Social Engineering AI Agents: The New BEC for 2026

As companies increasingly grant AI agents authority over business systems, a new threat has emerged that allows attackers to manipulate these agents like they would a human victim of Business Email Compromise (BEC). This development should prompt organizations to rethink their training on BEC attacks and focus on securing their AI-powered infrastructure.

The problem arises from the fact that AI agents can be tricked into taking authorized actions by attackers who inject malicious content or prompts. This is made possible by the way large language models (LLMs) process instructions, which can be manipulated by embedding malicious code within the input data. In a BEC-like scenario, an attacker can convince an AI agent to change vendor information or redirect payments, all without the need for human interaction.

The implications of this threat are significant, given that third-party involvement in breaches has increased by 60% year-over-year, according to Verizon’s 2026 Data Breach Investigations Report. Moreover, BEC remains a costly enterprise threat, with reported losses of over $3 billion in 2025 alone. While educating employees on social engineering is still crucial, it is no longer enough to safeguard against this new threat.

John Wilson, senior fellow of threat research at Fortra, explains that AI agents are primarily socially engineered through prompt injections, which can be as simple as embedding malicious instructions within the input data. This allows attackers to subvert even hardened systems, as seen in cases where job applicants’ résumés contain hidden instructions that alter the hiring process.

The comparison between social engineering humans and AI agents breaks down when it comes to emotional manipulation. Since AI agents are not sentient, they do not experience emotions like fear or urgency, which human attackers often exploit. Instead, equivalent attacks target how LLMs interpret instructions, establish trust, and distinguish trusted commands from untrusted instructions.

The use of indirect prompt injections is also on the rise, with Palo Alto Networks’ Unit 42 identifying 22 distinct techniques used by attackers to create payloads. Check Point Research has similarly noted a surge in this type of attack, which allows attackers to manipulate AI agents without direct interaction.

To mitigate this threat, organizations must shift their focus from training employees on BEC attacks to securing their AI-powered infrastructure. This includes hardening systems against prompt injection and ensuring that LLMs are trained to distinguish between trusted and untrusted instructions. By taking these steps, companies can prevent attackers from manipulating their AI agents and minimize the risk of costly breaches.

In conclusion, the emergence of social engineering AI agents as a new threat should prompt organizations to rethink their cybersecurity strategies. While employee education on BEC attacks is still essential, it must be complemented by measures to secure AI-powered infrastructure and protect against prompt injection attacks. By doing so, companies can safeguard themselves against this evolving threat landscape.


Source: Dark Reading — 2026-10-09