The 2026 InfoSec Playbook · Scenario playbooks

#14.9 Deepfake and AI-Enabled Social Engineering

Playbook ID: PB-DEEPFAKE | Default severity: SEV-3 (SEV-2 once a payment has been sent or a credential, MFA re-enrolment or access grant has been given up; SEV-1 if the target held a privileged role or synthetic media of a named executive is circulating outside the company) | Owner: Incident Commander

#When to run this

Open this playbook on: an employee reporting a call, voicemail, video meeting or voice note from an "executive" pressing for a payment, a credential, a gift-card purchase or an urgent exception; a service-desk contact requesting a password reset or MFA re-enrolment where the caller's identity rests on their voice, or a request deliberately split across two contacts — the CISA AA23-320A pattern; an approach that arrives on a channel the real person never uses (personal WhatsApp, a new mobile number, a meeting invite from outside the tenant); a participant on a video call whose audio, lip sync or lighting is wrong, or who will only appear on camera and never type; a synthetic audio or video clip of a named executive circulating externally; or a phishing wave with unusually fluent, well-targeted copy at volume and almost no shared indicators.

Not this playbook: a compromised mailbox sending real mail from a real account (14.2 PB-BEC — and if the deepfake succeeded and money left, run 14.2's money track in parallel from minute one); a completed identity-provider or privileged-credential compromise (14.4 PB-IDP); an attack against your own AI systems, agents or model supply chain (14.11 PB-AISYS); a genuine employee abusing genuine access (14.6 PB-INSIDER). The design of help-desk identity verification, and the phishing-resistant MFA program that makes a stolen reset worthless, belong to Chapter 4. Executive media exposure and workforce training sit in Chapter 19.

#What you are dealing with

Someone will call your accounts payable clerk in your CFO's voice. Not a robotic approximation — the voice, with the pauses and the regional vowels, on a Tuesday afternoon, about an invoice that genuinely exists. The technology is a commodity; the target is not the technology, it is the moment where one junior person weighs their own doubt against apparent authority and picks authority.

The reference case is Arup's Hong Kong office: an employee received a phishing email impersonating the UK-based CFO, was sceptical, and had that scepticism dismantled by a multi-person video conference in which every other participant was AI-generated. About US$25.6 million left across 15 wire transfers in a single day (CNN). Three other named attempts failed, and how they failed is the whole of this playbook. WPP's CEO was impersonated through a WhatsApp account, a Teams meeting, a voice clone and stitched YouTube footage — stopped by an employee who did not buy it (OECD AI Incidents). A Ferrari executive challenged a voice clone of the CEO with a shared-secret question — a book the real CEO had recently recommended — that the clone could not answer (AI Incident Database). A LastPass employee flagged a voice clone of their CEO because the channel was wrong — WhatsApp, outside normal business communication — not because the audio sounded off (LastPass). Zero of those three were stopped by detection technology. Three of three were stopped by a human process check.

This is not a niche. Voice phishing was the #2 initial infection vector in 2025, at 11% of all Mandiant investigations (M-Trends 2026), and DBIR 2026 finds voice and text phishing convert better than email (Help Net Security). IC3 added "AI-related" as a formal crime descriptor for the first time in its 2025 report: 22,000+ complaints and roughly $900 million in losses (FBI). The written variant scaled too — Hoxhunt found AI-generated spear phishing went from 31% less effective than elite human red-teamers in 2023 to 24% more effective by March 2025 (Hoxhunt), and Microsoft assesses AI can make some phishing operations up to 50× more profitable (MDDR 2025). Keep the calibration honest, though, because it changes what you fund: Mandiant's conclusion from over 500,000 hours of 2025 response work is that 2025 was not the year breaches directly resulted from AI — most intrusions still stem from human and systemic failures, and Anthropic's mapping of banned malicious accounts found AI-assisted phishing actually fell 8.6% while post-compromise use rose (Anthropic). AI is a force multiplier on social engineering you already faced, not a new kill chain.

