In today's AI-interested world, UCaaS solutions, from Webex to Microsoft Teams, have been inundated with a raft of new AI features.
AI transcripts, AI Copilots, AI-enabled search—the list goes on.
Yet amid all the efficiencies and optimizations AI has brought to the UC sphere, it is important to understand that it has also brought new challenges.
This not only comes in terms of regulation or integration but in the form of new AI-enabled attacks.
Yes, AI has given attackers new ways of entering enterprises' systems, and with more and more communication over UCaaS solutions like Teams, they are becoming an increasing target.
But what exactly are the new threats to look out for in the age of AI? To find out more, UC Today spoke with Jeff Schumann, VP Collaboration Security and AI Strategist at cybersecurity company Mimecast, about the biggest cyber threats facing UCaaS users in the age of AI.
The Human Element: UCaaS Weakest Link
When it comes to cybersecurity vulnerabilities in UCaaS platforms, the greatest risk often lies with the users themselves.
"The human element is the primary weak point, and attackers are evolving to exploit it in new ways,"
Schumann said.
This comes in the evolution of the classic phishing attack. Previously, bad actors would have to trick you into opening an attachment or entering details on a fake link within an email or a message that looked like it was from a trusted source.
However, further inspection of the communique, like looking at the email address, would reveal it is not the same as the user name, and a hint of foul play would be revealed.
Yet, AI has changed these phishing attempts to remove any investigative attempts.
"Voice cloning, visual cloning, and deepfake-driven impersonation are making it nearly impossible for users to differentiate between real and fraudulent interactions," Schumann explained.
This means attackers are no longer needing to phish for credentials; they can manipulate individuals into handing over access willingly.
Think this is outlandish? A British engineering firm, Arup, last year confirmed it was the victim of a deepfake fraud after an employee was duped into sending £20 million to criminals using AI to replicate voices and images of senior officers of the company.
This highlights how sophisticated social engineering tactics have become, with attackers leveraging advanced technologies to create highly convincing impersonations.
What's more, such attempts at gaining access can bypass even the most robust security, as they don't contend with any technical element.
The challenge for organizations therefore has evolved further to not just implementing technical safeguards but also preparing their workforce to recognize these increasingly realistic deception techniques.
The stakes are particularly high given the central role UCaaS platforms play in modern business.
"UCaaS platforms are the modern workspace. This is where people do their jobs, hold critical business conversations, and exchange sensitive data. They've become the operating system of work, integrating at scale with other enterprise tools like CRMs and financial platforms,"
Schumann noted.
"Gaining control of a UCaaS platform means gaining access to workflows, decisions, and proprietary business intelligence. Protecting UCaaS is about protecting the entire business, not just the communications layer."
AI as Both Shield and Sword
As threats evolve, so too must defense mechanisms. AI is playing an increasingly crucial role in strengthening UCaaS security, offering capabilities beyond what traditional systems can provide.




