
Industries in Focus
Last updated:
8 min.
Based on the research work of Dr. iur. Dr. rer. pol. Fabian M. A. Teichmann
Imagine this: A member of your accounting team receives an email that looks like a message from you as the CEO. The subject line reads "Confidential – urgent transfer". In the text, they are asked to transfer 85,000 euros to an alleged escrow account – due to a highly confidential acquisition about which they should speak to no one. The employee makes the transfer. The money is gone.
CEO fraud is just one of many variations of social engineering – that attack method which targets not technical vulnerabilities, but the human being itself. In his research, Teichmann analyzes why these attacks are so successful, what legal consequences they have – and what companies can do to prevent them (Teichmann, Phishing and Social Engineering in the Media Sector: Prevention and Legal Challenges, AfP 2025, pp. 490–499).
What Phishing and Social Engineering Really Are
Phishing and social engineering are not synonyms, even though they are frequently mentioned together. Social engineering is the umbrella term: It describes all methods in which attackers purposefully exploit human traits – helpfulness, trust, respect for authority, fear, or simple carelessness – to induce individuals to take actions that they would otherwise not perform (Teichmann, AfP 2025, pp. 490–499).
Phishing is the most well-known manifestation: Attackers send fake emails or set up deceptively realistic websites to illicitly obtain access credentials, passwords, or sensitive information. The mass form relies on broad distribution – millions of emails, and a small percentage still clicks. The more dangerous variant is spear-phishing: specifically tailored to individual persons, based on previously researched information regarding the victim's role, projects, and contact network. Such an email, which addresses the recipient by name and refers to a concrete ongoing project, is barely distinguishable from genuine messages.
And then there is the latest escalation phase: AI-powered social engineering. Generative AI enables attackers to produce personalized attacks on an industrial scale – and to use deepfakes to forge not only emails but also voices and faces. The EU cybersecurity agency ENISA explicitly warns that AI allows attackers to design social engineering attacks in an even more targeted manner (Teichmann, AfP 2025, pp. 490–499).
The Shocking Success Rate
According to current analyses by ENISA, phishing is by far the most common method that attackers use to initially penetrate organizations. In the FBI statistical report for 2022, phishing was the most reported internet crime in the US with over 300,000 reported cases – well ahead of all other cybercrime categories (Teichmann, AfP 2025, pp. 490–499).
The reason: Phishing bypasses firewalls, antivirus software, and all other technical protective measures. There is no security system that identifies an email as phishing if it is technically flawless and deceives solely through its content. Phishing frequently serves as the entry point for far more severe attacks: Once a perpetrator has captured access data, the actual potential for damage begins – ransomware, systematic data theft, industrial espionage, or sabotage (Teichmann, AfP 2025, pp. 490–499).
The Deception Methods: From Classic to AI-Powered
In his research, Teichmann distinguishes several social engineering techniques, which are often combined in practice.
The most effective method is pretending to have a false identity combined with artificial time pressure. Classic in CEO fraud: The attacker poses as a superior, creates a sense of urgent need for action, and appeals to discretion. This combination of authority, urgency, and secrecy is psychologically highly effective because it bypasses precisely those control mechanisms that would apply in normal everyday work (Teichmann, CEO Fraud in the Context of Generative Artificial Intelligence, ZWH 2024, pp. 1–8).
With vishing – voice phishing – the same mechanism is used over the phone. Smishing uses SMS messages. And deepfake-based social engineering has reached a qualitative new dimension through generative AI: a call with the deceptively real voice of the boss, a video conference with fake faces – as in the already documented case from Hong Kong in 2024, in which an employee transferred 25 million US dollars because he believed he was speaking to real colleagues (Teichmann, AI-powered Scam Techniques – Deepfakes as a New Challenge for Fraud Detection, Jusletter, June 30, 2025).
The Criminal Law Dimension
From a criminal law perspective, successful phishing and social engineering attacks in Germany regularly fulfill several statutory definitions of offenses (Teichmann, AfP 2025, pp. 490–499).
Anyone who gains unauthorized access to password-protected data through a phishing attack is liable to prosecution for spying on data under § 202a StGB – with imprisonment of up to three years or a fine. If the attack aims at financial damage – such as in CEO fraud – the offense of fraud under § 263 StGB or computer fraud under § 263a StGB applies. Deceiving the victim about the identity of the sender constitutes deception regarding facts, which induces an error and a damaging disposition of property on the part of the victim. If IT systems are disrupted by the attack – for example, by introducing ransomware –, § 303b StGB on computer sabotage applies, with a sentencing range of up to ten years in severe cases.
