The Current State of Social Engineering: 8 Threats Security Leaders Must Prioritize in 2026
Social engineering is no longer limited to poorly written phishing emails sent indiscriminately to thousands of recipients.
Modern campaigns combine artificial intelligence, stolen personal data, compromised business accounts, synthetic media, voice calls, collaboration platforms, and carefully researched pretexts. Attackers are not simply trying to convince someone to click a suspicious link. They are attempting to manipulate established business processes, trusted relationships, and identity controls.
For security leaders, the current state of social engineering presents a difficult reality: the attack surface now includes every employee, contractor, executive, supplier, communication channel, and approval workflow connected to the organization.
The Verizon 2025 Data Breach Investigations Report analyzed 22,052 security incidents and 12,195 confirmed breaches, demonstrating the continuing importance of attacks involving human behavior, credentials, and organizational processes. Meanwhile, the FBI received more than one million internet crime complaints during 2025, with reported losses exceeding $20 billion.
Security awareness remains necessary, but awareness alone cannot address the current threat. Organizations need to treat social engineering as an adversarial risk that must be modeled, tested, detected, and controlled across people, technology, and business processes.
Key Takeaways
- Generative AI is increasing the speed, quality, and personalization of social engineering campaigns.
- Business email compromise remains one of the most financially damaging forms of cybercrime.
- Attackers increasingly target identities, workflows, help desks, collaboration tools, and trusted vendors rather than relying only on malicious attachments.
- Deepfake audio and video are making executive impersonation more credible.
- Security awareness training must be supported by technical controls, resilient approval processes, and adversarial testing.
- Security leaders should measure whether the organization can resist manipulation, not simply whether employees completed annual training.
What Is Social Engineering?
Social engineering is the use of psychological manipulation, deception, impersonation, or manufactured urgency to influence a person into taking an action that benefits an attacker.
That action may include:
- Disclosing credentials or sensitive information
- Approving a financial transaction
- Resetting an account password
- Registering a new multifactor authentication device
- Installing remote access software
- Opening a malicious file or website
- Granting access to a building, system, or application
- Changing supplier payment information
- Bypassing an established security procedure
The defining feature of social engineering is not the communication channel used. It is the manipulation of human judgment or organizational trust.
A phishing email, fraudulent help desk call, deepfake video conference, malicious QR code, fake recruitment approach, and vendor impersonation campaign can all be components of the same social engineering operation.
The Current State of Social Engineering in 2026
The most important change in social engineering is not that attackers have discovered entirely new psychological principles. Urgency, authority, fear, curiosity, scarcity, and trust continue to influence decision-making.
What has changed is the operational capability available to attackers.
Generative AI can improve grammar, translate messages, imitate communication styles, research targets, create synthetic identities, and produce convincing content at scale. Information-stealing malware and data breaches provide the personal and organizational context needed to make those messages believable.
Microsoft reports that threat actors are using AI to automate phishing and support increasingly complex, multistage attack chains. ENISA has also identified artificial intelligence as a defining element of the current threat landscape, with AI-supported phishing reportedly representing a significant share of observed social engineering activity by early 2025.
The result is an industrialized social engineering ecosystem in which attackers can rapidly move from reconnaissance to impersonation, credential theft, account takeover, financial fraud, and persistent access.

Ranked: The 8 Social Engineering Threats Security Leaders Must Prioritize
The following threats are ranked according to their current business impact, scalability, frequency, and potential to bypass organizational controls.
1. Business Email Compromise and Payment Fraud
Business email compromise remains the most important social engineering threat for many organizations because it targets business processes directly.
Rather than delivering malware, the attacker impersonates or compromises a trusted identity and attempts to influence a financial or operational decision. Common targets include accounts payable teams, finance leaders, executives, payroll departments, procurement teams, and employees responsible for supplier relationships.
Typical scenarios include:
- A compromised supplier account requesting updated banking details
- An executive requesting an urgent wire transfer
- A fraudulent invoice inserted into a legitimate email conversation
- A payroll change request impersonating an employee
- A legal or acquisition-related payment presented as confidential
- A fake customer requesting a refund to a different account
Business email compromise is particularly dangerous because the malicious request may arrive through a legitimate mailbox. The message may contain no malware, suspicious attachment, or obviously malicious link.
The FBI’s 2025 Internet Crime Report found that business email compromise remained one of the largest categories of reported financial loss. Overall reported internet crime losses surpassed $20 billion during the year.
What Security Leaders Should Do
Organizations should require independent verification for payment changes, new banking instructions, high-value transfers, payroll modifications, and unusual refund requests.
Verification should occur through a known communication channel rather than contact information contained in the request itself. Financial controls should also incorporate transaction thresholds, dual approval, separation of duties, behavioral analytics, and defined escalation procedures.
