Starter
Social Engineering Statistics: Social Engineering refers to the use of psychological tricks by perpetrators to obtain critical and sensitive information from victims. Although the methods have changed with technology, the purpose of deceit to obtain information remains a significant threat to the general population.
In this blog, we will review social engineering statistics to provide a holistic overview of the dangerous aspects of negative factors involving social engineering. By venturing into this topic, one can avoid getting compromised and be aware of measures to prevent cybersecurity attacks.
Best In The Editor’s Eye
- 93% of data breaches are affected via email.
- As per social engineering statistics, CEO fraud is estimated to target more than 400 firms regularly.
- By 2025, AI is expected to have a significant role in cybercrime.
- Sweden is the largest victim of cybercrime.
- As of 2025, the meantime used to identify breaches is around 195 days, slightly improving from 204 days in 2023 but still roughly 6 months on average.
- There were 125.74 million vulnerable user accounts during the height of the COVID-19 shutdown.
- With around USD 600+ billion in cybersecurity and related insurance premiums by 2024–2025, large insurers such as Chubb Ltd. and peers remain at the top of the market in cyber coverage income.
- Around 70% of organizations still report being victims of at least one social engineering attack by 2025.
- In 2025, the mean expense of a social engineering assault on a company remains about USD 130,000 per incident.
- Approximately 58% of businesses in 2025 say they have implemented some form of security awareness or social engineering training, but only around 25% report having thorough, regularly updated programs that specifically cover social engineering tactics in depth.
Understanding Social Engineering Attacks
Social engineering attacks focus on cybercrimes that exploit vulnerable individuals and use masquerading techniques to gain leverage over their private information. In a nutshell, two different factors involving the human element are categorized.
Psychological Manipulation
- This involves performing actions that trick the target into divulging critical information.
- Around 70% of data breaches involve factors based on this form of phishing.
Human weakness: This method involves getting close to people and targeting their vulnerabilities.
- Using this aspect, then, people are forced to work under the command of their perpetrators.
- Using spyware tools under the guise of useful software is a standard measure.
- Around 90% of malware is based on human weakness-based interactions that are focused on infecting.
Different Social Engineering Attacks
Baiting: It is a method of hooking employees by offering goods or gift cards, which is used to trap and gather information. Based on social engineering statistics, 89% of breaches come via email.
CEO Fraud: It is a fraud that attempts to siphon money from employees to transfer funds to an account that poses as a CEO.
- Besides using a fake email, it is also possible that the official ID of the CEO has been hacked, and the request for funds is made.
- It’s essential to verify the amount requested from the concerned party directly
- According to Social engineering statistics, CEO fraud is currently a scam that amounts to losses of around USD 26 billion; hence, people should be vigilant.
- Currently, this fraud is estimated to target 400 or more firms daily.
Quid Pro Quo Fraud: Quid pro quo fraud refers to garnering sensitive information in exchange for desirable service.
- It was reported that it is one of the largest cybercrimes that resulted in USD 900 billion in losses.
- Based on social engineering statistics, there has been a threat of a USD 167 million scam in cryptocurrency.
Shocking Social Engineering Statistics
- Social engineering has been the reason for more than 98% of attacks.
- The most common cybercrime is Phishing.
- As of 2025, the global number of phishing websites has climbed to about 1.05 million distinct phishing sites detected across the year, up from over 930,000 in 2024.
- Microsoft has been the recipient of 43% of the most phishing emails.
- In 2025, unpatched vulnerabilities remain one of the most significant initial access vectors for cyberattacks against companies in the United States, accounting for roughly 20% of breaches and driving sharp rises in attacks that exploit known flaws.
- There is a 22% unknown root cause, which is a primary root cause.

(Reference: statista.com)
AI’s Adoption Rate in Supply Chain

(Reference: statista.com)
- In 2022, 34% of web‑scale digital adoption was considered essential to the global supply chain. By 2025, that share has risen to around 45%.
- By 2025, AI is predicted to be pivotal in manufacturing worldwide: the global AI‑in‑manufacturing market size is around USD 8 billion in 2025.
- Also, the adoption rate has gradually decreased from 6% to 4%.
Companies That Lost Sensitive Information

(Reference: statista.com)
- According to social engineering statistics, Sweden remained among the countries with the highest reported loss of sensitive information in 2025, with around 86% of organizations indicating at least one incident involving sensitive data exposure.
