Skip to main content

451 RESEARCH BY S&P GLOBAL DISCOVERY REPORT COMMISSIONED BY DELETEME

Your employees’ personal data is now attack infrastructure.

  • 300+ security leaders surveyed
  • AI impersonation attacks are getting personal
  • Existing controls weren’t built for these attacks
  • No link. No attachment. Attackers now weaponize trust.

Get the Report

Independent research · n=303 security practitioners and leaders · Fielded 2026 · Published by 451 Research by S&P Global

The attacks changed.
The assumption didn’t.

92%

say AI has increased the overall effectiveness of social engineering attacks.

91%

say personal data available online or through data brokers increases their exposure to it.

67%

still consider that exposure an individual privacy issue rather than a corporate security issue.

Those three numbers can’t all be comfortable at once. The report is about what happens in the space between them.

What the research covers

01

What AI actually changed about the economics of an attack.

Token costs, spam infrastructure at 100,000-device scale, and where the money is made downstream — including who buys access after the initial compromise.

02

Which personal details make an attack land.

Role and job function (77%), family, interests, or life history (72%), direct contact information (72%), org structure (65%) — ranked by how much easier they make AI-powered techniques.

03

Who gets targeted, and who costs the most when it works.

Helpdesk and IT staff are seen as the most commonly hit. Executives carry the most severe business impact. The two answers aren’t the same, and the gap matters for how you prioritize.

04

How prepared teams really are.

74% say they’re very or extremely prepared. 61% say their SecOps tooling struggles with exactly this attack class. Both are in the same dataset.

05

What’s actually working.

Identity verification (54%) and security awareness training (51%) top the list of most effective controls — with monitoring or removal of employee personal data close behind, and a note on why these rankings reflect security teams’ view rather than end users’ experience.

06

Why most teams are still investing reactively.

59% say a successful incident, a peer getting hit, or regulatory pressure is what would accelerate spend.

Figure 2 · From the report

Specific PII types make AI-driven attacks easier for adversaries

Role or job function
77%
Family, interests or history
72%
Direct contact information
72%
Organizational structure
65%

Base: All respondents (n=303). AI-driven social engineering & impersonation risk survey 2026. Source: 451 Research by S&P Global and DeleteMe.

”Attackers used to log in. Now they talk their way in — and the script is written from data your employees never knew was public.“

Rob Shavell, CEO, DeleteMe

Why “we’re prepared” and “our tools don’t catch it” are both true

A social engineering attempt that arrives with no malicious link, no attachment, and no brand impersonation doesn’t trip a detection rule. A user who approves an MFA prompt they didn’t initiate hasn’t done anything unauthorized. There’s nothing for SecOps to intervene on — the activity is valid, the identity is valid, the permissions are valid. Only the intent is wrong, and intent is the one thing your stack can’t see.

That’s why 82% of teams told 451 Research that traditional email tools and awareness training aren’t sufficient for the current threat, even as the same teams reported high confidence in detection and response. The controls are working on the attacks they were designed for.

74%

say they are “very” or “extremely” prepared

61%

say traditional SecOps tools struggle with these attacks

What the report says about the input side

42% of organizations have an active, org-wide initiative to remove employee PII or reduce digital footprints. 20% are evaluating or piloting. 18% cover high-risk and executive personnel only. Meanwhile 55% monitor online PII exposure continuously or automatically — leaving nearly half checking monthly, quarterly, or not at all.

The report’s conclusion is not “buy more detection.” It’s that reducing what adversaries can learn about your people shrinks the surface these attacks are built on.

See what an adversary would find on your team

The report describes the exposure. If you want the version specific to your organization, DeleteMe can show you what’s currently public on your executives and high-risk employees across data broker sites, people-search directories, and aggregators.

About the research

Trust at Scale: How AI Is Industrializing Deception is a Discovery report from 451 Research by S&P Global, authored by Senior Research Analyst Justin Lam. Findings draw on the AI-driven social engineering and impersonation risk survey 2026 (n=303), alongside 451 Research’s Voice of the Enterprise: Information Security, Organizational Behavior study and Voice of the Connected User Landscape research.

A Discovery report assesses market dynamics through the reported experience of practitioners — what they’re doing and why.


Commissioned by DeleteMe. © 2026 S&P Global. All rights reserved.

Trust at Scale — The 451 Research Report