2. AI-Enhanced Spear Phishing
Generative AI has reduced the effort required to create credible and personalized phishing messages.
Attackers can use public websites, professional profiles, breached data, social media posts, job descriptions, press releases, and supplier information to construct messages that closely reflect a target’s role and current responsibilities.
AI-enhanced phishing can help an attacker:
- Correct spelling and grammatical errors
- Translate campaigns into multiple languages
- Recreate executive communication patterns
- Produce role-specific pretexts
- Generate convincing follow-up messages
- Adapt messages after receiving a response
- Create fake documents, websites, and identities
The main risk is not that every phishing message will become perfect. It is that attackers can test, refine, and personalize significantly more campaigns without a corresponding increase in cost.
Microsoft’s 2025 defense reporting describes the growing use of AI for automated phishing and other stages of cyber operations. ENISA similarly identified AI-supported social engineering as a major component of the evolving threat environment.
What Security Leaders Should Do
Security teams should move beyond organization-wide phishing simulations that send the same template to every employee.
Testing should reflect real roles, accessible information, business relationships, communication channels, and likely adversary objectives. Executives, finance personnel, developers, help desk staff, human resources teams, and system administrators face different pretexts and should be tested accordingly.
3. Credential Phishing and Session Theft
Credential phishing continues to provide attackers with a direct path into cloud services, email accounts, customer platforms, development environments, and administrative systems.
Modern phishing infrastructure may replicate a legitimate sign-in experience and relay authentication requests in real time. This can allow an attacker to capture credentials, session cookies, authentication tokens, or multifactor authentication responses.
Once an account is compromised, attackers can:
- Search email for sensitive information
- Identify financial workflows
- Register forwarding rules
- Contact customers and suppliers
- Access cloud storage
- Impersonate the victim internally
- Launch additional phishing campaigns
- Abuse trusted application permissions
This makes identity compromise both an initial access technique and a mechanism for expanding the social engineering campaign.
What Security Leaders Should Do
Phishing-resistant authentication should be prioritized for administrators, executives, finance teams, developers, and other high-impact roles.
Security teams should also monitor for suspicious sign-ins, impossible travel, unusual device enrollment, mailbox rule creation, token reuse, consent grants, authentication method changes, and access from unfamiliar infrastructure.
Multifactor authentication remains important, but not every form of MFA provides equal resistance to phishing.
4. Help Desk and Identity Recovery Manipulation
Help desks and account recovery processes have become high-value targets because they can provide a legitimate path around technical identity controls.
An attacker may call a service desk while impersonating an employee and request:
- A password reset
- Enrollment of a new authentication device
- Removal of an existing MFA method
- Account recovery assistance
- Access to an internal application
- Changes to contact information
The attacker may possess enough personal information to answer standard verification questions. That information may come from previous data breaches, social media, professional networking sites, criminal data markets, or compromised employee records.
The weakness is often not the employee handling the call. It is an identity recovery process that relies on information an attacker can obtain.
What Security Leaders Should Do
Identity recovery should be treated as a privileged security workflow.
High-risk requests should require stronger verification, documented escalation, manager involvement, device-based confirmation, or in-person validation where appropriate. Help desk employees should be trained and authorized to stop a request when the context appears inconsistent.
Security leaders should also test these processes through controlled social engineering exercises.
5. Vishing and Collaboration Platform Impersonation
Voice phishing, commonly called vishing, has expanded beyond traditional telephone calls.
Attackers now contact employees through Microsoft Teams, messaging platforms, video conferencing tools, personal mobile numbers, and other channels that employees associate with trusted business communication.
A common scenario involves an attacker posing as internal IT support. The attacker may claim that the employee’s device is infected, an account has been compromised, or an urgent software update is required.
The target is then persuaded to:
- Install remote access software
- Open a command prompt
- Run a script
- Share a screen
- Provide an authentication code
- Visit a malicious website
- Approve an unexpected login
In a recently disclosed campaign observed between February and June 2026, attackers impersonated IT personnel through Microsoft Teams and attempted to gain remote access. Some compromises reportedly progressed to ransomware deployment within hours.
What Security Leaders Should Do
Organizations should define exactly how IT support personnel communicate with employees and what they will never request.
Controls should restrict unauthorized remote access tools, monitor script execution, limit communication from external Teams accounts where practical, and alert on suspicious administrative activity following support interactions.
Employees should have a fast, well-known method for independently verifying an IT request.
6. Deepfake Executive and Vendor Impersonation
Synthetic audio and video can make impersonation attacks more persuasive, particularly when the target believes they are communicating with an executive, customer, supplier, recruiter, or trusted colleague.