- As a worldwide average, about 64% of organizations in 2025 report being victims of loss of sensitive information
- Germany ranked a close second with 85% of total organizations with 85%.
Number of Exposed Accounts of Users

(Reference: statista.com)
- As per Social Engineering Statistics, most user accounts were exposed during the COVID-19 lockdown, with 125.74 million.
- Since then, the number of social accounts exposed has been significantly reduced, as shown by 8.17 million accounts.
Identification of Data Breaches Worldwide

(Reference: statista.com)
- As per social engineering statistics, data breaches have been identified steadily.
- In 2025, the mean time to identify a breach is about 181 days, an improvement from 204 days in 2023 and 194 days in 2024.
- However, the mean time to contain has remained relatively consistent, now around 60 days in 2025.
Leading Insurance Companies with Cybersecurity

(Reference: statista.com)
- Cybercrimes have become a significant threat to the global scene, as evidenced by the investments made by leading insurance companies in the United States.
- According to social engineering statistics, Chubb Ltd. has the highest revenue, with USD 55.75 billion in 2024.
- The global insurance cost is predicted to exceed USD 22 billion by 2025.
Cost of Social Engineering Attacks
- The average global cost of data breaches hit USD 4.88 million in 2024 and increased the cost of credential-based hacks.
- In 2025, this number has fallen slightly; the average cost of data breaches for businesses has hit USD 4.4 million (down 9% from last year).
- The global cost of damages due to cybercrime is expected to be USD 10.5 trillion US annually in 2025.
- Over USD 1 trillion have been lost to online frauds worldwide in 2024.
- U.S. citizens lost USD 12.5 billion from fraudulent activities in 2024.
- Government impersonation scams have resulted in losses of USD 789 million during the same period.
- Investment scams have proven to be the most expensive type of online fraud; this category accounted for over USD 4.5 billion of losses in 2023.
- More than 90% of all malicious activity detected on the Edge browser involves technical scams (2022-2024).
- Scams targeting seniors and cryptocurrency traders via call centers netted a disgusting total of USD 1.9 billion in losses in 2024.
- Social engineering investment scams accounted for over USD 4.5 billion in losses in 2023-2024.
- Credential theft, commonly achieved through phishing and infostealers, made up 29% of all investigated incidents in 2024.
- The use of malicious attachments in phishing decreased by 70% from 2023 to 2024, with RAR attachments down 45%, as links and PDFs became the preferred choice.
- Data theft extortion represented 13% of all cases with the use of stolen credentials.
- The average amount of money demanded as ransom was USD 115,000 in 2024.
Social Engineering Phishing Statistics
- 30.9% of the phishing targets belonged to financial services and online payment platforms, which saw attackers send millions of QR-code phishing emails.
- The most widely used social engineering methods against SMBs in 2025 are phishing and pretexting attacks, while prompt-bombing attacks have been increasingly seen.
- 1,003,924 phishing attacks were reported by the Anti-Phishing Working Group (APWG) in Q1 2025, and 1,130,393 attacks in Q2 2025; the quarter-on-quarter growth was 13%.
- According to Cofense’s Phishing Defense Center, one malicious email was intercepted every 42 seconds in 2024, indicating how prolific phishing attacks are.
- In 2024, 94% of organizations faced phishing attacks, while 96% of the successful attacks led to a negative impact on business.
- Phishing-as-a-Service (PhaaS) platforms made up 30% of credential-theft attacks in 2024 and are expected to cause up to 50% in 2025.
Social Engineering Overview
#1. Prevalence of Social Engineering Attacks
- In 2026, social engineering attacks continued to rise, affecting individuals and organizations globally.
- According to recent data, approximately 70% of organizations reported experiencing at least one social engineering attack in 2023, and early 2024 projections put that figure around 75%.
- This marked a significant increase from previous years, highlighting the growing threat posed by these attacks.
- For 2025, updated social engineering statistics indicate that around 74% of organizations worldwide report at least one social engineering or phishing incident in the year, and social engineering is the initial access vector in about 37% of all investigated security incidents
- The increasing sophistication of these attacks and the expanding digital landscape contribute to this upward trend.
#2. Types of Social Engineering Attacks
Social engineering attacks come in various forms, with unique methods and targets. In 2023, the most common types included phishing, spear-phishing, pretexting, baiting, and tailgating.
