Categories
research security

From Automated Social Engineering Bot to Agents

Automated Social Engineering

Back in 2009, I published my master’s thesis on Automated Social Engineering (ASE). The core idea was simple: combine chatbots with data from online social networks to fully automate social engineering attacks. At the time, the poor quality of automated conversations was the main limitation.

2020s: Automated Social Engineering Became Practical

Today, the limitation of automated conversation has largely disappeared. Modern large language models (LLMs) can hold natural conversations, adapt their tone, and generate highly personalized messages at scale. Research by Jones & Bergen (2026) suggests advanced models can even pass for human in controlled Turing-style tests. That level of fluency was far beyond the capabilities of the original ASE bot. Instead of following predefined scripts, modern AI agents act autonomously. They can gather information, reason about a target, and maintain long-running conversations. What required significant custom code in 2009, can now be built using off-the-shelf AI models. The volume of data available to these agents has also exploded. Today’s digital ecosystems harvest massive amounts of personal information. Data streams in from mobile apps, location services, ad networks, social networks, and data brokers. Together, they create a vastly richer (but also sensitive) digital profile of individuals than anything available when Automated Social Engineering was first proposed.

2026: Rogue Agents became real

In 2009, ASE posed a simple question: can social engineering scale by automation? In 2026, the answer is an undeniable yes.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.