Close Menu

    Subscribe to Updates

    Get the latest creative news from infofortech

    What's Hot

    What It Does to Your SOC

    September 12, 2026

    Is A Free VPN Worth Using? Here’s Why It Could Be Risky

    September 12, 2026

    Researchers link another hacking campaign to OpenAI agents

    September 12, 2026
    Facebook X (Twitter) Instagram
    InfoForTech
    • Home
    • Latest in Tech
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    Facebook X (Twitter) Instagram
    InfoForTech
    Home»Cybersecurity»What the 49ers and Giants Teach IT Pros About AI Social Engineering
    Cybersecurity

    What the 49ers and Giants Teach IT Pros About AI Social Engineering

    InfoForTechBy InfoForTechAugust 30, 2026No Comments7 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email


    Every security team has a version of the same nightmare: an employee receives a message that looks and sounds exactly like it came from the boss — and then acts on it. No matter how much training a company provides, something eventually slips through the cracks, leaving the IT department scrambling. This underscores the importance of preparedness across the threat lifecycle.

    During a recent webinar sponsored by Doppel and hosted by its chief strategy officer, Bobby Ford, two NFL technology leaders, Costa Kladianos, EVP and head of technology for the San Francisco 49ers, and Christina Morillo, senior director and head of information security for the New York Giants, walked through how AI has rewritten the social engineering playbook heading into the 2026 season. Their environments are extreme, but the lessons apply directly to any enterprise.

    The threat didn’t change, but the economics did.

    Social engineering remains one of the most accessible ways for attackers to target an organization. Generative AI has changed the speed, scale, and believability of these attacks. “I don’t think that threats created by AI are a new thing,” Morillo said. “I just think that AI made it a little bit simpler. Like, this process could likely take minutes, whereas in the past it may have taken a day or two or three.”

    She also pointed to the collapse in the skill required. “Before, we used to just talk about script kiddies, and you had to know which tools to use. Now it doesn’t really take much. You can go to any of these models, and the tools are just right there. Just pay $20 a month, and you’re in.”

    Ford cited research indicating that AI-enhanced phishing can produce higher click-through rates and that AI-assisted impersonation is increasing. The speed and scale of these attacks concerned both executives, who said the volume facing sports organizations was already substantial.

    The other change is in quality. “Before, it used to be, ‘I’m from this country, send me your bank account, and I’ll send you a billion dollars,” Morillo said. “Now it could be coming from a vendor, a partner, or someone you work with, and it may not be them. They’re just very, very convincing now.”

    Kladianos framed the deepfake problem in terms most enterprises underestimate: the more public your people are, the more raw training material an attacker has. “Everyone knows who George Kittle and Christian McCaffrey are, and that makes them easy targets,” he said. “It’s very easy to go on there, use social media, and deploy a deepfake, and it’s incredibly convincing. The eye test is something, but they’re getting incredibly good.”

    Substitute your CEO’s keynote videos, your CFO’s earnings call audio, and your sales team’s LinkedIn presence, and the exposure remains identical. The attack surface now extends far beyond systems IT controls, encompassing impersonated executives, fake accounts, lookalike domains and cryptocurrency scams on external platforms.

    More must-read AI coverage

    Practical advice for IT and security leaders

    Several defensible practices emerged that don’t require an NFL budget.

    Make verification a process, not a judgment call. Kladianos’ warning about the after-hours request is the session’s most transferable insight: “The attacks come at any time, and they can come when your guard is down. That 2 a.m. call — I need to get in, I need to do this.” His answer is gates and governance, and refusing to treat low-friction requests as low risk. “You need to do that for things you consider small, like password resets. They’re not small. That’s the gateway to what you have in your organization. Secure your resources like you secure your money, because they are the same thing.”

    Morillo’s version uses out-of-band confirmation by default. “One of our players just called. How do I validate that that’s who that is? They could spoof his number, they could spoof his whatever.” Her team relies on face-to-face contact and pre-established side channels for high-consequence requests. In practice: money movement, credential resets, MFA enrollment, and access escalation should all be confirmed on a second channel the requester didn’t choose.

    Stop assuming the eye test scales. Kladianos’s prescription is to fight fire with fire, pairing AI-based detection with human review and continuous education — a three-part model he likens to scouting experience, coaching tools, and player development. “You put all three together, and now you’re going to win games.”

