
Palo Alto Networks has released its 2025 Unit 42 Global Incident Response Report: Social Engineering Edition, revealing that attackers are increasingly targeting people—not just technology—to break into organizations.
Based on more than 700 incident response cases handled worldwide between May 2024 and May 2025, the report found that 36 percent of all cyber incidents started with social engineering tactics. These schemes rely on tricking individuals into giving away access, rather than exploiting technical flaws.
Interestingly, not all attacks relied on email phishing. More than one-third used other methods, such as search engine manipulation, fake pop-up prompts, and even impersonating IT help desks.
Faster, smarter, more deceptive
The report highlights two main trends:
- Targeted scams – Criminals impersonate employees, manipulate help desks, and escalate privileges in real time using stolen identities and voice lures.
- Mass deception – Large-scale tricks like fake browser updates, SEO poisoning, and callback scams that trap thousands of users at once.
Key Findings
- Weak Detection Still a Problem – 13% of critical security alerts went unnoticed or misclassified, giving attackers an open door to exploit systems.
- Business Disruption Rising – Over half of the incidents exposed sensitive data or disrupted operations.
- AI Boosts Attacks – Nearly a quarter (23%) of incidents involved AI-powered lures such as fake calls or voice prompts.
- Money is the Goal – 93% of cases were financially motivated, showing how cheap and effective social engineering has become.
- Industries Hit Hardest – Manufacturing (15%), professional/legal services (11%), wholesale/retail (10%), and financial services (10%) topped the list.
In the Philippines, identity fraud, illegal access, and data interference remain common threats. The government’s National Cybersecurity Plan (2023–2028) addresses these risks through stronger incident response teams and public cyber awareness campaigns.
“The biggest weakness in cybersecurity isn’t always the system—it’s trust,” said Philippa Cogswell, Vice President and Managing Partner of Unit 42, Asia-Pacific & Japan at Palo Alto Networks. “Attackers are now using AI to scale deception. Organizations must protect not only their networks but also their people and processes. Staying ahead requires collective resilience.”
What organizations should do
The report stresses that awareness campaigns are no longer enough. Companies must build stronger defenses by:
- Securing identities – Use analytics and Identity Threat Detection and Response (ITDR) to spot unusual logins, MFA abuse, and stolen credentials early.
- Adopting Zero Trust – Enforce least-privilege access and network segmentation to contain intrusions.
- Protecting human workflows – Strengthen verification at help desks and identity recovery points, and train frontline staff against impersonation.
- Monitoring beyond email – Track browsers, DNS, and collaboration tools to block fake prompts and malicious links.
Full report: 2025 Unit 42 Global Incident Response Report – Social Engineering Edition