Which brings us to the mistake teams make, and it arrives as a purchase order. The instinct is to buy a synthetic-media detector and declare the problem handled. But that enters your people into a perception contest against a generator that improves monthly, with a stressed clerk as the classifier. Do not enter that contest. Actionable takeaway: stop trying to detect the fake and start verifying the request — a callback on a number from your own directory, a shared-secret challenge, dual authorization. The control is procedural, it is nearly free, and it works against a perfect fake.

#Roles for this incident

RoleResponsibility in this scenario
Incident CommanderOwns the "is this real?" determination and the tip-off timing; decides workforce broadcast; runs no queries.
Operations LeadPreserves the media and platform records; runs the identity and campaign scoping; executes any revocation.
Communications LeadStands up the out-of-band channel; runs the workforce warning and, if media is public, the external statement.
Finance Lead (Controller/Treasury)Payment freeze, beneficiary screening, bank recall — the money track in 14.2 Phase 2A.
Legal LiaisonAttaches privilege; approves law-enforcement filing and any external statement; owns the notification determination.
Impersonated Party (the executive or employee whose likeness was used)Gives ground truth on the alleged request; approves use of their name in the warning; is a witness, never a suspect.
ScribeMinute-by-minute timeline, including the moment the request was received and the moment it was doubted.
Executive SponsorLoss disclosure, insurer notification, materiality escalation, and the authority behind the refusal rule.

#Phase 1 — Detection and Triage

The first fifteen minutes answer one question — did the request succeed — and preserve one artefact that has a short and unforgiving life. Voicemail boxes overwrite. Meeting chats fall off retention. People delete embarrassing messages.

#ActionWhoDone whenEvidence to capture
1.1Declare; open the timeline; Legal attaches privilege before the first substantive assessmentIC / LegalIncident ID issuedDeclaration time (UTC, ISO 8601), declarer, reporter
1.2Ask the recipient, by voice, exactly four things: did money move or get queued; did you give a credential, code or approval; did you grant access to anything; did you install anythingOps LeadAll four answered yes/no/unsureVerbatim answers, time asked, who asked
1.3Tell the recipient: do not delete anything, do not reply, do not call the number back. Their instinct will be to clean upOps LeadInstruction acknowledgedInstruction time and acknowledgement
1.4Preserve the media in its original form — the voicemail audio file, the video recording, the chat export. Copy the file; do not forward it through a channel that re-encodes itOps LeadOriginal file in the evidence store with a hashSHA-256, file name, source path, collector, collection time
1.5Preserve the platform record separately from the media: meeting attendance report, join and leave times, participant identifiers, tenant of origin, chat transcript, call detail recordsOps LeadRecords exported for every session in the windowMeeting/call IDs, participant list, join IPs where available, export query and time
1.6Place a Purview eDiscovery hold on the recipient, the impersonated party and any finance approver — this covers the mailboxes and sites backing Teams and M365 GroupsOps LeadHold active on all custodiansCase ID, hold policy ID, custodian list, timestamp
1.7Record every attacker-controlled identifier: calling number and display name, WhatsApp/Signal handle, sender address and full headers, meeting organiser identity, external tenant ID, any URL or attachmentOps LeadIdentifier list completeIdentifiers, where each was observed, screenshots with visible timestamps
1.8Run the verification callback. Reach the impersonated party on the number in the corporate directory of record — never a number supplied in the approach — and ask whether they made the requestOps LeadImpersonated party confirms or denies, by voiceNumber called and its source, time, who answered, exact words of the denial
1.9Ask the impersonated party's assistant and direct reports whether they received the same approach; check whether the lure went to anyone elseOps LeadSecond-target list produced or ruled outNames contacted, responses, times
1.10If a service-desk contact is involved, pull the ticket, the call recording and the agent's notes before the agent goes off shiftOps LeadTicket and recording preservedTicket ID, agent, verification steps the agent performed, recording hash
1.11Set severity and confirm which parallel playbook is now running: 14.2 for money, 14.4 for a granted resetICSeverity recorded, parallel playbook declaredSeverity, rationale, time, named leads for each track
PowerShell
# Pull the audit record around the approach for the targeted account and the impersonated party.
# Search broadly first, then filter the returned records - but the search is only broad if
# -SessionCommand ReturnLargeSet is set. Without it the cmdlet returns at most 100 records
# however high you set -ResultSize, and filtering a truncated set is how you conclude that
# nothing happened. ReturnLargeSet comes back unsorted; re-run it with the SAME -SessionId
# until it returns zero rows, then sort what you have. Operation strings vary by tenant and by
# how the action was performed - read them out of your own results, do not assume them.
Search-UnifiedAuditLog -StartDate <MM/DD/YYYY> -EndDate <MM/DD/YYYY> `
  -UserIds <target-upn>,<impersonated-upn> `
  -SessionCommand ReturnLargeSet -SessionId <id> -ResultSize 1000