    Make reporting easier than clicking. This is one of the simplest potentially high-value changes on the list. “It shouldn’t be hard for someone to report,” Kladianos said. “It should be easier to report than to click the phishing link.” Friction in your reporting workflow is a security control you’ve quietly disabled.

    Remove the shame. Morillo identified the real reason reports don’t arrive. “There’s always this feeling of like, I did something wrong, I’m embarrassed.” Her fix: make it safe to text her, call her, or walk into her office and say, “I clicked on this, I entered my credentials, I’m sorry” — then respond without punishment. “The response is also a big piece of that puzzle.” She also makes awareness training personal rather than corporate: “I make it about this is what happens at home, this is what happens with your bank account, so it can resonate.”

    Work the fundamentals year-round instead of building a checklist. When asked what belongs on a preseason security check, Morillo pushed back on the premise. “If you stay ready, you don’t have to get ready,” she said, citing continuous assessments, penetration testing, MFA coverage audits, patch cadence reviews, and security training that is automatically triggered the moment an account is created. “Just because they’re basics or fundamentals doesn’t mean they’re simple to do.”

    Integrate your tools, even if you can’t consolidate them. Morillo was blunt about the reality of tooling: there is no single pane of glass; risk and GRC platforms rarely integrate cleanly; shadow IT and shadow AI create blind spots; and a platform can become a single point of failure. Kladianos offered this counterpoint: “Every system has to talk to each other. If you’re having disparate systems here and there, you can miss something.”

    Share intelligence with your competitors. One frequently overlooked practice is peer collaboration. The executives said NFL clubs exchange indicators of compromise, vendor assessments and notes about security tools. “We’re competitive on the field, but we’re not competitive behind the scenes,” Morillo said. Kladianos supported this, explaining that if the Giants arrived at Levi’s Stadium with an incident, “we would 100% hop in and we would both work together on that threat” while the game was underway.

    Get leadership buy-in, or don’t bother. “If you don’t have leadership’s buy-in, you don’t have anything; it will crumble,” Kladianos said, crediting 49ers CEO Al Guido’s support. His advice for earning it: translate technical risk into business risk, establish a cross-functional cybersecurity governance committee, and stop framing security as a technology problem. “It’s not an IT problem, it’s a business problem.”

    The line that should follow IT leaders into their next budget conversation is his description of the job: “Cybersecurity is like a referee — it’s best when you don’t notice it.”

    For IT leaders, the immediate takeaway is to identify which requests require secondary verification, test how easily employees can report suspicious messages and ensure that admitting a mistake triggers support rather than punishment. AI can make impersonation cheaper and more convincing, but established verification procedures and rapid reporting can still limit the damage.

    Read more: A ClickUp API key exposed through automated emails shows how routine business workflows can inadvertently expose credentials and create broader security risks.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    InfoForTech
    • Website

    Related Posts

    What It Does to Your SOC

    September 12, 2026

    AI Agents Help Hackers Compromise 440 PaperCut Servers

    September 12, 2026

    Best Practices for Deception Technology Implementation

    September 12, 2026

    Weekly Update 521: Breach Perception v. Reality

    September 11, 2026

    Claude Used to Automate Exploitation and Data Theft Across Multiple Victims

    September 11, 2026

    180 Android Security Flaws Patched: What to Do

    September 11, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026337 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202640 Views

    Mayiduo spent S$1M to produce his movie. It broke even & that’s a win in S’pore.

    March 31, 202628 Views

    How is Luckin Coffee expanding rapidly in S’pore while keeping its coffee so cheap?

    April 23, 202621 Views
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Advertisement
    About Us
    About Us

    Our mission is to deliver clear, reliable, and up-to-date information about the technologies shaping the modern world. We focus on breaking down complex topics into easy-to-understand insights for professionals, enthusiasts, and everyday readers alike.

    We're accepting new partnerships right now.

    Facebook X (Twitter) YouTube
    Most Popular

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026337 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202640 Views

    Mayiduo spent S$1M to produce his movie. It broke even & that’s a win in S’pore.

    March 31, 202628 Views
    Categories
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    • Latest in Tech
    © 2026 All Rights Reserved InfoForTech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.