Social Engineering Statistics

26 STATS17 SOURCES

Social Engineering by Industry

Latest Statistics

58% of internal audit leaders identify automated social engineering as a leading AI-enabled fraud threat.

The Internal Audit Foundation and AuditBoardInternal Audit and AI-Enabled Fraud·3mo ago
Automated Social EngineeringAI FraudInternal Audit

77% of organizations have been targeted by deepfake attacks.

DeepfakeSocial Engineering

51% of organizations have faced sophisticated, personalized phishing emails powered by deepfake technology.

PhishingDeepfakeSocial Engineering

In Q4 2025, callback phishing increased from 3% to 18% of all phishing incidents, a 500% spike.

VIPRE Security GroupQ4 2025 Email Threat Trends Report·3mo ago
PhishingCallback PhishingEmail SecuritySocial Engineering

In 2025, 'ClickFix' social engineering techniques were used in 1% of phishing attacks.

PhishingPhishing TechniquesSocial EngineeringClickFix

63% of retailers plan to invest significantly in generative AI for social engineering attacks.

RetailGen AISocial engineeringBudgetInvestment

65% of organizations expressed serious concern about IT help desk bypass and social engineering attacks as a top threat.

IT help desk bypassSocial engineering

Nearly a third of leaders at financial services firms admit they are not fully confident employees could recognize an AI-driven phishing or social engineering threat.

Financial services AI-driven attackPhishingSocial engineering

64% of surveyed enterprises confirmed social engineering attacks via encrypted or informal channels in the past 12 months.

EnterprisesSocial engineering

38% of organizations admit to being underprepared for AI-driven social engineering threats such as automated attacks, deepfake-based videos, and voice scams.

AISocial engineeringDeepfakesVoice scams

AI-enhanced phishing and social engineering are the most concerning tactics (27%) for insider threats.

Insider threatAIPhishingSocial engineering

78% of security leaders identify social engineering and phishing as their top threat.

Social engineeringPhishing

Fake CAPTCHA social engineering attacks, particularly ClickFix campaigns, jumped 1,450% from the second half of 2024 to the first half of 2025.

Social engineeringCAPTCHA

Social engineering attacks accounted for 39% of initial access incidents observed during the first half of 2025.

Social engineering

51% of respondents consider AI-enhanced social engineering a fairly or extremely significant concern.

AISocial engineering

44.7% of respondents cited phishing/social engineering as a top concerning threat.

PhishingSocial engineering

44.7% of respondents cited phishing/social engineering as a top concerning threat.

PhishingSocial engineering

28% of healthcare executives say they are likely to invest in generative AI for social engineering attacks.

HealthcareAIGen AISocial engineering

Social engineering attacks (48%) and ransomware (34%) were the most common types of cyberattacks on healthcare organizations in the past year.

HealthcareSocial engineeringRansomware

28% of healthcare executives say they are likely to invest in generative AI for social engineering attacks.

HealthcareAIGen AISocial engineering

56% of financial professionals cite social engineering as a significant tactic powered by AI.

Financial servicesFinancial fraudSocial engineeringAI

Social Engineering was the second-most common incident pattern in the region, with phishing appearing in 19% of breaches in EMEA.

Social engineeringPhishingEMEA

The FBI received 193,407 complaints about phishing/spoofing in 2024 (versus 298,878 in 2023 and 321,136 in 2022).

Social engineeringPhishingSpoofing

20% of phishing emails between September 15, 2024 and February 14, 2025 relied solely on social engineering.

PhishingSocial engineering

In Q4 2024, HP threat researchers saw a growth in social engineering campaigns that rely on fake CAPTCHA challenges to infect users with malware

Social EngineeringFake CAPTCHAQ4 2024Malware

42% of organisations reported phishing and social engineering attacks in 2024.

World Economic ForumGlobal Cybersecurity Outlook 2025 ·1y ago
PhishingSocial engineering