Industry executives and experts share their predictions for 2026. Read them in this 18th annual VMblog.com series exclusive.
By Stephanie Schneider, Cyber Threat Intelligence Analyst at LastPass
Modern-day security, without a doubt, has evolved beyond anything previously known. With the introduction of Zero Trust, systems have more demanding benchmarks for identity verification. With the introduction of multi-factor authentication (MFA), passwords are no longer the sole layer of security. And with endpoint detection and response (EDR), we’re going beyond traditional antivirus to stop advanced attacks in their tracks.
The list of defensive measures continues, yet there are still pervasive threats trying to evade every fortress defenders put up.
As security measures evolve to counter threats, cybercriminals evolve and find ways to circumvent them. It’s an ongoing game of tit for tat as defenders and attackers try to stay ahead of one another’s cyber chess board moves. That’s where humans come into play. Nobody’s perfect, and cybercriminals are counting on it. Humans are often described as the weakest link in cybersecurity, and social engineering is the resulting method of exploitation.
Given its relative ease and efficiency, social engineering will remain the primary method for threat actors to circumvent security controls and gain access.
According to research from Barracuda Networks, the average organization is targeted by over 700 social engineering attacks a year. As technical defenses mature – and the path of least resistance continues to shift toward humans – that number is poised to surge in 2026, especially as AI further amplifies attack scale and success.
Trouble On the Horizon: AI Set to Exacerbate Social Engineering Attacks
To maximize the success of a cyberattack, hackers tend to focus on three priorities: ease of entry, persistence, and impact. In other words, how can they gain access with minimal effort, remain undetected for as long as possible, and extract the greatest amount of valuable data? Increasingly, attackers have found that using social engineering to exploit identities and credentials is the most effective way to achieve all three objectives.
Credentials are arguably more valuable than endpoints, giving cybercriminals access to cloud applications and other sensitive business data while their malicious activity looks like nothing more than legitimate user behavior. It’s all about manipulating or tricking a victim into doing the hacker’s dirty work without them ever realizing. And while detecting a social engineering attack is hard, sometimes stopping the attack in the first place can feel even harder. You can fortify your systems, but even a well-trained employee can be caught off guard under pressure, urgency, or authority-based manipulation – especially as AI takes social engineering to an unprecedented level.
If social engineering is psychological manipulation, then AI is a force multiplier. Social engineering threats will become more sophisticated, personalized, and harder to detect as threat actors integrate AI into their attacks. Most of us have been trained to spot the “tells” of a social engineering attack: spelling mishaps, poor grammar, lack of context, offbeat tone; the list goes on. But, in the age of AI, it doesn’t take long for a cybercriminal to generate an attack with flawless language and hyper-personalized tone and context. What will make social engineering especially dangerous in 2026 is the growing inability of users to distinguish reality from deception.
As LLMs ingest information from public data, such as LinkedIn, social media, or company websites, social engineering targets are increasingly vulnerable. Would you be able to spot an attack if a phishing email referenced real projects or relationships, or a follow-up phone call contained an AI-generated deepfake audio of your executive? The answer, for many, is no.
Prepare for the Attack Today
While security training and human awareness remain critical, we’re living in an era where that cannot be your one and only defense. Social engineering is expected to take a sharp, upward turn in 2026, and now is the time to stay one step ahead.
- Secure identities first: Strengthen identity and access management (IAM) with Zero Trust networks, phishing-resistant MFA, and a least-privilege approach – granting users, applications, and systems only the access they need to do their jobs. This significantly reduces your attack surface and ensures you verify the identity of all network users.
- Close the basic gaps: Maintain strong patch management by regularly updating operating systems, applications, and firmware to fix bugs and eliminate known security vulnerabilities.
- Consider advanced, proactive defenses: Enhance protection with tools like AI-powered email filtering, secure browser extensions, and real-time link analysis to stop threats before they even reach users.
- Empower the people: Humans are still a critical layer of defense. Foster a security-aware culture that prioritizes ongoing education and encourages quick reporting of suspicious activity without fear or friction. Educate employees and customers on how to report social engineering attempts, so organizations can take proactive steps to raise awareness and shut them down when possible.
As social engineering attacks grow more targeted, believable, and popular amongst hackers, defending against them in 2026 will require a multifaceted approach that doesn’t prioritize system upgrades over human education and vice versa. The most capable defenses will come from combining modern security controls with continuous awareness and a clear understanding that people remain both the target and the solution.
##
ABOUT THE AUTHOR

Stephanie Schneider is passionate about raising awareness of cybersecurity challenges, blending strategic analysis with a deep understanding of how global geopolitical trends influence current threats. As a Cyber Threat Inteligence Analyst at LastPass, she tackles emerging threats, provides crucial intelligence insights, and monitors significant events in the cybersecurity landscape. Prior to joining LastPass, Stephanie served as VP, Nation-State Lead in Cyber Threat Intelligence at Bank of America, where she specialized in defending against nation-state and criminal cyber threats, including cyberespionage and information warfare. Her career is defined by a commitment to anticipating and mitigating cybersecurity risks on a global scale. Prior to working at Bank of America, Stephanie worked as a consultant for the Congressional Research Service and with the Atlantic Council.
Fluent in French and skilled in policy and cybersecurity research, Stephanie brings a unique international perspective to the cyber realm. Her team leverages analytical prowess to dissect and neutralize advanced cyber threats, ensuring robust protection for users globally. Her vision is to bridge the gap between technology and policy, creating a safer digital landscape through informed, strategic countermeasures. Stephanie can be found on LinkedIn.