Attackers can generate synthetic media using publicly available recordings, conference presentations, podcast appearances, earnings calls, webinars, social media videos, and corporate marketing content.
Deepfakes may be used to reinforce an existing pretext rather than operate as a standalone attack. For example, a fraudulent payment request may begin through email and then be supported by a synthetic voice call or manipulated video meeting.
The strategic risk is clear: seeing or hearing someone is no longer sufficient proof of identity.
What Security Leaders Should Do
Organizations should never rely solely on voice or video recognition for high-impact approvals.
Sensitive requests should be verified through established processes, authenticated systems, trusted contact methods, and transaction-specific controls. Executives should understand that publicly available audio and video can contribute to impersonation risk.
Deepfake scenarios should also be included in tabletop exercises involving finance, communications, executive protection, legal, and incident response teams.
7. Smishing, QR Phishing, and Mobile-First Attacks
Employees increasingly conduct business through mobile devices, creating opportunities for attackers to use text messages, mobile applications, QR codes, and consumer communication channels.
Mobile interfaces often display less information about a sender, domain, or destination. Employees may also be more likely to act quickly while traveling, moving between meetings, or working outside a controlled office environment.
Common mobile-first pretexts include:
- Missed delivery notifications
- Payroll or benefits updates
- Authentication warnings
- Calendar invitations
- Shared document notifications
- Travel disruptions
- Executive requests
- QR codes presented as login or payment shortcuts
QR phishing can be particularly effective because the destination is concealed until the code is scanned, and the interaction may transfer the user from a managed workstation to a less-monitored personal device.
What Security Leaders Should Do
Mobile threat defense, safe-link inspection, domain monitoring, device management, and clear reporting procedures should complement security awareness.
Organizations should also evaluate whether employees are being asked to complete sensitive workflows through channels that the security team cannot adequately monitor or authenticate.
8. Recruitment, Contractor, and Synthetic Identity Attacks
Remote hiring and distributed work have created opportunities for attackers to use fabricated or stolen identities to gain legitimate access to organizations.
A malicious applicant may use an AI-generated profile, manipulated identification documents, a proxy interview participant, or synthetic video during the hiring process. The objective may be financial fraud, intelligence collection, unauthorized access, data theft, or the placement of malware inside the organization.
Recruiters and candidates are also targeted through fake job postings, fraudulent interview invitations, malicious coding assignments, and counterfeit onboarding documents.
Microsoft reported continued use of AI-generated personas in schemes involving fraudulent remote technology workers, illustrating how identity deception can extend beyond traditional phishing.
What Security Leaders Should Do
Human resources, talent acquisition, security, identity teams, and hiring managers should jointly define verification requirements for remote candidates and contractors.
Controls should include identity validation, consistent interview procedures, device shipping safeguards, geographic and payment anomaly review, least-privilege access, and enhanced monitoring during the early stages of employment.
Why Traditional Security Awareness Training Is Not Enough
Annual awareness training often assumes that social engineering is primarily a knowledge problem.
That assumption is incomplete.
Employees may understand phishing and still approve a fraudulent request because:
- The message arrives from a compromised account
- The request matches their job responsibilities
- The attacker references accurate internal information
- The employee is placed under time pressure
- The apparent sender has organizational authority
- The process itself lacks meaningful verification controls
- Reporting a suspicious request is slow or difficult
- Challenging an executive or customer feels professionally risky
Security awareness can help employees recognize and report suspicious behavior. It cannot compensate for weak approval workflows, excessive privileges, inadequate identity controls, insufficient monitoring, or an organizational culture that rewards speed over verification.
Security leaders should stop treating people as the control of last resort. Business processes must be designed to remain secure when an employee is distracted, pressured, deceived, or operating with incomplete information.
How Threat Modeling Improves Social Engineering Defense
Threat modeling helps organizations examine how an attacker could manipulate the interaction between people, technology, and business processes.
A risk-driven threat model can identify:
- Which employees control high-impact actions
- What information an attacker can obtain about them
- Which communication channels are trusted
- Where identity is assumed rather than verified
- Which workflows allow one person to approve a sensitive action
- How a compromised account could influence other employees
- What controls could prevent or detect manipulation
- What business impact would follow a successful attack
- This is especially important because social engineering rarely exists in isolation.
A successful campaign may combine breached credentials, public intelligence, cloud misconfiguration, weak help desk verification, excessive permissions, and an unmonitored payment process. Focusing only on the phishing message misses the larger attack path.
VerSprite’s PASTA threat modeling methodology begins with business objectives and application context before examining technical threats, weaknesses, attack scenarios, and residual risk. This allows security teams to evaluate social engineering in relation to the business processes and assets an attacker is attempting to reach.

