Nothing about the text message seemed off.
His boss was just asking him to buy some gift cards for an award she was putting together. So he did and sent the codes over. But his boss needed more, so he bought more and sent the codes over. After a few rounds of this, he asked around the office and learned the truth.
The texts didn’t come from his boss. He’d spent $300 for an award that didn’t exist.
Yvonne Pire, CEO of Trofholz Technologies, an electronic security systems company based in Sacramento, recounts this scam as a cautionary tale. It was her employee it happened to. She was the one being impersonated.
This was nine years ago, before AI took off. These days, using AI-generated social engineering tricks, attackers can make an email or text from a boss look more realistic than ever. No more obvious typos. No obscure email address. Just a simple message that looks or sounds authentic enough for a person to click a link or open an attachment or enter their credentials or send money.
Yvonne Pire, CEO of Trofholz Technologies, an electronic security
systems company based in Sacramento, says she has been
impersonated by scammers. (Photo by Fred Greaves)

“I personally have been attacked multiple times through the network, but we have a great system in place, so we always see when it’s happening and we’ve always stopped it,” Pire says. “But my biggest attacks have been more on the people side. My own people getting text messages or emails saying that they were from me.”
According to the 2026 Verizon Data Breach Investigations Report, which analyzed data from more than 22,000 confirmed data breaches involving organizations in 145 countries in the past year, the human element was involved in 62 percent of breaches, up from 60 percent. Social engineering, the third most common attack pattern, represented 16 percent of all breaches. The report also found that more attackers are breaking in by exploiting software flaws rather than stealing passwords, accounting for 31 percent of breaches, up from 20 percent last year.
AI’s impact right now is primarily about speed, giving attackers a boost in techniques that defenders already know how to catch. In other words, AI hasn’t unlocked rare, never-before-seen attack methods, so defensive strategies don’t need to be reinvented today, the report says. But given how fast AI tools have been evolving, that reality could change sooner than later.
Still, on a weekly basis, Pire says, her employees get bombarded with AI-generated emails. “Employees are regularly targeted with requests to buy something, update direct deposit information or pay invoices,” she says, “all impersonating people they aren’t.”
Threat actors
In this day and age, exposing data isn’t just a matter of leaving a private folder in an Uber or forgetting a confidential report at a cafe. An emerging threat is users feeding corporate-sensitive data into the AI platforms themselves. Regular AI use on corporate devices tripled in a single year, from 15 percent of employees to 45 percent, the Verizon report found.
About 67 percent of those users accessed AI tools through non-corporate accounts on work devices, which means security teams can’t see what’s being uploaded.
But that gap isn’t limited to AI tools. The Verizon report also highlights the multipronged attack using many elements to gain access to internal systems: Attackers flood a target with spam emails to fake an IT emergency, then swoop in via Microsoft Teams pretending to be the “help desk” assigned to fix the issue. The target then grants desktop access for troubleshooting, allowing the attacker to operate from inside their own device.
Caleb Kwong, CEO of Savant Solutions, a Sacramento-based cybersecurity firm, has seen how easy it has become for attackers to exploit systems using people, and AI can only protect so much.
“People are trying to use AI to help filter out some of the noise and do some of the investigation, and that’s improving in some areas,” he says. “But also the attackers are able to pivot a lot faster because AI is on their side too.”
Caleb Kwong, CEO of Savant Solutions, a Sacramento-based
cybersecurity firm, has seen how easy it has become for attackers
to exploit systems using people. (Photo by Fred Greaves)

Most companies have the basics in place: a firewall, some endpoint protection. But that’s just a small slice of the security stack, Kwong says. Other layers include identity, cloud, email and network monitoring. Smaller companies usually skip some of these pieces, he says, while larger companies might have them, but set them up wrong. Attackers target these blind spots, lurking in the corners nobody’s watching, where they can sit undetected for weeks.
“Things move at a much faster pace now,” Kwong says. “Chasing signatures doesn’t work anymore because the threats evolve constantly — by the time a variant is catalogued somewhere, the version hitting you has already changed.”
Even watching behavior instead of signatures has gotten harder, he adds. These days, a lot of what’s hitting companies isn’t even malware. Attackers are using AI to find hidden flaws in software and hardware that developers have no time to fix, known as zero-day vulnerabilities. More and more, they’re also using legitimate tools inside a company’s own systems, such as valid credentials and trusted third-party vendor access.
Many organizations spend a good amount securing themselves, but reliance on third parties for software and services opens up new exposure. Third-party involvement in breaches keeps climbing, rising 60 percent year-over-year to account for almost half of all breaches, the Verizon data shows.
Cybercrime economics
For small organizations, a major threat is ransomware: malicious software that hijacks your computer or files, then encrypts them to lock you out. The attacker demands you pay a ransom to gain access. Ransomware appeared in 48 percent of all breaches this past year, up from 44 percent, the Verizon report notes.
“The top action varieties in breaches confirm that ransomware is still the yoga pants of cybersecurity,” the report authors wrote, dubbing this era of cybersecurity the “Ransoming Twenties.”
