90% of All Cyber Attacks on Organizations Involve Social Engineering

Stu Sjouwerman | Oct 1, 2021

90% Cyber Attacks Involve Social EngineeringIt’s official: threat actors and cybercriminal gangs alike are enlightened and have locked in on the use of social engineering as the primary means to trick recipients into becoming victims.

At the end of the day, any attack that utilizes email as the delivery mechanism requires the engagement of the email recipient. Whether your users are clicking a link, opening an attachment, or performing the requested task, your users have to do something to enable an attack.

It’s one of the reasons social engineering has become a staple in the threat actor’s arsenal of tools. And, according to Positive Technologies’ Cybersecurity Threatscape: Q2 2021 report, social engineering is nearly ubiquitous across all attacks and are involved in 90% of all cyberattacks. With email used as the primary method of distribution of malware (58% of attacks), it’s necessary to use social engineering to both get the recipient’s attention and motivate them to engage with the malicious email content.

To get a better sense of how social engineering is used, take a look at some of the other stats from this report:

  • 77% of attacks were targeted (spoofing of a brand or individual is likely used)
  • 73% of attacks involve malware (an attachment or link is the singular focus)

Additionally, the report highlights the focus for the majority of campaigns:

  • 69% of attacks on organizations involve ransomware
  • 59% of attacks were intent on gaining access to data

With social engineering taking such a prominent place in cyberattacks, it has become necessary to counteract these tactics with Security Awareness Training. Your users can be both vigilant on the types of attacks and the specific campaigns so they are armed with an understanding of current social engineering tactics and know how to identify them.

See KnowBe4 Security Awareness Training in Action

See how you can efficiently safeguard your organization from sophisticated social engineering threats.

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.