How VerSprite Tests Social Engineering Risk
VerSprite approaches social engineering as an adversarial security problem rather than a compliance exercise.
Our teams evaluate how real attackers may use publicly available intelligence, trusted relationships, technical weaknesses, identity processes, and organizational behavior to reach a defined objective.
Depending on the authorized scope, an assessment may examine:
- Email phishing resistance
- Voice phishing scenarios
- Help desk verification procedures
- Executive impersonation risks
- Physical access processes
- Supplier and payment workflows
- Credential recovery controls
- Remote access procedures
- Publicly exposed employee information
- Escalation and incident reporting processes
The objective is not to embarrass employees or produce a simple click rate.
The objective is to determine whether an attacker can convert human interaction into meaningful business impact, identify why the control environment allowed that path, and provide practical remediation guidance.
A Social Engineering Defense Framework for Security Leaders
A mature social engineering program should include several mutually reinforcing layers.
1. Model the Business Process
Identify the people, applications, communication channels, decisions, and approvals involved in high-impact workflows.
2. Identify Likely Adversary Objectives
Focus on outcomes such as account takeover, fraudulent payments, intellectual property theft, remote access, identity compromise, and data exfiltration.
3. Reduce Publicly Available Intelligence
Evaluate what executives, employees, suppliers, technologies, and organizational structures are visible to an attacker.
4. Strengthen Identity Controls
Deploy phishing-resistant authentication, stronger recovery procedures, conditional access, device trust, and effective identity monitoring.
5. Engineer Resilient Workflows
Require independent verification and multiple approvals for sensitive changes and transactions.
6. Test Realistic Scenarios
Use controlled exercises based on actual roles, technologies, business processes, and threat intelligence.
7. Make Reporting Easy
Employees should be able to report suspicious email, voice, text, collaboration, and physical interactions quickly.
8. Measure Security Outcomes
Track reporting behavior, detection speed, process failures, control effectiveness, repeat exposure, and remediation completion rather than relying only on training completion rates.
What Security Leaders Should Prioritize Now
The current state of social engineering requires security leaders to reconsider the idea that employees simply need to become better at identifying deception.
Attackers are targeting the systems around the employee: identity recovery, supplier management, executive authority, payment approvals, remote support, cloud authentication, and internal trust.
The most effective defense is not a single technology or annual training module. It is a risk-driven combination of resilient processes, strong identity controls, behavioral detection, security culture, threat modeling, and realistic adversarial testing.
Organizations should assume that some fraudulent messages will reach employees and that some attempts will appear convincing.
The critical question is whether one manipulated interaction can result in a material security incident.
Frequently Asked Questions
What is the current state of social engineering?
The current state of social engineering is defined by more personalized, multichannel, and AI-assisted attacks. Adversaries combine phishing, voice calls, text messages, collaboration platforms, synthetic media, stolen credentials, and compromised accounts to manipulate employees and business processes.
What is the biggest social engineering threat to businesses?
Business email compromise is among the most serious social engineering threats because it directly targets payment processes, supplier relationships, payroll changes, and executive authority. Credential phishing and help desk manipulation are also major risks because they can provide access to trusted organizational accounts.
How is artificial intelligence changing social engineering?
Artificial intelligence allows attackers to improve message quality, translate campaigns, research targets, imitate communication styles, create synthetic identities, and generate convincing audio, video, documents, and websites more efficiently.
Can multifactor authentication stop social engineering attacks?
Multifactor authentication reduces many account takeover risks, but not every form of MFA is equally resistant to phishing. Attackers may use real-time phishing proxies, session theft, push fatigue, help desk manipulation, or fraudulent device enrollment to bypass weaker authentication processes.
Why is security awareness training not enough?
Training cannot correct every weakness in identity verification, payment approval, access recovery, supplier management, or organizational culture. Employees need technical controls and business processes that prevent one deceptive interaction from causing significant harm.
How can organizations test their social engineering defenses?
Organizations can conduct authorized social engineering assessments, phishing and vishing simulations, help desk testing, tabletop exercises, threat modeling, and workflow reviews. Testing should reflect realistic adversary objectives and measure whether existing controls prevent meaningful business impact.
How does threat modeling address social engineering?
Threat modeling identifies the people, assets, trust relationships, technologies, and business processes an attacker may target. It helps organizations understand how social engineering could combine with technical weaknesses and identifies controls that reduce the likelihood and impact of a successful attack.
What should security leaders prioritize to reduce social engineering risk?
Security leaders should prioritize phishing-resistant authentication, secure account recovery, independent transaction verification, dual approval for sensitive actions, realistic adversarial testing, simple reporting mechanisms, and threat modeling of high-impact business workflows.
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /