451 RESEARCH BY S&P GLOBAL DISCOVERY REPORT COMMISSIONED BY DELETEME
Your employees’ personal data is now attack infrastructure.
- 300+ security leaders surveyed
- AI impersonation attacks are getting personal
- Existing controls weren’t built for these attacks
- No link. No attachment. Attackers now weaponize trust.
Get the Report
Independent research · n=303 security practitioners and leaders · Fielded 2026 · Published by 451 Research by S&P Global
The attacks changed.
The assumption didn’t.
92%
say AI has increased the overall effectiveness of social engineering attacks.
91%
say personal data available online or through data brokers increases their exposure to it.
67%
still consider that exposure an individual privacy issue rather than a corporate security issue.
Those three numbers can’t all be comfortable at once. The report is about what happens in the space between them.
What the research covers
01
Token costs, spam infrastructure at 100,000-device scale, and where the money is made downstream — including who buys access after the initial compromise.
02
Role and job function (77%), family, interests, or life history (72%), direct contact information (72%), org structure (65%) — ranked by how much easier they make AI-powered techniques.
03
Helpdesk and IT staff are seen as the most commonly hit. Executives carry the most severe business impact. The two answers aren’t the same, and the gap matters for how you prioritize.
04
74% say they’re very or extremely prepared. 61% say their SecOps tooling struggles with exactly this attack class. Both are in the same dataset.
05
Identity verification (54%) and security awareness training (51%) top the list of most effective controls — with monitoring or removal of employee personal data close behind, and a note on why these rankings reflect security teams’ view rather than end users’ experience.
06
59% say a successful incident, a peer getting hit, or regulatory pressure is what would accelerate spend.
Figure 2 · From the report
Specific PII types make AI-driven attacks easier for adversaries
Base: All respondents (n=303). AI-driven social engineering & impersonation risk survey 2026. Source: 451 Research by S&P Global and DeleteMe.
”Attackers used to log in. Now they talk their way in — and the script is written from data your employees never knew was public.“
Why “we’re prepared” and “our tools don’t catch it” are both true
A social engineering attempt that arrives with no malicious link, no attachment, and no brand impersonation doesn’t trip a detection rule. A user who approves an MFA prompt they didn’t initiate hasn’t done anything unauthorized. There’s nothing for SecOps to intervene on — the activity is valid, the identity is valid, the permissions are valid. Only the intent is wrong, and intent is the one thing your stack can’t see.
That’s why 82% of teams told 451 Research that traditional email tools and awareness training aren’t sufficient for the current threat, even as the same teams reported high confidence in detection and response. The controls are working on the attacks they were designed for.
say they are “very” or “extremely” prepared
say traditional SecOps tools struggle with these attacks
What the report says about the input side
42% of organizations have an active, org-wide initiative to remove employee PII or reduce digital footprints. 20% are evaluating or piloting. 18% cover high-risk and executive personnel only. Meanwhile 55% monitor online PII exposure continuously or automatically — leaving nearly half checking monthly, quarterly, or not at all.
The report’s conclusion is not “buy more detection.” It’s that reducing what adversaries can learn about your people shrinks the surface these attacks are built on.
See what an adversary would find on your team
The report describes the exposure. If you want the version specific to your organization, DeleteMe can show you what’s currently public on your executives and high-risk employees across data broker sites, people-search directories, and aggregators.
About the research
Trust at Scale: How AI Is Industrializing Deception is a Discovery report from 451 Research by S&P Global, authored by Senior Research Analyst Justin Lam. Findings draw on the AI-driven social engineering and impersonation risk survey 2026 (n=303), alongside 451 Research’s Voice of the Enterprise: Information Security, Organizational Behavior study and Voice of the Connected User Landscape research.
A Discovery report assesses market dynamics through the reported experience of practitioners — what they’re doing and why.
Commissioned by DeleteMe. © 2026 S&P Global. All rights reserved.
Trust at Scale — The 451 Research Report
