
Security teams have traditionally built their defenses around the assumption that attackers operate within human limitations — constrained by time, scale, and the effort required to repeat campaigns. That assumption is no longer valid. Generative AI has fundamentally changed the threat landscape, enabling adversaries to create highly convincing phishing campaigns, replicate executive voices, and conduct reconnaissance at a speed and scale that was previously impossible.
Researchers call this pattern ‘vibe hacking,’ in which attackers direct AI tools using plain, conversational language rather than writing code or building infrastructure themselves.
For CIOs and security leaders, this shift changes what a credible enterprise defence strategy needs to include and how quickly it needs to adapt.
Vibe hacking occurs when attackers use AI coding assistants and chatbots to plan, script, and run intrusions in a conversational manner rather than manually. Anthropic’s threat intelligence team disrupted an operation where a single actor used coding agents to automate reconnaissance, credential harvesting, and network penetration across at least seventeen organisations, work that would have previously required an entire technical team with specialised skills built up over years.
In one documented case, AI handled 80 to 90% of an extortion campaign end-to-end, with a human operator stepping in only at a handful of critical decision points. Attackers also used AI to draft custom ransom notes and fake login pages tailored to each victim’s specific profile and industry, turning stages of an attack that once took days into tasks completed within minutes, with far fewer errors along the way.
Attackers can now create grammatically flawless emails, synthetic voices, and convincing video impersonations without requiring advanced technical expertise. By early 2025, AI-generated content and deepfake techniques had become increasingly prevalent in observed phishing campaigns, with executive voice and video impersonation emerging as a common tactic in business fraud attempts across industries.
Agentic systems can run continuously, issuing thousands of requests during a single campaign at a pace no human team could realistically sustain over time. Fewer skilled attackers can now strike more targets at once, a pattern clearly reflected in the rising number of AI-powered cyberattacks reported by Indonesian organisations, as digital banking adoption accelerates and more services move online.
Attackers rely on predictable human shortcuts: trust in a familiar voice, deference to a senior title, and urgency created around tight deadlines. A fabricated instruction that sounds and looks right slips past skepticism that a badly written, generic phishing email would normally trigger among alert staff.
Finance staff, executive assistants, and helpdesk agents face disproportionate targeting because their roles demand fast, trust-based decisions under pressure. This is where deepfake social engineering enterprise incidents cause the most measurable damage. In one widely reported case, a finance employee transferred $25 million during a video call in which every senior leader visible on screen was AI-generated.
Static, rule-based filters cannot keep pace with content specifically built to evade them. A stronger technology stack should include the following layers, each addressing a different point in the attack chain:
Every wire transfer, credential reset, or access change tied to an urgent request should require a second, independently verified channel, regardless of how senior the requester appears to be on screen, on a call, or in writing.
Technology alone cannot close this gap, regardless of how advanced security tools become. Organizations must pair their defenses with regular, scenario-based training that uses realistic deepfake and social engineering simulations to help employees recognize manipulation tactics before responding under pressure. Gartner reported that 62% of organizations experienced a deepfake-related social engineering attack within the previous year, highlighting the need for stronger human-layer defenses.
CIOs can no longer treat AI risk as a technical footnote buried inside the security team’s roadmap. Leadership now means funding identity-verification infrastructure, running cross-functional incident-response drills, and holding vendors accountable for provenance standards across every platform in use. These decisions belong at the same table as digital transformation strategy, not several steps behind it, and not left until after an incident forces the conversation.
AI systems are already capable of executing complex cyberattacks with minimal human intervention, and this capability will only grow. To prepare, organisations should take the following proactive steps:
As cyber threats evolve from traditional attacks into sophisticated AI-enabled campaigns, enterprise leaders across Southeast Asia are redefining what effective security leadership looks like. digitalCIO Indonesia, taking place on 11 November 2026 at The Ritz-Carlton Jakarta, Pacific Place, brings together leading CIOs, CISOs, and technology practitioners to share firsthand experiences, analyze real-world incidents, and collaborate on strategies that strengthen organizational resilience.
From synthetic identity fraud to AI-driven executive impersonation through voice and video, today’s threats demand informed leadership, stronger governance, and collective action. The summit provides a platform for security decision-makers to exchange practical insights, learn from peers who have navigated these challenges firsthand, and develop strategies to address the evolving risks shaping enterprise security across Southeast Asia.
Register today!
What is vibe hacking?
It describes attackers using AI tools conversationally to plan and execute cyberattacks without great technical skill.
How does deepfake social engineering target enterprises?
Attackers impersonate executives through fabricated audio or video to authorise fraudulent payments or extract sensitive data.
Can traditional security tools detect AI-generated attacks?
Often not reliably, since these tools typically cannot verify identity or authenticity of content in real time.
Why is Indonesia particularly exposed to these threats?
Rapid growth in digital banking and limited data sharing between institutions widen the attack surface for fraud.
What is the first defence step for CIOs to take?
Require out-of-band verification for all high-value financial and access requests, regardless of requester seniority.