NFL Tech Leaders Outline Strategies for Defending Against AI-Driven Social Engineering

AI-powered social engineering is accelerating the speed, scale, and sophistication of phishing and impersonation threats, forcing enterprise IT and security teams to adopt multi-channel verification and supportive awareness programs.

Speaking during a webinar hosted by security firm Doppel and moderated by Chief Strategy Officer Bobby Ford, prominent technology executives from the National Football League outlined the growing risks posed by generative AI tools. Costa Kladianos, executive vice president and head of technology for the San Francisco 49ers, and Christina Morillo, senior director and head of information security for the New York Giants, detailed how artificial intelligence has lowered the technical barriers for threat actors heading into the 2026 season.

While social engineering remains a traditional attack vector, threat actors now leverage generative models to orchestrate highly convincing phishing campaigns and deepfake impersonations within minutes rather than days. Morillo noted that while AI-driven threats are not entirely novel, the technology has streamlined the process dramatically. She explained that attackers no longer require advanced technical expertise or specialized toolkits, as commercially available models allow anyone to deploy sophisticated social engineering schemes for a nominal monthly fee.

“I don’t think that threats created by AI are a new thing,” Morillo stated during the session. “I just think that AI made it a little bit simpler. Like, this process could likely take minutes, whereas in the past it may have taken a day or two or three.”

Morillo further emphasized that the democratization of cybercrime has eliminated the traditional skill barriers associated with script kiddies, putting advanced exploitation capabilities into the hands of virtually anyone willing to subscribe to low-cost AI services. Ford reinforced these observations by pointing to ongoing research indicating that AI-enhanced phishing attacks consistently yield higher engagement and click-through rates across corporate environments.

To combat these escalating threats, enterprise security leaders are advised to establish robust out-of-band identity confirmation protocols, reduce the friction of reporting suspicious communications, and foster non-punitive employee cultures that encourage early incident notification. As cybercriminals continue to refine their generative tools, maintaining strict multi-channel verification remains essential for protecting enterprise assets against sophisticated executive impersonation and spear-phishing.

Leave a Reply

Your email address will not be published. Required fields are marked *