Social Engineering in the GenAI Era

The Numbers Behind the Threat

Part 3 of 5

Why the Voice Channel is Now the Front Line of Cyber Defense

AI-powered deception is rewriting the rules of cybersecurity.

Part 3

The Numbers Behind the Threat: Social Engineering Has Taken Over

Every major cybersecurity dataset released over the past 18 months points to the same conclusion: human deception, amplified by AI, has overtaken technical exploitation as the leading cause of enterprise compromise.

Below is a synthesis of the most authoritative research shaping that consensus.

Special 5-Part Series

Each installment in the Social Engineering in the GenAI Era series will be released weekly on Tuesdays, guiding readers through the evolving threat landscape and the critical role of voice security in modern cybersecurity defense.

This is Part 3.

CrowdStrike – Global Threat Report 2025

Source: https://www.crowdstrike.com/en-us/global-threat-report/

CrowdStrike’s data provides the clearest indicator of how fast voice-driven social engineering is accelerating.

  • Vishing attacks surged 442% between the first and second halves of 2024, the steepest increase ever recorded for any single intrusion vector.
  • “Access brokers,” criminal intermediaries selling actionable, stolen data, saw a 50% year-over-year increase in credentials and session tokens obtained via social engineering and voice pretexts.
  • The report concludes: “Attackers no longer need to exploit code; they can exploit conversation.”

Insight: The scale of vishing growth marks the inflection point where talking has become as dangerous as hacking. CrowdStrike’s data makes clear that voice compromise is no longer fringe activity, it is a mainstream intrusion path.

Unit 42 (Palo Alto Networks) – 2025 Global Incident Response Report (Social Engineering Edition)

Source: https://unit42.paloaltonetworks.com/2025-unit-42-global-incident-response-report-social-engineering-edition/

Unit 42’s investigation of thousands of breach cases identifies social engineering as the #1 initial access vector, responsible for 75% of incidents.

  • Average dwell time in these cases is six days. Attackers move faster when exploiting humans than when exploiting software.
  • Telephone-Oriented Attack Delivery (TOAD) campaigns now account for 17% of total incidents, combining phishing emails with phone callbacks that close the deception loop.
  • AI and automation have enabled “hyper-personalized pretexts at scale.”

Insight: Unit 42 confirms the operational shift from code-based intrusions to human-interaction attacks. The voice channel is now a measurable, documented vector in global incident data.

Proofpoint – The Human Factor 2025

Source: https://www.proofpoint.com/us/resources/threat-reports/human-factor-social-engineering

 Proofpoint’s research quantifies how social engineering has displaced malware delivery:

  • 25% of APT (Advanced Persistent Threat) campaigns use only social manipulation, no technical payload.
  • Controlled vishing exercises show 52% of participants voluntarily shared sensitive data.

Insight: Proofpoint demonstrates that the payload is no longer a file, it’s a conversation. AI makes that conversation believable, multilingual, and endless.

Mimecast – State of Human Risk 2025

Source: https://www.mimecast.com/resources/ebooks/state-of-human-risk-2025/

 Mimecast’s behavioral dataset reveals the fragility of the human layer:

  • 94% of CISOs rank human error as their top cyber risk.
  • Only 6% of organizations continuously update policies for emerging threats.
  • 40% of employees admit being too distracted to verify authenticity.
  • The report labels 2025 “The Decade of Human Risk,” warning that AI-generated deception is outpacing human attention.

Insight: Even the best training cannot overcome fatigue, multitasking, or AI-enhanced realism. Prevention must move upstream, before the call ever reaches a human.

ISACA – 2025 Emerging Technology & Risk Research

Source: https://www.isaca.org/about-us/newsroom/press-releases/2025/new-isaca-research-identifies–what-will-keep-tech-pros-up-at-night-in-2026

ISACA’s survey of technology professionals highlights growing anxiety around AI impersonation:

  • AI-driven social engineering ranks among the top five risks expected to define 2026.
  • 61% of respondents believe deepfake content will be “nearly impossible to detect” within a year.
  • The study warns of a “trust collapse” in digital and verbal communication alike.

