designed to process instructions and interact with their environment. They can struggle to distinguish between legitimate commands and malicious prompts, making them susceptible to “socially engineering” through prompt injections – essentially injecting malicious content that is fed into a third-party AI tool. This allows attackers to exploit the agent’s trusted access to sensitive systems without having to directly compromise an employee.

The implications are far-reaching, particularly in light of recent statistics. According to Verizon’s 2026 Data Breach Investigations Report, third parties were involved in 48% of breaches, a staggering increase from previous years. Meanwhile, BEC remains one of the costliest enterprise threats, with the FBI’s Internet Crime Complaint Center recording approximately $3 billion in reported losses last year.

While educating employees on social engineering and BEC is still crucial, it’s no longer enough to simply teach humans how to avoid these types of attacks. As AI agents become increasingly integral to business operations, organizations must also focus on securing their digital assistants from manipulation.

“Ai agents can struggle to distinguish between instructions and the data they are asked to process, allowing an attacker to embed malicious instructions within that data,” explains John Wilson, senior fellow of threat research at Fortra. “This is particularly concerning in cases where AI agents have privileged access to sensitive systems.”

To mitigate this risk, organizations should prioritize hardening their AI agents against prompt injection attacks and ensure they can distinguish between trusted and untrusted instructions. This may involve implementing additional security controls, conducting regular security audits, or even retraining employees on how to interact with AI-powered systems.

Ultimately, the rise of social engineering AI agents serves as a stark reminder that cybersecurity threats are constantly evolving – and it’s up to organizations to stay ahead of the curve. By acknowledging the new risks and vulnerabilities associated with AI-powered systems, we can take proactive steps to safeguard our digital assets and prevent these sophisticated attacks from taking hold.


Source: Dark Reading — 2026-10-09