
Audience: Students, faculty, and staff
What social engineering is
Social engineering is a type of cyber attack that relies on human interaction rather than technical hacking. The attacker may seem friendly and legitimate, while impersonating a new employee, IT staff, a repair person, or a researcher. Artificial intelligence (AI) now makes these attacks easier to run while also being more convincing: attackers can use AI to write convincing messages, research their targets from public posts, and imitate real people's voices and faces. Common forms of social engineering include these attacks:
- Phishing: fraudulent emails that trick you into sharing sensitive information or visiting a hacked website. AI-written phishing now has no typos or awkward wording, so a polished message is no longer a reliable signal that an email is legitimate.
- Vishing: phone calls or voicemails that attempt to have you take action or share sensitive information.
- Smishing: similar to regular phishing, but done through text messages which has fewer protections than email.
What deepfakes are
Deepfakes are audio, video, or images created or edited with AI to look or sound real. A scammer only needs a short clip of someone's voice, such as a video posted online, to clone it and use it in a communication. Convincing fakes used to take experts days or weeks to make, but today they can be made quickly with little technical skill.
See it in action: Deepfakes are already being used in real scams, fraud, and misinformation around the world. For real cases, see 20+ Real Deepfake Examples That Shocked the World.
Common social engineering scenarios
- Fake emergency. The caller claims a relative is in trouble and may pose as a lawyer, police officer, or doctor. They say it is urgent, say you are the only one who can help, and may ask you to keep it secret. They may ask for payment by wire, cryptocurrency, payment app, or gift card.
- Impersonated leaders. The attacker uses fake audio, video, or text to pose as executives or financial officers and ask for money to be sent to illigetimate accounts.
- Personalized scams. Attackers use AI to gather details from social media, class pages, and staff directories, then write messages that mention your real classes, coworkers, or supervisor.
- Fake job recruiters. The fake recruiter offers you an interview or job opportunity while referencing your work history.
Warning signs
- Pressure to act right now
- A request to keep the matter secret
- Anything related to finances, including gift cards and routing numbers
- A request for passwords, codes, or personal information from someone you cannot confirm
- A push to move from a call or video to text
- Personal details you would not expect a stranger to know, used to make the request feel legitimate
- Audio or video with odd pauses, lips that do not match the sound, or other inconsistencies
What to do
- Pause. Do not act while someone is rushing you.
- Verify through a second channel. Hang up and contact the person or office using a phone number you know is theirs or one you look up yourself from an official source. Do not use contact details supplied in the message. If you cannot reach them, try to reach them through someone else who knows them.
- Hold back money and credentials. Do not send money or gift card numbers, and do not share passwords, MyUI login details, or verification codes.
- Say something. See the reporting section below.
- Limit your online presence. Limit what video or photographic information you share online that could be used to create deep fakes and target others.

For students
Be wary of unexpected calls or texts that claim to come from financial aid, campus police, or a family member in an emergency that ask for money or gift cards. Never give your MyUI login, Social Security number, or bank information by email or text. If a video or voice message feels off, with odd pauses, mismatched lip movement, or extreme urgency, verify another way before you react. Think about setting up a verification word or phrase with your family.
For employees
Be skeptical of urgent requests for money, passwords, or access, even when the voice or video seems legitimate. Verify independently by hanging up and calling a known number, and do not rely on contact details the caller or sender provides. For sensitive communications and financial transactions, use identity checks such as a one-time code or PIN, known personal details, or multi-factor methods. If you approve payments or access changes, use a verification step that does not depend on the message that made the request.
How to report
Further reading: Finance worker pays out $25 million after video call with deepfake "chief financial officer" (CNN)