# Social engineering: the attack path around the firewall

**Social engineering** has become the dominant way into corporate systems, and the numbers make the shift clear. Security budgets keep rising, yet documented losses keep climbing. Unit 42 puts social engineering behind 36% of all documented intrusions between May 2024 and May 2025, overtaking technical vulnerabilities and traditional exploits. A human element appears in 98% of attacks, and 60% of data breaches involve a person, whether through a careless error, psychological manipulation or credential abuse.

## The attack is now a staged operation

The malformed email with obvious grammar errors is gone. Modern social engineering combines deep reconnaissance, open-source intelligence and behavioural manipulation. Attackers spend weeks studying targets: they map reporting lines from LinkedIn, identify moments of change such as a supplier switch, a merger or the onboarding of a new executive, and strike then. Two thirds of social engineering attacks target privileged accounts, and in 45% of cases the attacker impersonates internal staff.

Time to compromise has collapsed. One group moved from initial access to domain administrator in under 40 minutes using native operating system tools and no malware. The median time for a user to fall for a phishing message is under 60 seconds, too short for a SOC analyst or an automated control to intervene.

## ClickFix and the fake CAPTCHA

The defining technique of 2025 is ClickFix. Attacks built on fake CAPTCHA pages rose 1,450% between the second half of 2024 and the first half of 2025, and now account for 39% of initial access incidents. The mechanism is simple. Attackers compromise legitimate sites or register domains that imitate trusted brands, then show what looks like a standard verification step, often carrying the branding of Cloudflare Turnstile or Google reCAPTCHA. Clicking the verify button does not start a puzzle. It walks the user through opening the Windows Run prompt, pasting a command that the page copied silently to the clipboard, and pressing Enter.

Microsoft documented thousands of devices compromised every month through this route, including machines with active EDR. Payloads range from infostealers such as Lumma Stealer, DarkGate and Vidar to remote access trojans such as NetSupport and to ransomware. The Interlock group uses ClickFix as its primary entry vector, targeting IT professionals with pages that imitate tools like Advanced IP Scanner.

## Industrial ransomware

Social engineering opens the door; ransomware monetises the intrusion. Attacks against industrial operators rose 46% between the fourth quarter of 2024 and the first quarter of 2025, with 2,472 potential attacks documented in that single quarter, 40% of the whole 2024 total. Manufacturing absorbs two of every three industrial ransomware incidents and has held the top target position worldwide for four consecutive years.

The logic is economic: production lines cannot stop. A compromised SCADA system in a chemical plant or a power station carries public safety risk as well as financial loss, and attackers calibrate demands accordingly. Median payments moved from USD 200,000 in early 2023 to USD 1.5 million by mid-2024, and ransomware payments reached a record USD 460 million in the first half of 2025. The largest single payment on record, USD 75 million, went to the Dark Angels group. Ransomware-as-a-service has industrialised the model: groups such as Qilin, SafePay and Anubis offer affiliate platforms where mid-level criminals buy ready-made attack infrastructure. SafePay moved from 13 industrial victims in the first quarter of 2025 to 49 in the second.

## The cost sits beyond the ransom

The global average cost of a data breach reached USD 4.44 million, and the figure for the United States hit a record USD 10.22 million. Direct costs include forensic investigation and containment, mandatory customer notifications, credit monitoring and regulatory fines that reach 4% of global turnover or EUR 20 million under the GDPR. Indirect costs weigh more. Three quarters of organisations take over 100 days to recover fully, and 65% of consumers lose trust in a company after a breach. Healthcare carries the highest average at USD 7.42 million, followed by financial services at USD 5.56 million. Personal identifiable information appears in 53% of breaches, and 30% involve data spread across on-premise, public cloud and SaaS environments, where resolution cycles stretch to 276 days.

## AI on both sides

Attackers use AI at three levels: automation that speeds up reconnaissance and targeting, generative tools that produce personalised phishing text, [cloned voices and deepfake video](/en/ecorner/2023/deepfake-identity-protection.html), and autonomous agents that run multi-step campaigns and build synthetic identities. Voice cloning works from three seconds of audio, and deepfake vishing rose 1,600% in the first quarter of 2025. One documented case saw a cloned executive voice persuade a manager to transfer USD 35 million.

