“Hey John, it’s Jamie. I’m locked out of my email and I left my cell at the office. If I don’t get this spreadsheet over to finance by COB tonight, Bill is going to melt down for sure. Can you help me get into my email to send this one thing???”
Jamie sounds like Jamie, Bill is indeed the department head, and the company’s financial quarter is set to close within the next day.
Jamie sounds stressed, even close to tears, and John of course wants to help her out.
The problem is that Jamie is being impersonated using AI deepfake tech, and once John resets the MFA (multi-factor authentication), attackers will be inside the network within minutes.
As long as humans are part of any workflow, security is vulnerable to human error. Social engineering, the attack method utilizing convincing pretext to deceive and manipulate, is nothing new. However, AI has intensified the threat landscape.
Deepfakes, voice cloning, and synthetic identities mean human judgement defenses are more vulnerable now than they were a few years ago.
Help desks are valuable targets for threat actors using these tactics.
Muddled Libra (one alias for this group is Scattered Spider) is one such threat group utilizing these tactics, as outlined by Palo Alto Networks in June 2025, where they saw evidence of the group identifying key personnel, using publicly available information to build a profile and then use this to impersonate the employee, thus allowing them to gain access to systems and monetize attacks quickly.
Personal relationships which may exist between help desk and other company staff are often exploited, using deepfake tech to impersonate not only voice, but also cadence, inflection, and keyword peculiarities specific to the chosen individual.
Threat actor methods and tracking can be time consuming. It is important to note threat actors often share scripts, refine techniques, and trade stolen data on the dark web. Leaving threat actors un-investigated means leaving behind key defensive intel crucial for your business.
The NY Times identified threat actor Scattered Spider as being investigated for the 2025 Marks & Spencer cyberattack in Britain.
DarkOwl Vision offers intel and dossiers on threat actors. Scattered Spider is one such entity whose methods, aliases, tools, and other information are available. The identified alias of “Muddled Libra” is seen below for threat actor “Scattered Spider” in Dark Owl Vision:

Additional details for this threat actor include other targeted industries, Telegram accounts, and known tactics:

Social engineering defense is key, however, knowing specific attack methods can increase network defenses.
Three CVE’s have been identified as in use by Scattered Spider in DarkOwl Vision:

A known enemy is always better than fighting blind. Monitoring dark web content as part of proactive security measures can help defend against emerging attack vectors.
Network defenders can also watch for signals before an attack. To catch adversary reconnaissance from darknet sources, monitoring and subsequent alerting are key.
DarkOwl Vision’s Alerting function can ensure keywords specific to your company can be monitored, with alerts generated from any findings. Identified corporate keyword chatter on dark forums can be utilized as an advanced warning to all company staff in anticipation of social engineering attacks. If any are discovered, security passphrases can be refreshed, and additional social engineering prevention trainings issued.


Remember, the attackers already have enough data points to pull off a convincing pretext against your staff. The United States is by default opted IN, not opted out, of data brokers. The personal and specific details of your staff are already public. Names, roles, manager’s role, and other details are easily found.
Adding AI impersonations with deepfake technology, and you’ve got a recipe for disaster. Methods discussed online quickly turn into real world intrusion attempts.
Go back to John for a second. By the time “Jamie” called, the attacker had already done the hard part of research and preparation including details, urgency, voice, etc. That’s the uncomfortable truth about this kind of attack: the call itself is just the final step in a process that’s been visible, in pieces, for days or weeks beforehand. The organizations that get ahead of this are the ones who were watching the early signals closely enough that the call never had a chance to work in the first place. AI has made the pretext better. It hasn’t made the playbook any less visible to the people willing to look for it.
Products
Services
Use Cases