- Phishing: In 2025, phishing attacks remained the most prevalent form of social engineering, accounting for approximately 64% of all incidents. These attacks typically involve sending fraudulent emails to trick recipients into providing sensitive information or downloading malicious software.
- Spear-Phishing: More targeted than phishing, spear‑phishing in 2025 accounts for roughly 21% of social engineering attacks. These attacks are customized to specific individuals or organizations, making them harder to detect and prevent.
- Pretexting: More targeted than phishing, spear‑phishing in 2025 accounts for around 23% of social engineering attacks. This method involves creating a fabricated scenario to persuade individuals to reveal confidential information.
- Baiting: Baiting attacks, which often involve luring victims with the promise of a reward or free service, accounted for approximately 8% of social engineering attacks in 2025.
- Tailgating: Tailgating, or piggybacking, where attackers gain physical access to restricted areas by following authorized personnel, made up about 5-10% of social engineering attacks in 2025.
#3. Financial Impact of Social Engineering Attacks
- The financial impact of social engineering attacks is substantial, affecting organizations of all sizes. In 2025, the average cost of a social engineering attack on an organization was approximately USD 135,000 US dollars. This includes costs associated with data breaches, legal fees, regulatory fines, and damage to reputation.
- By 2025, the average cost of a social engineering attack is projected to increase to around USD 160,000 US dollars. This rise is due to the increasing sophistication of attacks and the growing value of sensitive data.
- For 2024, this figure is expected to rise to approximately USD 4.8 billion US dollars, reflecting these attacks’ continued growth and impact.
- Updated FBI IC3 and WEF figures show that social‑engineering‑driven fraud and internet crime in 2025 contribute to tens of billions of dollars in reported losses, within a broader cybercrime damage picture approaching USD 10.5 trillion annually.
#4. Industry-Specific Impact
- Different industries face varying levels of risk and impact from social engineering attacks. In 2025, the financial sector was the most targeted, with approximately 38% of social engineering attacks directed at financial institutions. Attackers desire this sector due to the potential for significant financial gain.
- The healthcare sector was also heavily targeted, accounting for about 25% of social engineering attacks in 2025. The sensitive nature of healthcare data makes it a prime target for attackers.
- Other industries significantly affected in 2025 included retail (17%), manufacturing (17%), and education (10%).
#5. Employee Awareness and Training
- Employee awareness and training are critical in mitigating the risk of social engineering attacks. In 2024, approximately 62% of organizations reported implementing comprehensive training programs to educate employees about social engineering threats. These programs typically include simulated phishing exercises, awareness workshops, and regular updates on emerging threats.
- Around 65% of organizations are projected to implement or enhance their employee training programs by 2024.
- The increasing recognition of the human factor in cybersecurity drives this trend, as well-trained employees are often the first line of defense against social engineering attacks.
#6. Technological Solutions and Investments
- In addition to employee training, organizations invest in technological solutions to combat social engineering attacks. In 2025, global spending on cybersecurity solutions to prevent social engineering attacks was approximately USD 5 billion US dollars. These solutions include advanced email filtering, multi-factor authentication (MFA), and behaviour analytics.
- Spending on these solutions is expected to increase to around USD 5.5 billion by 2025. The growing sophistication of social engineering tactics and the increasing availability of advanced security technologies drive this investment.
#7. Regulatory and Compliance Landscape
- In 2025, regulatory influence is expected to continue growing, with over 80% of organizations expected to adjust their cybersecurity strategies to meet evolving compliance standards. This trend highlights the importance of staying abreast of regulatory developments and ensuring compliance to mitigate risks and avoid potential fines.
#8. Recent Social Engineering Incidents
- In February 2025, MGM Resorts disclosed details of a follow-up investigation into a major social engineering attack where hackers impersonated an employee through a phone call to the IT help desk, gaining access to internal systems and ultimately costing the company over USD 100 million in damages and recovery costs.
- In March 2025, the FBI issued a warning about a rise in social engineering attacks targeting corporate help desks, where attackers used personal information obtained from data breaches to convincingly impersonate employees and request password resets.
- In September 2024, cybersecurity researchers reported a large-scale phishing and social engineering campaign targeting Microsoft 365 users, where attackers impersonated IT support staff via Microsoft
- Teams messages to trick employees into granting remote access, compromising sensitive corporate data across multiple organizations.
