AI & Technology

AI Exploitability: The Human Attack Surface Nobody Is Measuring Yet

By Matt Polak, CEO, VanishID

Ask a security team for their patch rate and you’ll get an answer to one decimal place. Ask them what AI could build from their CFO’s external identity data this afternoon and the room goes silent. 

Every security program runs on numbers. Vulnerability counts, mean time to remediate, phishing click rates, MFA coverage. Those metrics exist because the assets they describe sit inside a perimeter someone owns. The raw material for AI-enabled attacks sits outside that perimeter, scattered across data brokers, breach dumps, social profiles, conference bios, and public records. 

The framework says reduce exposure. No metric says how much you have. 

MITRE ATT&CK is unusually blunt about external identity data. Its entry for Gather Victim Identity Information (T1589) states the technique “cannot be easily mitigated with preventive controls” because the underlying behavior happens outside the scope of enterprise defenses. The recommended course of action is to minimize the amount and sensitivity of data available to external parties. 

So the framework tells you to reduce exposure, and no standard metric tells you how much exposure you have or which attacks it enables. Reconnaissance is the first step in the attack chain and the only step most organizations can’t quantify. Attackers quantify that step constantly. Finding a target’s face, voice, writing style, reporting line, and personal phone number is now a search, not a project. 

Reconnaissance just got industrialized 

Targeting a person used to take real labor. One operator, assembling a pretext by hand from whatever they could find, working a few targets at a time. Generative models collapsed the marginal cost and spread the work across an entire employee directory at machine speed. 

In February 2026, Trend Micro researchers demonstrated a system that turned public LinkedIn data into individualized target profiles and tailored phishing material at scale, work they estimated would previously have taken many hours per target. By July, the Financial Times was describing the broader trend as the industrialization of cybercrime and reporting cases of AI-generated executive deepfakes in live operations. 

CrowdStrike’s 2026 Global Threat Report found AI-enabled adversary operations rose 89% year over year, with average eCrime breakout time down to 29 minutes. The FBI’s Internet Crime Complaint Center has warned since May 2025 that actors impersonating senior US officials are “exploiting AI-generated audio to impersonate well-known public figures or personal relations,” and that synthetic content is now often hard to identify as fake. 

The best-known case is still the engineering firm Arup. A finance employee in Hong Kong wired roughly $25 million after a video conference in which every other participant, including the CFO, was synthetic, as CNN reported in May 2024. The attackers built the call from material that was already public, and the call arrived through a channel the company trusted. 

Every attack has a bill of materials 

The Arup call needed face photos and recorded voice. A voice clone needs a short audio sample. A spear phish that lands needs a writing sample and a position on the org chart. Every AI-enabled attack on a person has a bill of materials, and every line item comes from somewhere findable. 

Break an attack into ingredients and the exposure problem becomes measurable. Some ingredients are required: without them, the attack doesn’t work. Others are amplifiers that raise the success rate, and others are contextual details that glue the pretext together. Write the recipe for executive impersonation, vendor email compromise, help-desk pretexting, SIM swapping, or nation-state insider recruitment, and each recipe becomes a checklist you can test a real person against. 

You’ll never eliminate every ingredient, so break the chain instead. Remove or mitigate enough required ingredients and the attack can’t complete. Weaken the amplifiers and its odds of success drop. The checklist stops describing risk and starts mapping where your defenses can intervene. 

“Your senior systems administrator appears in four breach datasets” is a fact with no consequence attached. “Two of the three questions your help desk asks before resetting MFA are answerable from those same breach datasets, and the reset hands over an account with standing privileged access” is a completed recipe. A security leader reading the second sentence knows exactly what to change this week. 

What you can’t remove, you compensate for 

Assembling these recipes by hand has always been slow, and the labor was its own control: the friction that limited attackers limited defenders too. AI removed the friction on both sides. Collection, correlation, and analysis now run at a speed that makes systematic assessment practical. 

Some of what an assessment finds can be removed through broker opt-outs, privacy settings, and cleanup of stale profiles. Some of it can’t be removed at all. A face photo is the obvious example. 

Exposure you can’t remove has to be compensated for. Once you know which attacks a given exposure enables, you can map those attack paths onto the technical and administrative controls you already own and use those controls to disrupt the chain. The point is to make existing security investments work harder against the specific risk that remains. 

Verizon’s 2026 Data Breach Investigations Report finds 65% of AI-assisted attacks target people, and all of them run on the same fuel: the exposed external identity data of the targets. Most security teams instrument everything inside the perimeter, then act surprised when the attack routes around it. 

AI exploitability is measurable: the count of attack recipes an adversary can complete against a given person from what is exposed right now. Getting that number means accepting that the assessment happens outside your walls, person by person and attack by attack, on a loop rather than a schedule. 

Boards are already asking for this number. Better to have it before the question arrives. 

Related Articles

Back to top button