Email remains the top attack vector for social engineering breaches. But with so many on mobile devices, phishing scams and the attack method the report calls “pretexting” aren’t as simple as they used to be.
“The more involved pretexting attacks on the rise are also of a different nature to the ‘send-message-and-hope-for-a-click’ phishing attacks, as they are tailored to appeal to the nature of the employees being targeted,” the authors wrote.
To this end, security teams need to be asking questions: Do you know all the ways someone could reach employees on their devices? Could they actually spot a fake help desk request or a message from an impostor?
IBM cybersecurity expert Jeff Crume and his team spent 16 hours with a skilled cybersecurity person to design a phishing attack. The chatbot created a phishing attack nearly as well in five minutes. In the explainer video, he also highlights deepfakes, where generative AI can imitate a person’s voice and likeness, which will only become more realistic as the technology advances.
The global research from IBM and Ponemon Institute shows that companies are racing to adopt AI way faster than they’re putting security and oversight in place. AI systems without proper governance get breached more often and lose more money in the process. From the report:
$4.4 million: The global average cost of a data breach, a 9 percent drop over last year, driven by faster identification and containment.
$1.9 million: Cost savings from extensive use of AI in security, compared to organizations that didn’t use these solutions.
These figures, in U.S. dollars, came from 600 different organizations that experienced a data breach, with information directly from about 3,500 leaders, Crume notes in the video.
About 13 percent of organizations experienced a breach involving their AI models or applications, according to IBM and Ponemon Institute data. Of those, 60 percent had their data compromised and 31 percent dealt with operational disruptions.
“Another thing that we found in this was shadow AI,” Crume says in the video. “Now, what is that? There were 20 percent of organizations that found that they had AI, unauthorized AI implementations in their environment. So nobody approved this and maybe no one was aware of it until it became a problem. So clearly this is an area we need to start focusing on.”
Swiss cheese
A lot of what fails isn’t sophisticated, Kwong says. “Companies often have the right tools,” he says. “They’re just not set up properly to do their job.”
The other issue is patching: A known vulnerability that never got fixed, even though a fix exists. And the window to patch is shrinking. Attackers move on newly discovered vulnerabilities within hours, so patching has to be continuous. Basically, “once a quarter doesn’t cut it anymore,” Kwong says.
“If someone really wants to get inside your network, they’re going to get in there. I don’t care how big of a company you are. People will find a vulnerability. So the biggest thing is how quickly can you recover.”
— Caleb Kwong, CEO, Savant Solutions
At Savant Solutions, he says, everything is built on the zero trust framework: securing identity, devices, network and cloud to close the gaps. But recovery is the most important element.
“If someone really wants to get inside your network, they’re going to get in there,” he says. “I don’t care how big of a company you are. People will find a vulnerability. So the biggest thing is how quickly can you recover.”
With the rise in automation, attackers can use AI to scan for potential vulnerabilities before diving in manually. To combat this, some businesses have started using SOAR (Security Orchestration, Automation and Response) to automatically triage at a faster pace.
“It’s like Swiss cheese,” Kwong says. “You try to cover as many holes as possible, add another tool to cover another hole, but it’s not easy. I think it’s always best to plan for the worst-case scenario.”
‘Who’s doing the building?’
This year, Pire started running a weekly AI training for her team, teaching different ways to use AI and weaving in cybersecurity lessons. Her IT team also sends out monthly cybersecurity messages and alerts whenever someone gets hit with a phishing email.
Pire uses AI to its fullest capacity, she says, emphasizing how critical it is for principled people to be feeding the models.
“AI is here to stay and AI is going to become what its builders intend it to become, so the question is: Who’s doing the building?” she says. “The criminals are not going to debate whether AI is ethical because they don’t care.”
Pire has an assistant who reads her emails first, flagging and forwarding the ones that need her attention. Now they’re training an AI agent to do the initial review, sorting the real messages from the junk. AI isn’t sending anything on her behalf, though. Pire’s keeping “humans in the loop on that,” she says.
“There are ethical uses and unethical uses,” she says. “The trend right now is agents being able to run and do a job for people. There needs to be ethical standards of how we utilize that. It’s important to be part of the architecture future of AI and be involved versus on the sideline complaining about it.”
–
Stay up to date on business in the Capital Region: Subscribe to the Comstock’s newsletter today.
Recommended For You
The Increasing Risk of Cyberattacks: How to Protect Your Organization Against Massive Losses
As the bad guys get more sophisticated, all businesses, both large and small, are vulnerable. Cybercriminals view large business as a big pot of gold for them to steal and small or medium-sized business as an easy target. McKinsey & Company estimates that cyberattacks will reach $10.5 trillion by the end of this year, a whopping 300 percent increase from 2015.
AI Supercharges Talent Acquisition for Recruiters
How interview chatbots and other tools help employers find the right candidate
The job search is tedious on both ends. Depending on the size of the company, employers might sift through thousands of resumes to narrow down the field and find a single hire. It was a matter of time before technology came to the rescue.
