
Seqrite has warned organizations and individuals that human-targeted cyberattacks are outpacing purely technical threats in India. These attacks include shoulder surfing, phishing, vishing, smishing, impersonation, and digital honey traps. Despite the rise of automated and AI-assisted attacks, the most successful campaigns still exploit human trust, attention, fear, or routine behavior.
Social Engineering Tops Attack Vectors
According to Seqrite’s India Cyber Threat Report 2026, social engineering remains the leading attack vector reported by organizations, surpassing malware and web-application attacks. The report highlights that even advanced security technologies can be compromised when attackers manipulate employees into disclosing sensitive information or performing actions like scanning malicious QR codes or sharing OTPs.
One often-overlooked threat is shoulder surfing, where attackers observe users entering PINs, passwords, or confidential information in public spaces like offices, airports, or cafés. Even small pieces of information, when combined with public data, can enable fraud or intrusion attempts.
Rise of Human-Focused Campaigns
Seqrite’s analysis reveals a growing trend in human-focused campaigns that avoid traditional malware initially. For instance, digital honey traps use AI-generated profiles and realistic conversations on social media to build trust before extracting workplace information or private content. Victims are often later subjected to blackmail or coercion.
Read Also: SMEs plan budget hikes despite cyber risks and skills gaps
Attackers also exploit the familiarity of public services and brands. The report documents fake government-service apps and websites that mimic trusted interfaces to steal OTPs, payment details, and personal identifiers. Fraudsters use urgent language like “final notice” or “account blocked” to prompt immediate action.
Strengthening Human and Technological Defenses
While technology is essential, it must complement human judgment. Seqrite recommends a layered security approach that includes endpoint protection, identity monitoring, and behavioral analytics. During the reporting period, behavior-based security technologies detected over 34 million anomalous activities, showing their importance in identifying threats that traditional methods might miss.
Organizations are urged to strengthen the human layer of cybersecurity through continuous awareness programs, phishing simulations, and role-based training. Employees should be encouraged to verify unexpected requests and report suspicious activity. Practices like using privacy filters and being cautious in public spaces can reduce shoulder-surfing risks. Advanced solutions like Quick Heal AntiFraud.AI provide additional protection against evolving scams.
Leave a Reply