A public profile tells people where you work. Social media posts show how you write. Comments and replies reveal some of the people you know.
My concern is what happens when an AI agent can use that information to hold a conversation under your name.
AI agents impersonating a victim could answer follow-up questions, remember earlier exchanges, and adapt their next message. The person on the other end might recognize enough to keep talking.
I predict this with moderate confidence. By September 2028, I expect credible public reporting of at least one malicious campaign in which an agent uses public information to impersonate a named professional across repeated conversations. The components are emerging; reliable impersonation and its advantage over human operators remain unresolved.
Borrowing enough credibility
Consider the sort of notes an impersonator could assemble from profiles, posts, and public interactions:
Public context // illustrative identity model
A few facts. A familiar person.
Maya works in commercial property management.
Frequently discusses building renovations and tenant experience.
Posts concise, upbeat project updates on LinkedIn.
Knows Alice, who supplies fixtures for her buildings.
Previously worked with Bob on a retail refurbishment.
Often starts a reply with a project update.
Those details could form a relationship map: who Maya knows, what connects them, and what each contact might recognize. A supplier might remember the renovation she posted about. A former colleague might recognize a shared project. An agent could use that context to make a conversation feel familiar.
I call these AI impersonation agents: systems that represent a real person without permission and can choose and send replies. AI agents’ memory could carry the impersonation across conversations.
More consistent opinions, humour, and reactions might help an impersonation survive scrutiny. That is a proposed benefit, not a result established by the evidence reviewed here.
The software around the model matters. Browsing tools let it gather context; messaging tools let it act on that context. An impostor profile and a compromised genuine account bring different advantages. Public posts and stolen private messages also provide very different material for a clone.
Familiarity can become access
The dangerous moment comes when familiarity becomes permission.
Reset an account.
Share a project folder.
Change payment details.
Imagine Maya’s supplier receiving a message about a project they both know. Several ordinary exchanges later, the supposed Maya asks for access to a project folder. The supplier’s decision now depends on a relationship the real Maya built, and someone else is borrowing.
Human attackers already do this, and they may keep control of the conversation while using AI for research and drafting. That could deliver much of the benefit with fewer mistakes. The change to watch is whether agents let one operator maintain more relationships for the same effort. The evidence reviewed here does not establish that advantage.
What the research establishes
KAIST’s “When LLMs Go Online,” published at USENIX Security 2025 examines online information collection, impersonation posts, and targeted phishing emails. Its phishing evaluation was a survey, leaving sustained deception of real contacts untested.
Other researchers have simulated social-engineering conversations and observed agents in a live laboratory for two weeks.
A closer example comes from an August 2026 report by the UK’s AI Security Institute. During an evaluation with permissive internet access and some safeguards disabled, an agent researched real maintainers and used fabricated identities to pressure one into approving malicious code. The maintainer rejected it. The tested configurations were not commercially available. The incident shows that an agent can combine online research, fabricated identities, and live social engineering under those conditions.
Where the campaign evidence leads
The closest operational lead I found involves phone calls. In September 2025, EclecticIQ reported adaptive AI calling agents used by ShinyHunters affiliates. The report describes callers adapting their responses as victims react.
These examples cover parts of the problem. A persistent clone would also have to sustain a specific real person’s identity and relationships across conversations. The public evidence reviewed here does not establish that complete sequence or the amount of public information it would require.
The practical question is: which impersonation campaigns show credible evidence of AI-driven interaction, and what connects them to a known threat cluster?
Analysts group related attacks into threat clusters; attribution means working out who ran them. Establishing whether an agent chose the replies is a separate question. A human could follow a script, use AI assistance, or let a model choose and send replies. The wording alone cannot distinguish those possibilities.
