Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Defending against AI-fueled social engineering

Social engineering has always been the softest edge of enterprise defense, and AI is sharpening adversaries’ attacks. Phishing, business email compromise, and impersonation still dominate the initial-access playbook, but AI has stripped out the cost, time, and skill barriers that once forced attackers to choose between reach and precision.

Human Error Remains at the Core of AI-Enabled Social Engineering

AI is making social engineering attacks significantly more effective, according to a new report from cyber insurance firm Resilience. These attacks were behind more than 85% of losses in the first half of 2026, compared to less than 20% during H1 2024. “Losses tied to phishing, social engineering, and transfer fraud have climbed from 17.7% of incurred losses in H1 2024 to 85.3% in H1 2026, the single largest increase in the report’s five half-year comparison,” Resilience says.

AI Did Not Invent Social Engineering But It Did Industrialize It.

This year National Social Engineering Day falls on Aug. 6. This day is designed to give us an opportunity to remind people that cybercriminals do not always need sophisticated malware, an undisclosed vulnerability or a dark room filled with glowing monitors, sometimes, all they need is a good story. Social engineering existed long before computers. Confidence tricks, impersonation, false authority and appeals to greed or fear have been used for centuries.

How to Protect Yourself from Online Scams and Cyber Threats

The internet has become a huge part of our daily lives, from banking and shopping to connecting with friends and family. While this digital integration is incredibly convenient, it also exposes us to more and more sophisticated online scams. To protect your digital assets, you need to stay alert and understand the threats out there. This guide offers practical steps to help you navigate the online world safely and avoid common problems.

Report: Social Engineering Remains a Central Part of AI-assisted Attacks

Threat actors continue to rely on social engineering as AI is incorporated into their attacks, according to ESET’s Threat Report for the first half of 2026. ESET’s Director of Threat Prevention Labs, Jiří Kropáč, stated, “Rather than relying on entirely new methods and tools, attackers are quickly adapting established techniques to new platforms, technologies, and user behaviors.

ClickFix Social Engineering is Now the Leading Malware Delivery Method

The ClickFix social engineering technique is now the top malware delivery method, according to a new report from ReliaQuest. These attacks trick users into copying a malicious command, then pasting it into a terminal and running it on their computers. “ClickFix remained the dominant delivery method this period and, for the first time, we observed it expand to macOS, delivering infostealers onto a platform many organizations still monitor less closely than Windows,” the researchers write.

Hyper-Targeted Social Engineering Needs Real-Time Video Response

There’s an important metric that can tell you exactly how vulnerable your high-risk employees and departments are to the next generation of social engineering. It’s not phishing click rates or training completion percentages. It probably doesn’t show up on any security dashboard. It’s the precise number of days it takes your team to respond to a live, context-specific threat with adequate training – training time to market.

Physical Mail and the Overlooked Attack Surface

Cybersecurity investment has never been higher. Organisations are running zero trust architectures, deploying endpoint detection across every device, and monitoring network traffic in real time. Physical mail rarely appears on the threat register for most security teams, yet mail-based attack vectors are active and documented, and tend to be effective in part because they attract less scrutiny than digital channels.

Report: AI-Enabled Social Engineering Attacks Are on the Rise

Threat actors are increasingly using AI-enabled social engineering to get around technical security measures, according to a new report from Visa. Social engineering attacks were behind the largest number of losses in the second half of last year. “From July to December 2025, Visa identified nearly $1 billion in scam-related activity, making scams the single largest category of consumer payment fraud,” Visa says.