# Risk state on both accounts, in case the social engineering rode on an existing compromise.
Connect-MgGraph -Scopes "IdentityRiskEvent.Read.All","IdentityRiskyUser.ReadWrite.All"
Get-MgRiskDetection -Filter "RiskType eq 'anonymizedIPAddress'" |
  Format-Table UserDisplayName, RiskType, RiskLevel, DetectedDateTime

Search-UnifiedAuditLog syntax · ID Protection via Graph · eDiscovery holds

#Phase 2 — Containment

Containment here is unusual: there may be no malware, no beachhead and nothing to isolate. What you are containing is an instruction in flight and an adversary's ability to place the next call.

#ActionWhoDone whenEvidence to capture
2.1If funds moved or are queued, launch 14.2 Phase 2A now, in parallel — bank fraud desk by voice, recall request, IC3 filing. Do not wait for this playbook to finishFinance LeadBank case reference and IC3 complaint number issuedCall time, bank contact, case reference, complaint number
2.2Freeze the specific instruction: hold the payment, the vendor-master change, the payroll bank-detail change or the account modification that was requestedFinance Lead / Ops LeadHold confirmed by the system ownerHold ticket, systems affected, approver, time
2.3If a credential, MFA re-enrolment or access grant was given up: revoke sessions and reset in the same action, then hand to 14.4Ops LeadRevoke-MgUserSignInSession succeeds for the accountCmdlet output, timestamp, operator
2.4Freeze service-desk-initiated password resets and MFA re-enrolment for the privileged cohort tenant-wide until verification is upgraded to a scripted out-of-band checkICFreeze in force, service desk briefed by voiceFreeze scope, start time, authorizing role, exception path
2.5Brief the service desk on the specific pretext, the caller identifiers, and the split-request pattern — the same account approached twice, by two agentsOps LeadEvery agent on shift briefed and the briefing left for the next shiftBriefing content, time, agents briefed
2.6Warn the workforce through a channel the impersonated party is confirmed to control, naming the pretext and the channel — this tips off the adversary and is worth itComms LeadBroadcast sent, read receipts or acknowledgement trackedMessage text, channel, send time, approver
2.7Block the calling number, handle and sender domain at the telephony, messaging and mail gateway. Expect low yield; do it anyway and do not call it containmentOps LeadBlocks applied and confirmed activeIndicators blocked, systems, time
2.8For an AI-generated phishing wave, quarantine by campaign shape — same landing infrastructure, same send window, same targeted role — not by literal indicator matchOps LeadCampaign clustered and quarantinedCluster criteria, message count, recipients, quarantine action
2.9Preserve copies of every lure before purging it from mailboxes. Purging first destroys the evidence counsel and your insurer will ask forOps LeadExport complete and hashed, then purge executedExport manifest, hashes, purge command and time
2.10Notify the cyber insurer; social-engineering-fraud cover is commonly conditioned on prompt noticeExec SponsorClaim reference issuedNotification time, policy and claim reference

#Phase 3 — Eradication

There is often no implant to remove. What you eradicate is the adversary's information advantage and the process gap that let a voice function as an authorization.

