TLDR: Palo Alto Networks’ 2025 Unit 42 Global Incident Response Report highlights a significant rise in social engineering attacks, with 60% leading to data exposure. The report, based on 700 investigations across 49 countries, reveals that alert fatigue and vulnerabilities in privileged accounts are key weaknesses. Generative AI is identified as a major amplifier, enabling more sophisticated and scalable deception tactics.
Palo Alto Networks has released its 2025 Unit 42 Global Incident Response Report: Social Engineering Edition, shedding light on the escalating threat of identity-driven cyberattacks. The comprehensive report, compiled from 700 real-world investigations spanning 49 countries, underscores that human and process vulnerabilities are increasingly being exploited by attackers, often bypassing advanced technical controls.
One of the most alarming findings is that 60% of social engineering incidents resulted in data exposure, a significantly higher rate compared to the 44% across all other attack types. Furthermore, 13% of these incidents were directly linked to ignored or untriaged security alerts, indicating that “alert fatigue” remains a critical weakness for cybersecurity defenders.
Attackers are employing two primary playbooks: “High-touch compromise” involves real-time impersonation of employees or IT staff to circumvent authentication, while “At-scale deception” utilizes tactics such as SEO poisoning, malvertising, and fake browser prompts to trick users into granting access.
The report explicitly highlights the amplifying role of Generative AI in these evolving threats. AI technologies are enabling attackers to craft highly tailored lures at an unprecedented scale, generate convincing voice clones for impersonation, and even automate entire social engineering campaigns from inception to execution.
Systemic gaps within organizations are further compounding the risk. A staggering 66% of social engineering cases targeted privileged accounts, which significantly widens the potential impact of a breach. Credential recovery mechanisms, such as IT help desk resets, are routinely abused to bypass multi-factor authentication (MFA). Additionally, 10% of incidents were attributed to missing or misconfigured MFA protections.
Industries most affected by breaches leading to data exposure include manufacturing (15%), followed by professional services and retail. High-tech industries, however, remain the most frequently targeted overall.
Providing an Indian perspective, Swapna Bapat, VP and MD, India & SAARC, Palo Alto Networks, stated, “India’s pace of digital adoption is extraordinary, and with that comes a unique challenge. While we’re quick to embrace new technology, the layers of awareness and process maturity that secure those systems often take longer to build.”
To counter these sophisticated threats, the report recommends adopting Zero Trust principles for both people and networks. It also emphasizes the importance of correlating identity signals with Identity Threat Detection and Response (ITDR) and User and Entity Behavior Analytics (UEBA) tools to accelerate abuse detection. Strengthening recovery workflows and conducting live simulations to enhance organizational awareness at all levels are also crucial steps.
Also Read:
- Exabeam’s 2025 Report: AI Accelerates Insider Threats, Outpacing External Attacks
- Accenture Intensifies Focus on AI and Cybersecurity Amidst Growing Threat Landscape
Phishing, a classic social engineering tactic, continues to be a dominant initial access vector, accounting for 65% of all social engineering-driven cases, underscoring that human factors, not just technology, are key vulnerabilities.