The defensive picture is uneven. Organisations with extensive AI and automation in security save on average USD 1.9 million per breach and shorten detection and containment by 68 days, yet 97% of those that suffered an AI-related incident lacked proper access controls and 63% had no governance policy for AI use. Shadow AI adds roughly USD 670,000 to the average breach cost.

## The supply chain is the shortest path

Supply chain attacks grew from 15% to 20% of all breaches in 2025, with an average cost of USD 4.91 million and detection times 26 days longer than other categories. In the first half of 2025, 79 supply chain attacks directly affected 690 organisations and indirectly touched 78.3 million people. Scattered Spider reached Marks & Spencer, the Co-operative Group and Harrods through phishing against a third-party IT provider, using admin credentials to compromise systems serving over 1,400 stores. Yale New Haven Health suffered the largest healthcare breach of the year when attackers exploited a poorly protected data segment managed by an external supplier outside the core clinical systems.

## Why perimeter defences miss

The mismatch is architectural. Most organisations keep buying perimeter tools designed to stop technical threats, while 60% of breaches begin with the manipulation of a person. Four systemic weaknesses explain the rest: 13% of successful breaches come from security alerts nobody investigated, 10% from accounts with wider privileges than the role requires, 10% from critical accounts without multi-factor authentication, and 32% of human-related breaches from credential abuse.

Stolen credentials are reused within 48 hours to reach cloud systems or resold on the dark web. The more advanced groups, such as Muddled Libra, also known as Scattered Spider, bypass MFA by calling the help desk, impersonating a locked-out employee, passing a shallow identity check and persuading an operator to reset a password or disable two-factor authentication temporarily.

## What changes outcomes

The countermeasures with measurable returns are unglamorous. Continuous anti-phishing training cuts the click rate on malicious email by 43% after twelve months, and quarterly simulations with updated scenarios outperform annual sessions. A reporting rate above 60% on suspicious email is a useful operational target. Tested incident response pays: organisations with a rehearsed, current plan save USD 2.66 million per breach, and quarterly drills should involve executives, legal, communications and IT.

Identity work matters just as much: privileged identity management with just-in-time elevation, phishing-resistant MFA such as FIDO2 for administrative accounts, and full separation between on-premise and cloud privileges. On the supplier side, regular security attestation from critical vendors, least privilege for external access and continuous monitoring of third-party connections reduce the blast radius of a partner compromise.

## Frequently asked questions

**Why do trained employees still fall for phishing?**
The attacks exploit universal cognitive biases such as authority, reciprocity, scarcity and urgency, and the median decision window is under a minute. Training reduces the click rate; it does not remove human judgement from the loop.

**What makes ClickFix different from ordinary phishing?**
The user executes the payload voluntarily. The page instructs them to paste a command into the Windows Run prompt, so perimeter controls and sandboxes see a legitimate user action rather than a malicious download.

**Does multi-factor authentication stop social engineering?**
It blocks the simplest credential attacks. Help-desk manipulation and session hijacking can still bypass it, which is why phishing-resistant factors such as FIDO2 and identity verification procedures matter.

**How can a small business harden its supply chain?**
Start with an inventory of critical vendors, require security attestation at renewal, apply least privilege to external access and monitor third-party connections for unusual activity.

## Sources

Unit 42 — 2025 Global Incident Response Report, Social Engineering Edition — https://unit42.paloaltonetworks.com/2025-unit-42-global-incident-response-report-social-engineering-edition/
LevelBlue — Threat Trends Report, ClickFix growth and initial access share — https://levelblue.com/newsroom/press-releases/levelblue-threat-trends-report-edition-two-2025
Microsoft Security Blog — analysing the ClickFix social engineering technique — https://www.microsoft.com/en-us/security/blog/2025/08/21/think-before-you-clickfix-analyzing-the-clickfix-social-engineering-technique/
IBM — Cost of a Data Breach Report 2025, global and US averages — https://www.ibm.com/reports/data-breach
Honeywell — 2025 Cyber Threat Report, ransomware against industrial operators — https://www.honeywell.com/us/en/press/2025/06/ransomware-attacks-targeting-industrial-operators-surge-46-percent-in-one-quarter-honeywell-report-finds
KnowBe4 — social engineering attacks in the first half of 2025 — https://blog.knowbe4.com/social-engineering-attacks-surged-in-the-first-half-of-2025
