top of page

How Attackers Weaponize Social Media At Scale with AI

  • 44 minutes ago
  • 5 min read

This guest article was authored by Rachel Vrabec, CEO of Kanary

Rachel Vrabec, CEO of Kanary

Every CISO can tell you where their network ends. Far fewer can tell you where their organization's human attack surface begins. That gap is exactly where adversaries are operating.


The most sophisticated attack campaigns targeting enterprises today don't start with a vulnerability scan or a zero-day exploit. They start with a LinkedIn search. They continue with a cross-referenced Instagram account, a data broker record, a tagged photo that reveals a home neighborhood, and a family member's name pulled from a public Facebook profile.


By the time that information gets fed into a large language model and transformed into a personalized spear phishing message or a convincing impersonation account, your security stack hasn't registered a single anomaly, because none of this happened inside your organization. A single impersonated Tweet can move the market, cause reputational harm or destroy trust with customers. With this potential loss on the line, organizations are starting to feel the liability.


Trust and Safety Are Down While Impersonation, Bots and Non-Human Identities Are Rampant


Social media took over our lives, and alongside it, the security community benefitted from a new wave of OSINT and social media listening tools for better intel, faster responses, and automated posts. Many security and brand teams partner to use these tools to monitor all types of incidents: IP infringement, insider threat, executive safety. These tools and risks tend to fall outside of traditional endpoint protection or SOC purview, and focus on sentiment analysis for measuring brand health or PR.


But two headwinds are now hitting security teams all at once:


  1. A rollback in platform-level trust, safety, and security investment

  2. A rise in deepfake, AI-generated content, and fake profiles


These problems turn what used to be a 4hr/week job into a full time, multi-team-member effort. Doing this well now demands dedicated monitoring staff, active coordination with platforms, fluency in privacy law, and a direct line to internal teams that are already stretched thin. Nikita Bier, head of product of X, posted April '26 that he was working to take down over 208 bots per minute. But security teams still report the time to process complaints has significantly slowed since the days when the platform was repped by the little blue bird.


Attackers know these delays and repealed consumer privacy regulations work in their favor.


So much so, MITRE ATT&CK framework codified this into their Reconnaissance phase: adversaries deploy scrapers, bots, and AI-assisted tools to aggregate individual profiles at scale, turning public social media into a persistent, always-on intelligence operation directed at every person who uses it, and an impersonation platform for anyone who doesn't.


The Association Problem


No single piece of publicly available information is particularly dangerous on its own. A job title on LinkedIn. A neighborhood tagged in a photo. A comment thread revealing a family member's name. Individually, these seem innocuous. Combined and processed at machine speed, they form the basis of a targeting package sophisticated enough to deceive almost anyone. This is what makes the modern threat landscape so difficult to defend against through traditional means. Spear phishing campaigns that reference an employee's direct manager, a recently announced internal initiative, and a mutual conference connection aren't the product of a lucky guess. They're the output of a systematic data collection process that your security stack was never built to see.


The same raw material powers impersonation. When an attacker has access to a public photo library, years of written content, and a professional history, building a convincing synthetic identity becomes a low-cost exercise. AI tools have collapsed the time and technical skill required to produce deepfake audio, video, or written communication. Anyone with a grudge and a free AI tool can now build a convincing fake of your CFO.


When Attack Costs Are Low, Everyone Becomes a Target


For most of the history of social engineering, targeting was a resource allocation problem. A sophisticated attacker had a choice: go after the executive with the high-value access and the hardened security team watching their accounts, or go after the accounts payable manager with the wire transfer authority and the unmonitored LinkedIn. You could build a campaign against one or the other, but running both simultaneously wasn't worth it. The ROI on the mid-level employee didn't justify the operational cost when you could only run so many campaigns at once.


AI has collapsed that calculus entirely. When the cost of building a targeting package drops to near zero and personalized outreach can be generated and deployed at scale, attackers don't have to pick. They run the executive campaign and the accounts payable campaign and the IT administrator campaign in parallel, at a cost that would have been unthinkable five years ago.


Martin Casado has been sounding this alarm since 2020, long before AI made it obvious. His observation then was blunt: attackers had already shifted en masse away from targeting company networks and toward targeting people directly. What the intelligence community used to reserve for nation-state operations was showing up in small business inboxes. The attack surface had moved from your systems to your life.What AI did was finish the job. It didn't just make existing attacks faster, it changed which attacks were worth running at all. When targeting required significant manual effort, attackers made calculated choices.


Executives and high-value individuals absorbed most of the attention because they were worth the investment. But when you can build a targeting package on any employee in minutes and generate personalized outreach at scale for near zero cost, there's no reason to leave anyone off the list.


Closing the Gap


Executive protection conversations tend to stall in the same place. Senior leaders know they're visible. What they underestimate is how much that visibility has been indexed, cross-referenced, and catalogued by systems that now put them and their organizations at risk.


The most effective thing a security leader can do is show an executive exactly how a bad actor can compromise them based on the personal data linked across their LinkedIn activity, family members' public accounts, tagged photos and social media posts.


A structured "doxx yourself" session, or a formal tabletop built around the organization's real liability from personal risk exposure, puts leaders in the position of the target rather than the audience. Bring in an outside team if internal objectivity is a barrier. The goal is for your highest-risk personnel to feel the attack from the outside in, not hear about it from the inside out. Once that group is bought in, the rest of the program gets dramatically easier to sell and execute.


With leadership aligned, rolling out awareness training to the broader workforce covers moderate-risk employees at very low marginal cost. The tactical layer doesn't need to be sophisticated. Audit and update default privacy settings on personal and professional social accounts. Turn on MFA everywhere it's available. Build a habit of searching your own name and photo periodically to check for impersonation accounts. None of these steps are transformative on their own. Across a workforce, applied consistently, they shrink the available attack surface in ways that matter.


The attacks that start outside your perimeter are finding smaller and smaller cracks to get inside. The day-to-day work of hardening that perimeter is understaffed, over-alerted, and accelerating, fueled by the dismantling of third-party guardrails and the rapid improvement of AI tooling. Being reactive cuts off the head of Medusa where two more grow back. Smart security professionals are starting to take a step back and diagnose these problems at the source. It's not about more alerts. It's about building a seamless connection between small mitigations upstream that prevent attacks from snowballing.

bottom of page