Insight: Detection alone cannot solve a trust crisis. Technical verification, such as caller-authentication and call-reputation scoring, becomes a necessity.

EY – 2025 Global Cybersecurity Leadership Insights Report

Source: https://www.cybersecuritydive.com/news/artificial-intelligence-security-risks-ey-report/803490/

EY’s Global CISO Survey quantifies the governance gap:

  • 95% of organizations are using AI in cyber operations.
  • 81% fear AI tools are introducing new vulnerabilities.
  • 55% lack a formal AI-risk framework.

Insight: The same technology enterprises deploy for defense is arming adversaries. Leadership knows the risk, yet most lack the controls to contain it.

Social-Engineer LLC – State of Vishing Report 2025

Source:  https://www.social-engineer.com/state-of-vishing-report/

Through live testing, Social-Engineer LLC exposes the power of voice manipulation:

  • 52% of participants divulged confidential data.
  • 33% failed even after being warned a test was in progress.
  • Audio cues of authority and empathy consistently overrode training.

Insight: The human ear remains the easiest exploit surface. Voice authenticity triggers compliance more reliably than any written message.

IBM – Cost of a Data Breach Report 2025

Source: https://www.ibm.com/reports/data-breach

IBM’s global cost model shows that breaches initiated through social engineering are the most expensive, averaging $4.9 million per event, nearly $1 million higher than the overall mean.

Insight: The financial weight of deception now exceeds that of technical compromise, reinforcing the urgency for pre-emptive controls.

Every day, millions of calls traverse Enterprise Voice, Enterprise Collaboration, Contact Center and Carrier systems with no inspection, scoring, or authentication.

The voice channel, once considered benign, is now the perfect storm of trust, immediacy, and invisibility, a pathway where AI deception meets human vulnerability.

Verizon – Data Breach Investigations Report 2024

Source: https://www.verizon.com/business/resources/reports/dbir/

Verizon’s robust dataset mirrors IBM’s findings:

  • 68% of breaches involve a “non-malicious human element.”
  • Credential theft and social engineering remain the top two actions leading to compromise.
  • Analyst Insight: Every dataset, regardless of scope or geography, illuminates that people are both the path of least resistance, and the easiest path to exploitation.

Mutare – 2024 Voice Threat Survey (Full Report)

Source: https://www.mutare.com/voice-threat-survey/

Mutare’s proprietary survey brings voice-specific precision to the global trend:

  • 70% of enterprises faced a voice-borne threat in the past year.
  • 50%+ experienced measurable productivity loss from unwanted calls.
  • 94% of security leaders believe voice must be integrated into cyber strategy, yet fewer than 20% have deployed technical controls.

Insight: Awareness of the voice threat is nearly universal, but operational action is rare. This gap defines both the risk and the opportunity for enterprise voice defense.

Composite Insight

DIMENSIONCONSENSUS ACROSS SOURCES
Dominant Threat VectorSocial Engineering (phishing, vishing, hybrid deception) has overtaken system exploitation.
Fastest-Growing ChannelVoice-based vishing and hybrid call-back scams (+442%, CrowdStrike).
Human Risk Factor>90% of incidents trace to human engagement (Mimecast, Verizon, IBM).
AI ImpactGenAI enables hyper-personalized, scalable deception (Unit 42, ISACA, EY).
Financial ImpactSocial-engineering breaches cost ≈ $4.9 M per event (IBM).
Voice Control Gap< 20% of organizations have technical voice defenses (Mutare).

Conclusion

Across independent global datasets, the message is unequivocal:

  • Social engineering has become the primary breach driver.
  • Voice is the fastest-growing delivery vector.
  • AI is the force multiplier.

Enterprises that fail to secure voice traffic are statistically certain to encounter compromise.

The solution is clear: deploy a Voice Firewall to filter, score, and authenticate inbound calls before human interaction, converting the enterprise’s most trusted channel into its most defensible one.