#ActionWhoDone whenEvidence to capture
3.1Establish what source material the impersonation used: earnings calls, conference video, podcast appearances, published org charts, the executive's public social profilesComms LeadExposure inventory produced for the impersonated partySource list with URLs, dates, retrieval time
3.2Pivot on every attacker identifier from 1.7 across mail, telephony, messaging and sign-in logs, tenant-wideOps LeadFull target list produced or the single-target finding evidencedQuery, time range, matches, accounts touched
3.3Review every vendor-master, payroll and beneficiary change made in the approach window, whoever approved itFinance LeadEvery change in window reviewed and attributedChange records, approvers, verification evidence per change
3.4Review every service-desk password reset and MFA re-enrolment in the same window for the split-request patternOps LeadAll tickets in window reviewedTicket IDs, requester, agent, verification performed
3.5If any access was granted, enumerate OAuth consents and remove unexpected grants — a reset does not revoke a consented appOps LeadNo unexpected grants remainApp name, OAuthAppId, consent type, scopes removed
3.6Search the audit log for Consent to application carrying IsAdminConsent: True. Latency runs 30 minutes to 24 hours — run it twice, an hour apartOps LeadTwo runs, second returning nothing newSearch parameters, both run times, results
3.7Remove remaining lure copies from mailboxes and shared channels, after the 2.9 exportOps LeadSearch returns no remaining copiesSearch query, items removed, count
3.8Close the gap that let the request through: the missing callback, the single-approver threshold, the service-desk script that accepted a voice as identity proofICNamed owner and date on each gapGap register, owner, target date
PowerShell
# Tenant-wide consent inventory - Microsoft's documented method.
.\Get-AzureADPSPermissions.ps1 | Export-csv -Path "Permissions.csv" -NoTypeInformation

# Revoke what the inventory turns up - Microsoft's two documented revocation cmdlets.
Remove-MgOauth2PermissionGrant                  # revokes a delegated consent grant
Remove-MgServicePrincipalAppRoleAssignment      # revokes an application-permission role assignment

Detect and remediate illicit consent grants

Blocklisting is close to worthless against a caller who buys a new number for nine dollars, and indicator-matching is close to worthless against generated phishing text that is unique per recipient. Takeaway: hunt on the campaign's shape — the targeted role, the send window, the landing infrastructure, the pretext — and put the caller identifiers in the hunt query, not just the block list.

#Phase 4 — Recovery

#ActionWhoDone whenEvidence to capture
4.1Release the payment hold under joint Incident Commander and Finance Lead approval; retain the beneficiary holdIC / FinancePayments resumed, beneficiary hold retainedRelease approval, retained holds, time
4.2Restore any account access that was suspended; confirm the real user has service, by voiceOps LeadUser confirms access out of bandRestore time, first successful sign-in, confirmation call
4.3Publish or re-publish the verification protocol: callback to a directory-of-record number, on every payment, banking, credential or access request arriving by voice, video or messageFinance / OpsProtocol issued, acknowledged by finance, AP, treasury, HR and the service deskSigned procedure, distribution list, acknowledgement date
4.4Issue a shared-secret challenge to executives and their frequent counterparts — a phrase or fact not present in any public source, rotated on a stated schedule, never sent by emailComms LeadChallenge distributed out of band and rehearsed onceDistribution method, rotation schedule, rehearsal record
4.5Set dual authorization above a stated threshold and a cooling-off period on beneficiary bank changesFinance LeadControl live in the AP systemThreshold, approver roles, system configuration record
4.6Upgrade the service-desk identity-verification runbook: out-of-band callback, a challenge not derivable from public sources, and a mandatory second-agent check on any privileged-account resetOps LeadRunbook published, agents trained, one live test passedRunbook version, training record, test result
4.7Move the impersonated party, the target, and the whole finance and privileged cohort to phishing-resistant MFA (FIDO2/WebAuthn or PKI)Ops LeadCohort enrolled, legacy methods removed for those accountsEnrolment report, date legacy methods disabled
4.8Tell the workforce, by name and with credit, that the report was correct behavior — including when the report turned out to be a false alarmComms LeadMessage sentMessage text, send date

Phishing-resistant MFA blocks over 99% of identity-based attacks even when the attacker already holds a valid username and password (MDDR 2025). It does not stop a deepfake call, but it makes the credential the caller is fishing for far less useful. Number matching is a push-fatigue mitigation and CISA is explicit that it is not phishing-resistant MFA (CISA). Actionable takeaway: step 4.8 is not sentiment. If reporting a suspected fake costs an employee an awkward conversation with an executive, the next one will not report. Make the report cost nothing, publicly, once.