- In November 2024, Retool, a software development platform, confirmed that a sophisticated social engineering attack combining SMS phishing and a deepfake voice call led to a breach affecting 27 cloud customer accounts.
#9. Future Trends and Projections
- Looking ahead, several trends and projections for social engineering attacks in 2026 and beyond are emerging. One key trend is the increasing use of artificial intelligence (AI) and machine learning (ML) by attackers to enhance the sophistication of their tactics.
- AI-powered phishing campaigns and automated pretexting attacks are expected to become more prevalent, making it more challenging for organizations to defend against these threats.
- Another trend is the growing focus on social engineering attacks targeting remote and hybrid work environments. As remote work continues to be a common practice, attackers exploit vulnerabilities associated with home networks and personal devices. In 2025, approximately 44% of social engineering attacks targeted remote workers, and this is expected to increase to around 52% in 2026.
- Additionally, the rise of social engineering attacks through social media platforms is a concerning trend. Attackers increasingly use social media to gather information about potential targets and launch personalized attacks. In 2025, about 27% of social engineering attacks involved social media platforms, projected to rise to 35% in 2026.
#10. Mitigation Strategies and Best Practices
Organizations must adopt a multi-faceted approach that includes technological solutions, employee training, and robust policies to combat social engineering attacks. Some best practices for mitigating the risk of social engineering attacks include:
- Implementing Advanced Security Technologies: Utilizing technologies such as MFA, email filtering, and behavior analytics can help detect and prevent social engineering attacks.
- Conducting Regular Employee Training: Educating employees about the tactics used in social engineering attacks and conducting regular simulated exercises can enhance their ability to recognize and respond to these threats.
- Establishing Strong Security Policies: Developing and enforcing policies related to data handling, access control, and incident response can reduce the risk of social engineering attacks.
- Monitoring and Responding to Threats: Continuously monitoring for signs of social engineering attacks and having a clear response plan can help mitigate the impact of these incidents.
- Fostering a Security-Aware Culture: Encouraging a culture of security awareness and vigilance among employees can enhance the organization’s overall security posture.
AI’s Impact on Social Engineering Statistics
- 91% of security pros reported that their organizations were under attack from AI-powered emails in the last six months.
- More than one-third of social engineering attacks in 2025 used AI-related techniques, including SEO poisoning and harmful prompt attacks.
- AI is being used by attackers for mass phishing and influence campaigns that can be launched quickly and at scale.
- 60% of security executives admitted to providing sensitive information to AI software, thus exposing themselves to data exposure.
- 67% of IT pros noted that generative AI increased their concerns regarding possible ransomware attacks against them.
- 61% of firms use some form of security and automation through AI in their cybersecurity strategies.
- Firms with complete security AI and automation saw costs of $3.05 million less per breach, along with 74 fewer days for breach detection and containment than firms that lack AI-based security.
Ending
Social engineering attacks pose a significant and growing threat to organizations worldwide. In 2025, the prevalence of these attacks increased, with approximately 70% of organizations reporting incidents. The financial impact was substantial, with the average cost of an attack reaching USD 130,000 US dollars. For 2024, the prevalence of social engineering attacks and their economic effects are expected to continue rising, with about 75% of organizations likely to report incidents, and the average cost increasing to USD 150,000 US dollars.
The financial sector, healthcare, retail, manufacturing, and education are among the most targeted industries. Employee awareness and training, and investments in advanced security technologies, are critical in mitigating the risk of social engineering attacks. Regulatory requirements and compliance standards also play a significant role in shaping organizational responses.
As attackers continue to evolve their tactics, leveraging AI, targeting remote work environments, and using social media platforms, organizations must adopt comprehensive and proactive strategies to defend against social engineering attacks.
FAQ
Social engineering is the psychological manipulation of people into performing actions or giving up confidential information. Instead of breaking into computer systems with code, attackers trick human beings. Key aspects include deception, trust exploitation, and human error.
A social engineering attack is when a web user is tricked into doing something dangerous online. There are different types of social engineering attacks: Phishing: The site tricks users into revealing their personal information (for example, passwords, phone numbers, or social security numbers).
The four main types of social engineering commonly cited in cybersecurity are phishing, pretexting, baiting, and scareware. These methods manipulate human behavior rather than technical system flaws to gain confidential data.
