Social engineering has become one of the most dangerous methods of cyberattack, as it is no longer enough to detect malicious code — the threat is hidden in the live chat. The recent Brinks Home breach , revealed in August 2026 , is a prime example: the attacker did not use malware or exploits , but simply spoke to a help desk employee over the phone and convinced them to complete a Microsoft Entra authentication step . The result? Nearly 4.9 million Salesforce records and 41 GB of corporate data were posted on a public hacking forum .
See also: Social Engineering: The most dangerous “human” virus

The attack is being carried out by ShinyHunters, a group with proven connections to the wider Scattered Spider — also known as UNC3944, Octo Tempest , and Muddled Libra. The attack was detected on July 20, 2026, and Brinks refused to pay the ransom, resulting in the data being made public. Have I Been Pwned recorded approximately 732,000 unique email addresses from the breach, while the company's alarm monitoring services were not affected.
This incident is not an isolated incident. CISA and the FBI have issued a joint advisory describing vishing against corporate help desks as a recurring technique. Attackers impersonate employees, requesting password resets or transferring MFA to a device they control. ShinyHunters have been reported to target companies including Google , Qantas , Adidas , Cisco , Allianz Life , Workday , and LVMH brands .
Social Engineering: Why the Human Element Fails
The critical question is: why can’t people reliably detect social engineering? The answer lies in the nature of the attack. The attacker leaves no digital footprint — he doesn’t send phishing emails, he doesn’t install malware, he doesn’t exploit a CVE. Instead, he builds trust in minutes, using data from public profiles, previous breaches, corporate directories, and data brokers. Common pretexts include a lost device, an emergency executive trip, a broken authenticator, or an account lockout before a critical meeting.
One of the most concerning aspects is that MFA alone is not enough. If a help desk agent resets MFA or authorizes a device controlled by the attacker, then even the strongest authentication is bypassed through account recovery processes. ReliaQuest reported detecting 61 domains impersonating 48 organizations in a campaign linked to ShinyHunters, while stolen OAuth tokens from a Salesloft Drift enabled further spread to connected apps.
MITRE ATT&CK classifies vishing as T1598.004 (Phishing for Information: Spearphishing Voice). The attack chain typically follows these steps: target identification, creation of a credible pretext, help desk manipulation, identity hijacking, access to cloud/SaaS environments, and finally data extraction for extortion. None of these steps require a malicious file or known software vulnerability.
See also: Social Engineering: The Psychology Behind Attacks

Real-Time Social Engineering Technology Detection
Since human detection of social engineering cannot guarantee safety, technology takes the lead. One notable solution comes from Netarx ,which has developed a detection system that works during live communication. The system uses a proprietary orchestration layer — called the AI defense meta harness — that correlates signals from more than 40 AI models that continuously scan all communications, analyzing over 1,000 digital and metadata signals for each interaction.
To verify that the physical device belongs to the authorized user, Netarx analyzes device fingerprints, EXIF data, compression signatures , and location mismatches. For voice communications produced by GANs or voice cloners, it examines micro-artifacts impossible to detect by the human ear, such as unnatural background muting and electronic compression anomalies. If video is also available, the system compares lip movements with the incoming voice signals, while inspecting individual frames for anomalies in micro-expressions, unnatural eye frequencies, lighting inconsistencies, or distortions around hair — classic signs deepfake video.
No single signal is decisive on its own. However, the accumulation of multiple suspicious signals can tip the scales between genuine and fake in real time. Netarx has developed a color-coded indicator system: green means that the identity and device have been verified, yellow that the source is unknown or suspicious metadata anomalies have been detected, and red that a synthetic medium or active deepfake has been detected . If the yellow turns red during the conversation, the user — not the system autonomously — decides to end the communication.
NIK (Netarx Identity Key) works on Windows, macOS, Chrome, iOS , and Android. The company also publishes a database — the Impact Database — that records actual security incidents where human deception played a key role in the attack.
Practical Recommendations for Protection from Social Engineering
Organizations need to evaluate authentication as an end-to-end process. It’s not enough to ask if MFA is enabled — you also need to ask who can change it, under what circumstances, and whether those changes are independently verified. Requiring independent verification of identity — not relying solely on employee knowledge, caller ID, or inside information — is a critical first step.
Using out-of-band verification is equally important: calling the employee via a pre-registered number, contacting a manager via a separate channel, or requiring verification from a trusted device already enrolled. For privileged accounts, MFA resets should be prohibited from being reset by a single agent — requiring dual authorization or escalation for MFA overrides, password resets, Temporary Access Pass , and recovery email changes.
Opting for phishing-resistant MFA — such as FIDO2 security keys or passkeys instead of SMS, voice codes, and push approvals — is critical, especially for administrators and help desk staff. In addition, help desk roles should be narrowly defined so that a single agent cannot perform the entire account recovery chain without additional approval. Netarx’s solution is an early example of technology replacing human detection — and it certainly won’t be the last.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Surf Security adds Deepfake Detection tool to Enterprise Browser

The conclusion is clear: social engineering is a growing threat actor and a serious challenge to corporate security. The entire security stack is bypassed if a single privileged employee allows an attacker to cross the MFA threshold. Real-time technological detection, combined with strict procedural safeguards, is now a necessary — not optional — defense for every organization.
