Employees have spent a decade learning to distrust suspicious email. Attackers adapted. Social engineering now increasingly arrives through phone calls, text messages, collaboration platforms and the help desk - channels that often carry more trust and fewer technical controls.
Social engineering is the use of deception to persuade people to disclose information, approve a transaction, reset credentials or grant access. The technique is not new. What changed is where attackers are applying it and how convincingly they can do it.
By the numbers:
41% of social engineering breaches involved a vector other than email, according to the 2026 Verizon Data Breach Investigations Report.
The human element was present in 62% of all breaches, up from 60% the year before.
Voice phishing ranked as the second most common initial infection vector in 2025, at 11% of investigations where a vector could be identified, according to M-Trends 2026.
Verizon puts the median click rate for email phishing simulations at about 1.4%. For phone-centric methods, it is closer to 2% - roughly 40% higher.
The implication is straightforward: email defenses became harder to bypass and employees became more cautious, so attackers shifted toward channels with a better return.
Corporate email has accumulated a decade of defenses: filtering, authentication standards, link rewriting, external-sender banners and attachment sandboxing. It is also the channel where employees receive the most security-awareness training. An unexpected email with a link now triggers suspicion in a way it often did not ten years ago.
That same defensive context usually does not exist elsewhere. A text message has no external-sender banner. A Microsoft Teams or Slack message arrives inside a platform employees associate with colleagues. A phone call has no filter beyond caller ID.
There is a behavioral side effect as well. By repeatedly teaching employees that email is where deception lives, organizations may have reinforced an unintended assumption that other channels are safer. Attackers are exploiting that trust gap.
Verizon now tracks pretexting separately from phishing. That distinction matters because the defensive behavior is different.
A phishing email is fixed. Employees can be taught to recognize suspicious links, unusual requests or other warning signs because the message does not change. A live pretext is adaptive. A threat actor can answer objections, supply supporting detail, increase urgency when a target hesitates and back off when pressing too hard would raise suspicion.
Consider a caller to accounts payable who knows the CFO is traveling, references a transaction already in progress and names the bank the company uses. None of that necessarily requires a prior breach. Public websites, LinkedIn profiles and press releases can provide enough detail to make the story sound legitimate. The challenge is no longer simply spotting a bad message; it is validating a plausible request.
Verizon documents attacks that use Microsoft Teams and Quick Assist to manufacture an IT emergency and persuade an employee to open a remote support session with legitimate tools already built into the operating system. There may be no malware for security software to detect because no malware was required.
The same technique works in reverse. An attacker can call the help desk, impersonate a legitimate employee and request a password reset or MFA re-enrollment. Help desks are designed to solve problems quickly for people who sound stressed or blocked. That service orientation is exactly what the attacker is trying to exploit.
For leadership, the practical conclusion is simple: help desk identity verification is now a security control, not merely a customer-service step. The process must be written down, consistently applied and able to withstand a caller who claims an urgent meeting or business deadline.
AI did not invent social engineering. It lowered the cost of executing it well.
Voice cloning can use public audio from earnings calls, conference panels, podcasts or voicemail greetings. Generative tools can produce fluent, context-specific pretexts in multiple languages. That makes old awareness advice - such as relying on poor grammar as a warning sign - less dependable.
Verizon data indicates 44% of AI-assisted initial access activity falls into the phishing category. More important for business leaders, research and personalization that once required significant operator time can now be produced much faster.
That change matters for mid-sized organizations. Highly tailored attacks were once concentrated on larger targets because tailoring was expensive. Lowering the cost makes more convincing pretexts economical against organizations that may not have built controls for that level of attention.
Email remains the largest single social engineering channel, and the defenses built around it still matter. But a comprehensive security-awareness program can no longer treat the inbox as the entire attack surface.
The more important question is whether the organization has verification controls that still work when a request sounds completely legitimate. As attackers move into trusted channels and use AI to improve the quality and scale of their pretexts, recognition alone is not enough. Verification has to carry the control.
Next in this series: People are one way into an organization. Unpatched technology is the other, and it recently overtook stolen credentials as the most common way in. Next: "The Shrinking Patch Window."
RubinBrown Cyber Security Services helps organizations assess social engineering exposure, test help desk and verification controls, and build awareness programs that cover the channels attackers actually use. Learn more about RubinBrown Cyber Security Services.
Published: 09/24/2026
Readers should not act upon information presented without individual professional consultation.
Any federal tax advice contained in this communication (including any attachments): (i) is intended for your use only; (ii) is based on the accuracy and completeness of the facts you have provided us; and (iii) may not be relied upon to avoid penalties.