The problem in practice: Most social engineering perpetrators operate internationally and reside in jurisdictions where they are hardly prosecuted. Criminal liability is clear – its enforcement is the actual problem.
The Civil Law Dimension: Who Is Liable to the Victim?
If a company loses customer data due to a social engineering attack, there is a notification obligation to the responsible data protection authority under the GDPR within 72 hours and, if applicable, an obligation to inform the affected individuals. Critical in this regard is an unfavorable burden of proof rule: The company must prove that it had taken all reasonable technical and organizational protective measures. If it cannot do so, it is liable for non-material damages suffered by the affected individuals (Teichmann, AfP 2025, pp. 490–499).
This means that a company which does not conduct appropriate security training, does not employ multi-factor authentication, and does not operate technical phishing filters is in a worse legal position after a successful attack than one that has provably done everything reasonable. And under NIS-2, additionally: A successful phishing attack that leads to significant data loss or business disruption must be reported to the BSI within 24 hours.
The Psychology of the Attack: Six Levers That Work Every Time
What makes Teichmann's analysis particularly valuable is the look at the psychological mechanisms that make social engineering so effective.
Attackers specifically exploit six psychological levers. Authority: People automatically follow authority figures. Urgency: Time pressure overrides heuristics – anyone who has no time to think does not verify. Scarcity: "Only possible today" creates pressure to act. Liking: We help people we like or who appear similar to us. Social proof: "Everyone else is doing it too" legitimizes the requested action. And reciprocity: We feel obligated to those who have done us a favor.
These mechanisms cannot be overcome by technical measures. The only effective counter-strategy is awareness – and that is exactly why training is the crucial protective factor (Teichmann, AfP 2025, pp. 490–499).
What Companies Need to Do Concretely
Regular employee training is the single most important measure. Employees must understand what phishing emails look like, which psychological mechanisms attackers use, and how to react in case of doubt. Simulated phishing attacks – where test emails are sent to employees and it is evaluated who clicks – are one of the most effective training tools in this regard. The NIS-2 Directive explicitly requires such training as part of cybersecurity measures.
Multi-factor authentication is the most important technical countermeasure. Even if an attacker captures a password, they cannot access the system without the second factor. MFA reduces the success rate of phishing attacks dramatically.
Clear processes for sensitive transactions are crucial for CEO fraud. A simple rule can protect millions of euros: Transfers above certain amounts are always verified through a second channel – a callback to a known number, not the one provided in the email. This rule must be known before an emergency occurs (Teichmann, AfP 2025, pp. 490–499).
And company management must lead by example. If employees experience that executives ignore security rules or demand exceptions, these rules will not be taken seriously. Cybersecurity culture is created from the top down.
The New Dimension: When Deepfakes Overrule Detection Strategies
Teichmann points to a development that shifts the entire logic of social engineering prevention: AI-generated deepfakes render previous detection strategies obsolete. The recommendation to call in case of doubt falls short when voices can also be forged. The recommendation to be suspicious of unexpected video calls becomes more difficult when faces can be forged in real time (Teichmann, Deepfake Imitation and Fraud via AI-Generated Media, Kriminalistik 2026, pp. 194–200).
What follows from this? Companies need additional levels of authentication that function independently of visual and acoustic identification: code words for unusual requests, institutionalized callback processes via channels known in advance, and, above all, a corporate culture of doubt – the right and duty of every employee to question even urgent requests from supposed superiors without this being interpreted as disloyalty.
Conclusion: The Human Element Cannot Be Engineered Away
Firewalls and antivirus software protect against malware. Against a deceptively real email that triggers exactly the right psychological buttons, they do not help. And against AI-generated deepfakes even less.
Teichmann's research makes it clear: Social engineering is not a technical problem with a technical solution. It is a human problem that requires human solutions – education, training, processes, and corporate culture. The legal obligation to do so has long been in place with NIS-2 and GDPR. The question is no longer whether you have to act, but whether you do so before the first employee clicks.
All source citations refer to published scientific papers by Dr. iur. Dr. rer. pol. Fabian M. A. Teichmann. The complete bibliography is documented in the list of publications (as of May 2026).
Related Posts


