Automated Social Engineering
Back in 2009, I published my master’s thesis on Automated Social Engineering (ASE). The core idea was simple: combine chatbots with data from online social networks to fully automate social engineering attacks. At the time, the poor quality of automated conversations was the main limitation.
2020s: Automated Social Engineering Became Practical
Today, the limitation of automated conversation has largely disappeared. Modern large language models (LLMs) can hold natural conversations, adapt their tone, and generate highly personalized messages at scale. Research by Jones & Bergen (2026) suggests advanced models can even pass for human in controlled Turing-style tests. That level of fluency was far beyond the capabilities of the original ASE bot. Instead of following predefined scripts, modern AI agents act autonomously. They can gather information, reason about a target, and maintain long-running conversations. What required significant custom code in 2009, can now be built using off-the-shelf AI models. The volume of data available to these agents has also exploded. Today’s digital ecosystems harvest massive amounts of personal information. Data streams in from mobile apps, location services, ad networks, social networks, and data brokers. Together, they create a vastly richer (but also sensitive) digital profile of individuals than anything available when Automated Social Engineering was first proposed.
2026: Rogue Agents became real
In 2009, ASE posed a simple question: can social engineering scale by automation? In 2026, the answer is an undeniable yes.