Evidence record: the reported campaign connection
This record separates two published findings from the proposed connection between them:
| Question | Assessment |
|---|---|
| Were AI callers reported? | EclecticIQ reports adaptive AI agents used by ShinyHunters affiliates. This is a vendor-reported finding. |
| Is an access-to-extortion link reported? | Google Threat Intelligence Group (GTIG) links UNC6661 initial access to later UNC6240 extortion, citing a recurring negotiation account, branded messages, and stolen-data samples shared through the same service. |
| Were those intrusions initiated by AI callers? | Unestablished. Google does not establish AI use in those calls, and EclecticIQ does not identify its AI callers as UNC6661. |
My hypothesis is that AI-operated impersonation could enter this kind of chain through an access provider. Confidence in that placement is low. Human callers, AI-assisted operators, or separate affiliates using similar services remain plausible explanations.
MITRE’s entry on ShinyHunters’ reported AI voice-agent use cites EclecticIQ. It adds no independent confirmation.
There are concrete records to look for. Abnormal’s April 2026 analysis of the ATHR voice-phishing platform describes call records with campaign identifiers, agent assignments, and transcripts. Those fields suggest how an investigator could join an interaction to the service that handled it. A platform screenshot alone proves neither a victim outcome nor a named group’s involvement.
The missing connection is a dated victim interaction tied to records of the model’s decisions and an account controlled by the access operator. A platform’s “agent” label alone would not establish that a model chose the reply. An affected organization may hold messages, account activity, and approval records; service-provider records may be unavailable.
For the September 2028 forecast, a qualifying public case would need to identify the real person copied, explain the use of public information, and document agent-led interaction across repeated conversations. Human-led calls and generic invented personas would not qualify. Without a qualifying report by that date, the public-reporting forecast would have missed; undisclosed activity would remain unknown.
The record above separates reported findings from a proposed link. Extending it to a particular victim would mean recording the identity copied, what the operator knew, the requested action, and the source of each claim. That would focus the next evidence request. This is an investigation aid; its detection performance has not been tested.
Put the check where the damage happens
For leaders, the immediate decision is whether a familiar conversation can bypass an existing check. I would begin with three workflows where a convincing request can expose access, information, or money:
- Account recovery and security changes. IT and identity teams own the checks around password resets, changes to sign-in methods, and new access. The review should establish whether staff used the approved verification route, especially during urgent exceptions.
- Payments and supplier changes. Finance and procurement own confirmation of changed payment details through contact information already held on record. The FBI recommends verifying changes to payment procedures. Approval should cover the specific destination.
- Sensitive sharing and external access. Data and application owners approve the recipient, scope, and purpose through an established workflow. A real person’s identity does not automatically give them authority to approve every request.
Existing controls may already cover much of this risk. Reviewing recent approvals and exceptions should establish whether the approved verification route was actually used and whether approval covered the specific action. A completed form alone is weak evidence.
Two measures would help: the share of reviewed requests missing independent verification, and the outcomes of confirmed impersonation attempts. The first exposes process or recordkeeping gaps. The second provides case evidence of controls blocking or allowing abuse, although it cannot reveal attacks nobody detected.
Each demonstrated gap needs an owner and a corrective action. Additional spending should follow the exposure and the expected benefit of a fix, accounting for cost and disruption to legitimate work.
Phishing-resistant sign-in, such as security keys, helps protect logins. Retained account and application logs help reconstruct what happened. Neither replaces approval of the action itself.
Biometrics may play a bigger role in verification as familiar words and voices become easier to imitate. One useful application is a face or fingerprint check on your own device that activates a passkey. FIDO explains that this biometric data stays on the device; the service receives cryptographic proof of authentication. NIST’s guidance requires biometrics to be paired with a physical authenticator. A recognizable face or voice on a call offers no equivalent proof. Spoofing protection, secure recovery, and accessible alternatives remain essential. Approval still needs to cover the specific action.
The concern is that a public professional identity could become reusable material for someone else’s operation. Protecting against it means making consequential decisions depend on verifiable authority, even when the conversation feels completely ordinary.
Your public identity can be copied.
The authority to act in your name should never come with it.