#Phase 5 — Post-Incident

#ActionWhoDone whenEvidence to capture
5.1Blameless review within 10 business days with the recipient, the service-desk agent and the impersonated party present. The person who was targeted is a witness, not a defendantICFindings logged with owners and datesFindings register
5.2Close the notification determination with Legal, including a documented "no notification required"Legal LiaisonDetermination signed and filedMemo, decision date, reasoning
5.3Assess executive media exposure and agree what the impersonated party will and will not publish going forwardComms LeadExposure decision recorded with the executive's agreementDecision memo, review date
5.4Ship detections for the campaign shape: new external tenant meeting invites to finance roles, first-contact-from-unknown-number to payment approvers, bulk send patterns with unique bodiesDetection engineeringRules in production with a passing validation testRule IDs, ATT&CK mapping, last validated date
5.5Add this scenario to the exercise calendar as a tabletop card, including the version where the callback reaches an executive who is genuinely unreachableICExercise scheduled with a date and a facilitatorExercise card, date, participants
5.6Record in the playbook header: the directory of record used for callbacks, who owns it, and when its numbers were last verifiedOps LeadAll three recorded and datedContact source, owner, verification date

#Decision points

#Communications and notification triggers

The deepfake itself almost never starts a regulatory clock. What starts one is what the social engineering obtained. If the approach yielded access to personal data, GDPR Article 33's 72 hours from awareness is running, and the Scribe's timeline is your only evidence of when awareness arose. If it yielded a credential into a regulated service, the NIS2 and DORA clocks may run on the downstream compromise rather than on the call. If the loss could be material to a public filer, the Executive Sponsor opens the SEC materiality assessment on day one. The full matrix is Chapter 15 — do not reconstruct it under pressure.

Two things belong here rather than in Chapter 15. File with IC3 regardless of loss amount when funds moved — it is the entry point to the Recovery Asset Team, not a regulatory notification, and 14.2 Phase 2A owns the mechanics. And notify counterparties by telephone on numbers you already held, never by replying to any thread the approach touched.

#Automation notes

Automate the preservation, never the determination. The moment a suspected-impersonation report opens, a playbook can safely and reversibly: pull the meeting and call records for the window, snapshot the voicemail or recording and hash it, place the eDiscovery hold, export sign-in and audit logs for both the target and the impersonated party, extract the caller identifiers, search for the same identifiers across mail and telephony, and attach the lot to the ticket. All read-only, all racing a seven-day Entra Free retention, all faster than a human opening a console.

Gate everything else. The verification callback is the one step that must never be automated — its entire value is a human hearing a human on a number the attacker did not supply, and a system that auto-approves on a matched voiceprint has recreated the vulnerability in software. The rule that holds up: automation may gather, enrich, correlate and recommend without approval; it may act only where the action is reversible, scoped and rate-limited; irreversible or organization-wide actions require a named human approver. The tenant-wide reset freeze (2.4), the workforce broadcast (2.6) and the payment release (4.1) are all named-approver actions. And resist wiring an AI triage agent to auto-close these reports: the documented failure modes are overconfident closure on weak proof and hallucinated detail in the investigation narrative (Panther), and a report that reads like "employee thought a call sounded strange" is precisely where both bite.

#Pitfalls

This is one of the fourteen scenario playbooks in The 2026 InfoSec Playbook, a free field manual by Daniel Ramos. Written so somebody who has never read the book can pick it up mid-incident and run it. See all fourteen. Free, in full, no email wall.