September 23, 2026
Introducing Lookout Social Engineering Protection


For years, cybersecurity has focused on a few basic things: secure the perimeter, control access, and train employees to spot suspicious links. Do those things well, and the thinking was that you could keep the enterprise secure.
Frontier AI has shattered that assumption.
Attackers no longer need to breach the perimeter or trick an employee into clicking an obvious malicious link. AI can manufacture trust itself, creating convincing messages, impersonating executives, cloning voices, and adapting deception in real time. And increasingly, these attacks are reaching employees through the device and communication channels they trust most: mobile.
The old cybersecurity playbook wasn’t designed for this world.
The Small-Screen Deception Paradox
Mobile has become the ideal environment for deception. Employees make rapid decisions on small screens, with fewer security cues and little time to scrutinize what they see or hear. They move constantly across SMS, messaging apps, collaboration platforms, and voice calls, often beyond the reach of traditional enterprise security controls.
Attackers know mobile gives them an advantage, and they are using it. On a phone, there is less context, identities are harder to verify, and an attack can easily move from a text message to a phone call or another channel.
AI has made these attacks much harder to spot. Attackers can create convincing, personalized messages in seconds, clone an executive's or colleague's voice, and use deepfakes to make the interaction feel legitimate. What once took considerable time and effort can now be done quickly and at scale, making it much easier to earn someone’s trust and influence what they do next.
We are already seeing this play out in several ways:
- Voice Phishing (Vishing): AI-generated voice clones can convincingly impersonate executives, colleagues, IT support, and other trusted individuals, making phone calls a powerful social engineering tool. Industry research from Keepnet Labs estimates that vishing attacks cost affected organizations an average of $14 million annually.
- Linkless Smishing: Not every phishing message requires a convincing link. Attackers are increasingly using AI to carry on convincing text conversations, often posing as an executive, colleague, or other trusted person. Once they have established trust, they may ask the victim to transfer money, share credentials, or take another sensitive action.
Traditional security awareness training was not designed for this environment. On a six-inch screen, many of the visual and contextual cues employees have been trained to scrutinize simply disappear. Asking an employee under pressure to distinguish an authentic executive from an AI-generated message or a synthetic voice clone is no longer a sufficient security strategy.
The human element remains one of the most frequently exploited entry points into the enterprise. In an AI-powered threat landscape, attackers do not need to defeat every security control or fool every employee. They only need to convincingly deceive one person on one device at the right moment.
Introducing Lookout Social Engineering Protection (SEP)
Today, we are introducing Lookout Social Engineering Protection (SEP), a new module within the Lookout Mobile AI Security Platform designed to protect the mobile workforce from the next generation of AI-powered deception.
Legacy security tools typically look for known threats, such as malicious URLs or other indicators of compromise. SEP goes further. It looks beyond the link itself, using AI to understand what a message is asking someone to do, who appears to be behind it, and whether the interaction looks suspicious. That helps SEP catch social engineering attacks across text and voice, including attacks that do not contain a malicious link.
- Smishing Protection: Continuously analyzes incoming SMS, MMS, and RCS messages on iOS and Android to detect malicious links, phishing attempts, and suspicious intent in real time.
- Vishing Protection: Analyzes audio and voicemail to detect AI-generated voice clones and deepfakes, while transcribing conversations to identify suspicious intent and scam patterns.
- Phone Number Authentication & Centralized Call Blocking: Checks mobile identity signals and phone-number information to help determine whether a caller is legitimate or suspicious. Security teams can use that information to apply risk-based policies and block known or suspicious numbers across employee devices.
By combining advanced language intent analysis, carrier-level identity verification, and synthetic voice detection, SEP identifies and intercepts AI-powered deception at machine speed, before an employee can be manipulated into taking an unsafe action.
Completing the Mobile AI Risk Triangle
With the launch of Social Engineering Protection, Lookout adds the third core pillar to its Mobile AI Security Platform. The platform now addresses three of the biggest risks facing the mobile workforce: how employees use AI and potentially expose data, vulnerabilities in the mobile apps they rely on, and social engineering attacks designed to manipulate people.
- AI Visibility & Governance: Protects enterprise data by providing visibility and control over employee interactions with generative, agentic, and Shadow AI applications.
- Mobile Software Exposure Center (MSEC): Reduces mobile software risk by continuously identifying vulnerable components, SDKs, and libraries embedded within compiled mobile applications.
- Social Engineering Protection (SEP): Protects employees from AI-powered deception by detecting and stopping smishing, vishing, voice cloning, and other sophisticated social engineering attacks in real time.
A New Defense for the Age of AI Deception
AI has accelerated deception. Human judgment has no such accelerator.
For more than 15 years, Lookout has analyzed mobile threat telemetry across 235 million devices and 400 million applications worldwide. We built Social Engineering Protection directly into the Lookout Mobile AI Security Platform, extending protection through the same lightweight agent and unified console our customers already use. Organizations can add these advanced defenses without deploying another agent, creating another security silo, or adding complex infrastructure.
The new enterprise perimeter is human, mobile, and increasingly targeted by AI. Our defenses must evolve accordingly.
