What the 49ers and Giants Teach IT Pros About AI Social Engineering

What the 49ers and Giants Teach IT Pros About AI Social Engineering

AI-powered social engineering is pushing NFL security teams to strengthen identity verification, phishing reporting and employee awareness. Image: Paolo Aldrighetti/Unsplash

NFL technology executives share how AI-driven social engineering makes attacks faster and more convincing, offering practical strategies for IT leaders to build non-punitive, multi-channel defenses.

Écrit par
Zeus Kerravala
Zeus Kerravala
Aug 28, 2026

Every security team has a version of the same nightmare: an employee receives a message that looks and sounds exactly like it came from the boss — and then acts on it. No matter how much training a company provides, something eventually slips through the cracks, leaving the IT department scrambling. This underscores the importance of preparedness across the threat lifecycle.

During a recent webinar sponsored by Doppel and hosted by its chief strategy officer, Bobby Ford, two NFL technology leaders, Costa Kladianos, EVP and head of technology for the San Francisco 49ers, and Christina Morillo, senior director and head of information security for the New York Giants, walked through how AI has rewritten the social engineering playbook heading into the 2026 season. Their environments are extreme, but the lessons apply directly to any enterprise.

The threat didn’t change, but the economics did.

Social engineering remains one of the most accessible ways for attackers to target an organization. Generative AI has changed the speed, scale, and believability of these attacks. “I don’t think that threats created by AI are a new thing,” Morillo said. “I just think that AI made it a little bit simpler. Like, this process could likely take minutes, whereas in the past it may have taken a day or two or three.”

She also pointed to the collapse in the skill required. “Before, we used to just talk about script kiddies, and you had to know which tools to use. Now it doesn’t really take much. You can go to any of these models, and the tools are just right there. Just pay $20 a month, and you’re in.”

Ford cited research indicating that AI-enhanced phishing can produce higher click-through rates and that AI-assisted impersonation is increasing. The speed and scale of these attacks concerned both executives, who said the volume facing sports organizations was already substantial.

The other change is in quality. “Before, it used to be, ‘I’m from this country, send me your bank account, and I’ll send you a billion dollars,” Morillo said. “Now it could be coming from a vendor, a partner, or someone you work with, and it may not be them. They’re just very, very convincing now.”

Kladianos framed the deepfake problem in terms most enterprises underestimate: the more public your people are, the more raw training material an attacker has. “Everyone knows who George Kittle and Christian McCaffrey are, and that makes them easy targets,” he said. “It’s very easy to go on there, use social media, and deploy a deepfake, and it’s incredibly convincing. The eye test is something, but they’re getting incredibly good.”

Advertisement

Substitute your CEO’s keynote videos, your CFO’s earnings call audio, and your sales team’s LinkedIn presence, and the exposure remains identical. The attack surface now extends far beyond systems IT controls, encompassing impersonated executives, fake accounts, lookalike domains and cryptocurrency scams on external platforms.

More must-read AI coverage

Practical advice for IT and security leaders

Several defensible practices emerged that don’t require an NFL budget.

Make verification a process, not a judgment call. Kladianos’ warning about the after-hours request is the session’s most transferable insight: “The attacks come at any time, and they can come when your guard is down. That 2 a.m. call — I need to get in, I need to do this.” His answer is gates and governance, and refusing to treat low-friction requests as low risk. “You need to do that for things you consider small, like password resets. They’re not small. That’s the gateway to what you have in your organization. Secure your resources like you secure your money, because they are the same thing.”

Morillo’s version uses out-of-band confirmation by default. “One of our players just called. How do I validate that that’s who that is? They could spoof his number, they could spoof his whatever.” Her team relies on face-to-face contact and pre-established side channels for high-consequence requests. In practice: money movement, credential resets, MFA enrollment, and access escalation should all be confirmed on a second channel the requester didn’t choose.

Stop assuming the eye test scales. Kladianos’s prescription is to fight fire with fire, pairing AI-based detection with human review and continuous education — a three-part model he likens to scouting experience, coaching tools, and player development. “You put all three together, and now you’re going to win games.”

Make reporting easier than clicking. This is one of the simplest potentially high-value changes on the list. “It shouldn’t be hard for someone to report,” Kladianos said. “It should be easier to report than to click the phishing link.” Friction in your reporting workflow is a security control you’ve quietly disabled.

Remove the shame. Morillo identified the real reason reports don’t arrive. “There’s always this feeling of like, I did something wrong, I’m embarrassed.” Her fix: make it safe to text her, call her, or walk into her office and say, “I clicked on this, I entered my credentials, I’m sorry” — then respond without punishment. “The response is also a big piece of that puzzle.” She also makes awareness training personal rather than corporate: “I make it about this is what happens at home, this is what happens with your bank account, so it can resonate.”

Advertisement

Work the fundamentals year-round instead of building a checklist. When asked what belongs on a preseason security check, Morillo pushed back on the premise. “If you stay ready, you don’t have to get ready,” she said, citing continuous assessments, penetration testing, MFA coverage audits, patch cadence reviews, and security training that is automatically triggered the moment an account is created. “Just because they’re basics or fundamentals doesn’t mean they’re simple to do.”

Integrate your tools, even if you can’t consolidate them. Morillo was blunt about the reality of tooling: there is no single pane of glass; risk and GRC platforms rarely integrate cleanly; shadow IT and shadow AI create blind spots; and a platform can become a single point of failure. Kladianos offered this counterpoint: “Every system has to talk to each other. If you’re having disparate systems here and there, you can miss something.”

Share intelligence with your competitors. One frequently overlooked practice is peer collaboration. The executives said NFL clubs exchange indicators of compromise, vendor assessments and notes about security tools. “We’re competitive on the field, but we’re not competitive behind the scenes,” Morillo said. Kladianos supported this, explaining that if the Giants arrived at Levi’s Stadium with an incident, “we would 100% hop in and we would both work together on that threat” while the game was underway.

Get leadership buy-in, or don’t bother. “If you don’t have leadership’s buy-in, you don’t have anything; it will crumble,” Kladianos said, crediting 49ers CEO Al Guido’s support. His advice for earning it: translate technical risk into business risk, establish a cross-functional cybersecurity governance committee, and stop framing security as a technology problem. “It’s not an IT problem, it’s a business problem.”

The line that should follow IT leaders into their next budget conversation is his description of the job: “Cybersecurity is like a referee — it’s best when you don’t notice it.”

For IT leaders, the immediate takeaway is to identify which requests require secondary verification, test how easily employees can report suspicious messages and ensure that admitting a mistake triggers support rather than punishment. AI can make impersonation cheaper and more convincing, but established verification procedures and rapid reporting can still limit the damage.

Read more: A ClickUp API key exposed through automated emails shows how routine business workflows can inadvertently expose credentials and create broader security risks.

Zeus Kerravala

Zeus Kerravala is an eWEEK regular contributor and the founder and principal analyst with ZK Research. He spent 10 years at Yankee Group and prior to that held a number of corporate IT positions. Kerravala is considered one of the top 10 IT analysts in the world by Apollo Research, which evaluated 3,960 technology analysts and their individual press coverage metrics.