← All posts
StatisticsJuly 30, 2026 · 3 min read

Social Engineering Statistics 2026: The Numbers Behind the Human Element

The key social engineering statistics for 2026 — from the 62% of breaches involving the human element to the 442% surge in vishing and the $40B deepfake fraud forecast — with sources.

Chart-style graphic summarizing key social engineering statistics for 2026

Security budgets keep flowing into infrastructure, yet year after year the breach data points at the same root cause: people being manipulated. This page collects the most important social engineering statistics for 2026 — each with its original source — so you can use them in board decks, budget requests, and awareness programs.

Last updated: July 2026. We revise this page as major reports are released.

The headline numbers

Statistic Figure Source
Breaches involving the human element 62% Verizon DBIR 2026
Breaches involving a third party 48% (up 60% YoY) Verizon DBIR 2026
Growth in vishing attacks (H1→H2 2024) +442% CrowdStrike GTR 2025
Projected deepfake-enabled fraud losses by 2027 (US) $40B Deloitte
Read vendor-compromise emails engaged with 44.2% Verizon DBIR 2026
Attack techniques where median actor used AI 15 Verizon DBIR 2026

The human element is still the front door

The Verizon 2026 Data Breach Investigations Report found that 62% of breaches involved the human element — phishing, pretexting, stolen credentials, or plain error. Credential abuse alone appeared in 39% of breaches, remaining one of the most reliable ways into an organization.

Two details in the 2026 data deserve more attention than the headline:

  • Third-party risk is human risk. 48% of breaches involved a third party — a 60% increase year over year. Attackers increasingly compromise a supplier and then social- engineer their way into the real target. Vendor email compromise is brutally effective: 44.2% of read vendor-compromise messages were engaged with by employees, because a known supplier asking for an invoice change simply does not look suspicious.
  • AI is now table stakes for attackers. The median malicious actor leveraged AI across 15 documented attack techniques — from lure generation to voice cloning.

Voice is the fastest-growing channel

Email still carries volume, but growth belongs to the phone. CrowdStrike's Global Threat Report documented a 442% surge in vishing between the first and second half of 2024, driven by help-desk impersonation and callback scams that route victims from a harmless-looking email to a hostile phone call.

The financial tail is long. The FBI's IC3 recorded $924.5 million in US tech-support scam losses in a single year — a scam category that is essentially vishing with a script — and phone-based fraud losses overall run into the tens of billions annually.

Deepfakes moved from novelty to line item

Deepfake audio and video have crossed from proof-of-concept to routine tooling:

  • Deloitte projects generative-AI-enabled fraud could reach $40 billion in US losses by 2027.
  • Group-IB found over 10% of banks have already suffered deepfake-vishing losses above $1 million, with an average loss around $600,000 per incident.
  • Asia-Pacific saw a 194% year-over-year surge in deepfake scams in 2024 — a preview of what other regions are now experiencing.

Finance teams are the natural target: a cloned CFO voice asking for an urgent transfer defeats every email control you own. (We cover defenses in our guide to human risk management.)

What the numbers mean for your program

Three practical conclusions follow directly from the data:

  1. Test the channels attackers use. If your program only simulates email, you are testing a shrinking slice of the threat. Voice, SMS, QR codes, and messaging apps need the same treatment — see how NOUSEC simulates 8 channels.
  2. Measure engagement, not just clicks. The vendor-compromise engagement rate shows that "would my people act on a plausible request?" is the question that matters.
  3. Quantify it. A single trended metric — a Human Risk Score — turns these industry statistics into your statistics, which is what boards and regulators actually respond to.

The ENISA Threat Landscape and NIST SP 800-50r1 both point the same direction: social engineering keeps its top ranking, and awareness programs are expected to produce measurable outcomes.

If you want to know where your organization stands before an attacker finds out for you, book a demo and see your baseline Human Risk Score.

Frequently asked questions

What percentage of breaches involve the human element in 2026?

According to the Verizon 2026 Data Breach Investigations Report, 62% of analyzed breaches involved the human element — social engineering, errors, or misuse of credentials.

How fast are vishing attacks growing?

CrowdStrike's 2025 Global Threat Report documented a 442% increase in voice phishing (vishing) attacks between the first and second half of 2024, and the channel has kept growing since.

How big is deepfake fraud expected to become?

Deloitte's Center for Financial Services projects that generative AI–enabled fraud, including deepfakes, could reach $40 billion in losses in the United States by 2027.

Are third-party breaches also a human problem?

Largely yes. Verizon's 2026 DBIR found 48% of breaches involved a third party, and vendor email compromise is particularly effective — 44.2% of read vendor-compromise emails were engaged with by employees.

See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo