{"id":15272,"date":"2026-09-08T17:29:43","date_gmt":"2026-09-08T11:59:43","guid":{"rendered":"https:\/\/threatcop.com\/blog\/?p=15272"},"modified":"2026-09-08T17:29:45","modified_gmt":"2026-09-08T11:59:45","slug":"ai-social-engineering-why-click-rate-no-longer-measures-the-risk","status":"publish","type":"post","link":"https:\/\/threatcop.com\/blog\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\/","title":{"rendered":"AI Social Engineering: Why Click Rate No Longer Measures the Risk"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">AI social engineering attacks the trust between an employee and the AI tools they work with, rather than the employee alone. The shift matters for measurement. Click rate scores whether a person clicked a link, and the leading attacks in this class need no link, no click, and sometimes no action from the employee at all.<\/p><div id=\"ez-toc-container\" class=\"ez-toc-v2_0_87 ez-toc-wrap-center counter-hierarchy ez-toc-counter ez-toc-light-blue ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #414141;color:#414141\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #414141;color:#414141\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/threatcop.com\/blog\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\/#What_Does_AI_Social_Engineering_Actually_Target\" >What Does AI Social Engineering Actually Target?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/threatcop.com\/blog\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\/#Why_Email_Susceptibility_Still_Needs_Measuring\" >Why Email Susceptibility Still Needs Measuring<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/threatcop.com\/blog\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\/#Why_Zero-Click_Attacks_Break_the_Click_Rate_Metric\" >Why Zero-Click Attacks Break the Click Rate Metric<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/threatcop.com\/blog\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\/#Book_a_Free_Demo_Call_with_Our_Expert\" >Book a Free Demo Call with Our Expert<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/threatcop.com\/blog\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\/#How_Do_Employees_Become_the_Delivery_Route\" >How Do Employees Become the Delivery Route?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/threatcop.com\/blog\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\/#Why_66_of_Employees_Do_Not_Check_What_AI_Tells_Them\" >Why 66% of Employees Do Not Check What AI Tells Them<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/threatcop.com\/blog\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\/#What_a_Culture_That_Questions_AI_Looks_Like_in_Practice\" >What a Culture That Questions AI Looks Like in Practice<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/threatcop.com\/blog\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\/#What_Should_You_Measure_Instead_of_Click_Rate\" >What Should You Measure Instead of Click Rate?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/threatcop.com\/blog\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\/#How_to_Run_a_Simulation_for_an_Attack_With_No_Link\" >How to Run a Simulation for an Attack With No Link<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/threatcop.com\/blog\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\/#Where_People_Security_Management_Fits_Against_AI_Attacks\" >Where People Security Management Fits Against AI Attacks<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/threatcop.com\/blog\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\/#What_to_Change_Before_Your_Next_Awareness_Report\" >What to Change Before Your Next Awareness Report<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"https:\/\/threatcop.com\/blog\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\/#Frequently_Asked_Questions\" >Frequently Asked Questions<\/a><\/li><\/ul><\/nav><\/div>\n\n\n\n\n<p class=\"wp-block-paragraph\">That leaves most awareness programs reporting a number that improves while the exposure it was built to track moves somewhere else.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_Does_AI_Social_Engineering_Actually_Target\"><\/span><strong>What Does AI Social Engineering Actually Target?<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">AI social engineering targets the trust relationship between a person and their tools rather than the person&#8217;s judgment about a message. Classic <a href=\"https:\/\/threatcop.com\/blog\/social-engineering-attack\/\"><strong><span style=\"text-decoration: underline;\">social engineering works by manipulating human psychology<\/span><\/strong><\/a> directly, and awareness programs were built to interrupt that moment of manipulation. An employee who has learned to distrust an unexpected email has not learned to distrust the assistant summarizing that email, and the assistant has no suspicion of its own.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Alongside the established <a href=\"https:\/\/threatcop.com\/blog\/types-of-social-engineering-attacks\/\"><strong><span style=\"text-decoration: underline;\">types of social engineering attacks<\/span><\/strong><\/a>, three AI-specific forms are in circulation, and they behave differently:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Instruction smuggling.<\/strong> Hidden text inside a document, web page, calendar invite, or email that the AI reads as a command rather than as content. The employee sees an ordinary file.<\/li>\n\n\n\n<li><strong>Poisoned input.<\/strong> An attacker gets a helpful employee to supply a tainted dataset, reference document, or knowledge base entry, which then shapes every output the tool produces from it.<\/li>\n\n\n\n<li><strong>Confidence exploitation.<\/strong> The attacker relies on the AI&#8217;s authoritative tone to move a person past a control they would otherwise question, because output arrives formatted, fluent, and without visible uncertainty.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">None of the three fit the shape awareness programs were built around. There is no sender to inspect, no domain to hover over, and often no moment where the employee is asked to decide anything. The decision was already made when the organization connected a tool to a mailbox.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The direction of travel is visible in breach data. Verizon&#8217;s <a href=\"https:\/\/www.verizon.com\/business\/resources\/Td15\/reports\/2026-dbir-data-breach-investigations-report.pdf\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong><span style=\"text-decoration: underline;\">2026 Data Breach Investigations Report<\/span><\/strong><\/a>, covering more than 22,000 confirmed breaches, puts the human element in 62% of them, and found that 41% of social engineering breaches now involve vectors other than email. The human layer is still where breaches run, and the channel it runs through keeps moving away from the inbox that awareness programs were designed to defend.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Why_Email_Susceptibility_Still_Needs_Measuring\"><\/span><strong>Why Email Susceptibility Still Needs Measuring<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Email susceptibility still needs measuring, because phishing remains the leading initial access vector in most breach datasets. A program that dropped click rate entirely would lose sight of a real and large exposure, and would deserve the criticism it got. The case for what <a href=\"https:\/\/threatcop.com\/blog\/how-do-phishing-simulations-contribute-to-enterprise-security\/\"><strong><span style=\"text-decoration: underline;\">phishing simulations contribute to enterprise security<\/span><\/strong><\/a> has not weakened.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The claim is narrower. Click rate should not stand alone as the number that represents human risk, because it covers one delivery mechanism and this attack class routinely uses others. Keep it, report it, and stop treating an improvement in it as evidence that the whole human layer got safer.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Why_Zero-Click_Attacks_Break_the_Click_Rate_Metric\"><\/span><strong>Why Zero-Click Attacks Break the Click Rate Metric<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Click rate stopped covering this class the moment a working attack needed no click. Conventional <a href=\"https:\/\/threatcop.com\/blog\/best-practices-for-email-security\/\"><strong><span style=\"text-decoration: underline;\">email security practices<\/span><\/strong><\/a> assume a user decision somewhere in the chain, whether that is opening, clicking, or replying. The clearest case where that assumption fails is EchoLeak, catalogued as CVE-2025-32711 with a CVSS score of 9.3 and <a href=\"https:\/\/arxiv.org\/pdf\/2509.10540\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong><span style=\"text-decoration: underline;\">documented in a 2025 research paper<\/span><\/strong><\/a> as the first real-world zero-click prompt injection exploit in a production LLM system. A single crafted email reached a Microsoft 365 Copilot user. The user never opened it. Copilot processed the mailbox during routine summarization and organizational data left the tenant.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The pattern repeated. Reprompt, tracked as CVE-2026-24307, achieved single-click exfiltration from Copilot Personal through a crafted URL parameter. GitHub Copilot carried a remote code execution flaw at CVSS 9.6 under CVE-2025-53773. Published analyses put prompt injection success rates between 50% and 84% depending on system configuration, and NIST has called indirect prompt injection the greatest security flaw in generative AI. OWASP has kept prompt injection at the top of its LLM risk list through the 2026 edition.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Set those against what click rate measures. A simulated phishing email lands, a person either clicks or does not, and the resulting percentage is reported as human risk. That metric was a reasonable proxy when the delivery mechanism was a link and the decision point was a human one. For an attack that runs inside a tool the business deployed and trusts, it is measuring an unrelated behavior and reporting the result as coverage.<\/p>\n\n\n\n<meta charset=\"UTF-8\">\n<meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n<title>Threatcop \u2013 Book a Free Demo<\/title>\n<link href=\"https:\/\/fonts.googleapis.com\/css2?family=Outfit:wght@300;400;500;600;700&#038;display=swap\" rel=\"stylesheet\">\n<style>\n  .tc-wrap , .tc-wrap ::before, .tc-wrap ::after { box-sizing: border-box; margin: 0; padding: 0; }\n  .tc-wrap { font-family: 'Outfit', sans-serif; width: 100%; display: flex; justify-content: center; padding: 20px 10px; }\n  .tc-card { width: 100%; max-width: 820px; background: #fff; border-radius: 20px; overflow: hidden; box-shadow: 0 20px 60px rgba(24,57,148,0.13), 0 4px 16px rgba(24,57,148,0.07); display: flex; flex-direction: row; }\n  .tc-left { background: linear-gradient(160deg, #1e44b0 0%, #183994 40%, #0e2570 100%); width: 320px; flex-shrink: 0; padding: 40px 32px; display: flex; flex-direction: column; justify-content: center; position: relative; overflow: hidden; }\n  .tc-left::before { content: ''; position: absolute; inset: 0; background-image: radial-gradient(rgba(255,255,255,0.08) 1.5px, transparent 1.5px); background-size: 22px 22px; }\n  .tc-left::after { content: ''; position: absolute; bottom: -60px; right: -60px; width: 220px; height: 220px; background: radial-gradient(circle, rgba(99,179,255,0.22) 0%, transparent 65%); border-radius: 50%; pointer-events: none; }\n  .tc-panel-inner { position: relative; z-index: 1; }\n  .tc-badge { display: inline-flex !important; align-items: center !important; gap: 6px; background: rgba(255,255,255,0.1) !important; border: 1px solid rgba(255,255,255,0.18) !important; border-radius: 20px !important; padding: 4px 14px 4px 10px !important; font-size: 12.5px !important; font-weight: 600 !important; letter-spacing: .09em !important; text-transform: uppercase !important; color: rgba(255,255,255,0.85) !important; margin-bottom: 18px !important; font-family: 'Outfit', sans-serif !important; line-height: 1.4 !important; }\n  .tc-badge-dot { width: 6px; height: 6px; background: #5cd9a0; border-radius: 50%; box-shadow: 0 0 6px #5cd9a0; flex-shrink: 0; display: inline-block; }\n  .tc-left h1, .tc-left h2, .tc-left h3, .tc-left h4, .tc-left h5, .tc-left h6 { color: #ffffff !important; font-family: 'Outfit', sans-serif !important; font-size: 28px !important; font-weight: 700 !important; line-height: 1.35 !important; letter-spacing: -0.3px !important; margin: 0 !important; padding: 0 !important; background: none !important; -webkit-text-fill-color: #ffffff !important; }\n  .tc-left h2 em { font-style: normal !important; color: #7ec8ff !important; -webkit-text-fill-color: #7ec8ff !important; }\n  .tc-left p, .tc-left .tc-sub { color: rgba(255,255,255,0.78) !important; -webkit-text-fill-color: rgba(255,255,255,0.78) !important; font-family: 'Outfit', sans-serif !important; font-size: 14px !important; font-weight: 300 !important; line-height: 1.65 !important; margin-top: 12px !important; background: none !important; }\n  .tc-right { flex: 1; padding: 32px 32px 28px; display: flex; flex-direction: column; justify-content: center; }\n  .tc-form-title { font-size: 13px !important; font-weight: 600 !important; letter-spacing: .12em; text-transform: uppercase; color: #8fa4cc !important; margin-bottom: 20px !important; display: flex !important; align-items: center !important; gap: 10px; font-family: 'Outfit', sans-serif !important; }\n  .tc-form-title::after { content: ''; flex: 1; height: 1px; background: #eef1fa; }\n  .tc-grid { display: grid; grid-template-columns: 1fr 1fr; gap: 14px; }\n  .tc-field { display: flex; flex-direction: column; gap: 5px; }\n  .tc-field.full { grid-column: 1 \/ -1; }\n  .tc-field label { font-size: 13px !important; font-weight: 600 !important; color: #3a4f7a !important; letter-spacing: .04em; text-transform: uppercase; font-family: 'Outfit', sans-serif !important; display: block !important; }\n  .tc-input-wrap { position: relative; display: flex; align-items: center; }\n  .tc-input-wrap .tc-fi { position: absolute; right: 12px; width: 15px; height: 15px; stroke: #c0ccdf; stroke-width: 1.8; pointer-events: none; fill: none; }\n  .tc-wrap input[type=\"text\"], .tc-wrap input[type=\"email\"], .tc-wrap input[type=\"number\"] { width: 100% !important; border: 1.5px solid #e2e9f7 !important; border-radius: 10px !important; padding: 9px 34px 9px 13px !important; font-family: 'Outfit', sans-serif !important; font-size: 15px !important; font-weight: 400 !important; color: #1e2d50 !important; background: #f8faff !important; outline: none !important; transition: border-color .2s, background .2s, box-shadow .2s; -moz-appearance: textfield; box-shadow: none !important; -webkit-text-fill-color: #1e2d50 !important; }\n  .tc-wrap input[type=\"number\"]::-webkit-inner-spin-button, .tc-wrap input[type=\"number\"]::-webkit-outer-spin-button { -webkit-appearance: none; }\n  .tc-wrap input::placeholder { color: #c0ccdf !important; -webkit-text-fill-color: #c0ccdf !important; opacity: 1; }\n  .tc-wrap input:focus { border-color: #183994 !important; background: #fff !important; box-shadow: 0 0 0 3.5px rgba(24,57,148,0.1) !important; }\n  .tc-phone-row { display: flex; gap: 8px; }\n  .tc-flag-select { position: relative; flex-shrink: 0; }\n  .tc-flag-select select { appearance: none !important; -webkit-appearance: none !important; border: 1.5px solid #e2e9f7 !important; border-radius: 10px !important; padding: 9px 26px 9px 12px !important; font-family: 'Outfit', sans-serif !important; font-size: 14px !important; font-weight: 500 !important; color: #1e2d50 !important; background: #f8faff !important; outline: none !important; cursor: pointer; width: 100px !important; transition: border-color .2s, box-shadow .2s; }\n  .tc-flag-select select:focus { border-color: #183994 !important; box-shadow: 0 0 0 3.5px rgba(24,57,148,0.1) !important; }\n  .tc-flag-select::after { content: ''; position: absolute; right: 10px; top: 50%; transform: translateY(-50%); width: 0; height: 0; border-left: 4px solid transparent; border-right: 4px solid transparent; border-top: 5px solid #a0b0cc; pointer-events: none; }\n  .tc-phone-row .tc-input-wrap { flex: 1; }\n  .tc-btn-submit { width: 100% !important; margin-top: 18px !important; padding: 11px !important; background: #183994 !important; border: none !important; border-radius: 10px !important; color: #fff !important; -webkit-text-fill-color: #fff !important; font-family: 'Outfit', sans-serif !important; font-size: 15px !important; font-weight: 600 !important; letter-spacing: .05em; cursor: pointer; display: flex !important; align-items: center !important; justify-content: center !important; gap: 9px; transition: background .2s, transform .15s, box-shadow .2s; box-shadow: 0 6px 24px rgba(24,57,148,0.28) !important; text-decoration: none !important; }\n  .tc-btn-submit:hover { background: #1d46b5 !important; transform: translateY(-1px); box-shadow: 0 10px 32px rgba(24,57,148,0.35) !important; color: #fff !important; }\n  .tc-btn-submit:active { transform: translateY(0); }\n  .tc-btn-submit svg { width: 16px; height: 16px; stroke: #fff; stroke-width: 2.2; fill: none; flex-shrink: 0; }\n  .tc-trust { margin-top: 10px !important; display: flex !important; align-items: center !important; justify-content: center !important; gap: 5px; font-size: 13px !important; color: #a0b0cc !important; font-family: 'Outfit', sans-serif !important; }\n  .tc-trust svg { width: 12px; height: 12px; stroke: #a0b0cc; stroke-width: 2; fill: none; flex-shrink: 0; }\n  @media (max-width: 680px) {\n    .tc-card { flex-direction: column !important; }\n    .tc-left { width: 100% !important; padding: 28px 24px 24px !important; }\n    .tc-right { padding: 24px 20px !important; }\n    .tc-grid { grid-template-columns: 1fr !important; }\n    .tc-field.full { grid-column: 1 !important; }\n  }\n<\/style>\n\n<div class=\"tc-wrap\">\n  <div class=\"tc-card\">\n    <div class=\"tc-left\">\n      <div class=\"tc-panel-inner\">\n        <div class=\"tc-badge\">\n          <span class=\"tc-badge-dot\"><\/span>\n          People Security Management\n        <\/div>\n        <h2><span class=\"ez-toc-section\" id=\"Book_a_Free_Demo_Call_with_Our_Expert\"><\/span>Book a Free<br><em>Demo Call<\/em><br>with Our Expert<span class=\"ez-toc-section-end\"><\/span><\/h2>\n        <p class=\"tc-sub\">Discover how Threatcop protects your workforce from modern cyber threats.<\/p>\n      <\/div>\n    <\/div>\n    <div class=\"tc-right\">\n      <div class=\"tc-form-title\">Your Details<\/div>\n      <form action=\"https:\/\/threatcop.com\/thankyou-blog\" method=\"get\" target=\"_blank\">\n        <input type=\"hidden\" name=\"BlogForm\" value=\"BlogForm\">\n        <input type=\"hidden\" name=\"PageSource\" id=\"tc-page-source\" value=\"\">\n        <div class=\"tc-grid\">\n          <div class=\"tc-field\">\n            <label>Full Name<\/label>\n            <div class=\"tc-input-wrap\">\n              <input type=\"text\" name=\"FullName\" placeholder=\"Jane Smith\" required=\"\">\n              <svg class=\"tc-fi\" viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><circle cx=\"12\" cy=\"8\" r=\"4\"><\/circle><path d=\"M4 20c0-4 3.58-7 8-7s8 3 8 7\"><\/path><\/svg>\n            <\/div>\n          <\/div>\n          <div class=\"tc-field\">\n            <label>Company Name<\/label>\n            <div class=\"tc-input-wrap\">\n              <input type=\"text\" name=\"CompanyName\" placeholder=\"Acme Corp\" required=\"\">\n              <svg class=\"tc-fi\" viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><rect x=\"3\" y=\"3\" width=\"18\" height=\"18\" rx=\"2\"><\/rect><path d=\"M9 3v18M3 9h6M3 15h6\"><\/path><\/svg>\n            <\/div>\n          <\/div>\n          <div class=\"tc-field full\">\n            <label>Corporate Email<\/label>\n            <div class=\"tc-input-wrap\">\n              <input type=\"email\" name=\"email\" placeholder=\"jane@yourcompany.com\" required=\"\">\n              <svg class=\"tc-fi\" viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><rect x=\"2\" y=\"4\" width=\"20\" height=\"16\" rx=\"2\"><\/rect><polyline points=\"2,4 12,13 22,4\"><\/polyline><\/svg>\n            <\/div>\n          <\/div>\n          <div class=\"tc-field full\">\n            <label>Phone Number<\/label>\n            <div class=\"tc-input-wrap\">\n              <input type=\"number\" name=\"Phone\" placeholder=\"98765 43210\" required=\"\">\n              <svg class=\"tc-fi\" viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><path d=\"M22 16.92v3a2 2 0 01-2.18 2A19.79 19.79 0 013.09 4.18 2 2 0 015.07 2h3a2 2 0 012 1.72c.13.96.36 1.9.71 2.81a2 2 0 01-.45 2.11L9.09 9.91a16 16 0 006 6l1.27-1.27a2 2 0 012.11-.45c.91.35 1.85.58 2.81.71A2 2 0 0122 16.92z\"><\/path><\/svg>\n            <\/div>\n          <\/div>\n        <\/div>\n        <button type=\"submit\" class=\"tc-btn-submit\">\n          <svg viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><path d=\"M22 2L11 13M22 2L15 22l-4-9-9-4 20-7z\"><\/path><\/svg>\n          Book My Free Demo\n        <\/button>\n        <div class=\"tc-trust\">\n          <svg viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><rect x=\"3\" y=\"11\" width=\"18\" height=\"11\" rx=\"2\"><\/rect><path d=\"M7 11V7a5 5 0 0110 0v4\"><\/path><\/svg>\n          Your data is safe &amp; never shared with third parties\n        <\/div>\n      <\/form>\n    <\/div>\n  <\/div>\n<\/div>\n<script>document.getElementById('tc-page-source').value = window.location.href;<\/script>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_Do_Employees_Become_the_Delivery_Route\"><\/span><strong>How Do Employees Become the Delivery Route?<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Employees become the delivery route by moving content, not by clicking anything. That breaks the assumption behind most <a href=\"https:\/\/threatcop.com\/blog\/best-countermeasures-against-social-engineering\/\"><strong><span style=\"text-decoration: underline;\">countermeasures against social engineering<\/span><\/strong><\/a>, which place the control at a decision point the employee is aware of. Microsoft&#8217;s security research on <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/03\/12\/detecting-analyzing-prompt-abuse-in-ai-tools\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong><span style=\"text-decoration: underline;\">prompt abuse in AI tools<\/span><\/strong><\/a>, published in March 2026, describes hidden instruction attacks as instructions buried inside documents, web pages, emails, or chats that an AI interprets as genuine input, producing information leaks or altered summaries without the user typing anything malicious.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The employee&#8217;s part in that chain is ordinary work:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Uploading a supplier PDF into an assistant to extract the payment terms<\/li>\n\n\n\n<li>Pasting a competitor&#8217;s web page into a tool for a summary<\/li>\n\n\n\n<li>Forwarding a thread to an agent that has access to the file store<\/li>\n\n\n\n<li>Connecting an assistant to a shared drive so it can answer questions faster<\/li>\n\n\n\n<li>Adding a document to a knowledge base that other people&#8217;s agents will retrieve<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Each action is reasonable in isolation and none of them looks like a security decision. What makes them consequential is the privilege on the other side. An agent that uses access it legitimately holds to serve an attacker is a confused deputy, which is behaviorally close to the profile security teams already study in <a href=\"https:\/\/threatcop.com\/blog\/insider-threat-detection\/\"><strong><span style=\"text-decoration: underline;\">insider threat detection<\/span><\/strong><\/a>, with the difference that this insider has API-speed access and no motive to investigate.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The training implication is narrow and teachable. Employees cannot patch prompt injection, since instructions and data share one channel inside a model&#8217;s context window. What they can learn is which content is untrusted, which tools hold enough access to make untrusted content dangerous, and that the combination of the two is the thing to avoid.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Why_66_of_Employees_Do_Not_Check_What_AI_Tells_Them\"><\/span><strong>Why 66% of Employees Do Not Check What AI Tells Them<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Employees do not check AI output because verification was never built into the workflow, and confidence exploitation depends on exactly that gap. A global study by KPMG and the University of Melbourne found that 66% of employees trust the output of large language models without checking it, and that more than half reported work-related mistakes caused by over-reliance. The EY AI Sentiment Index puts the share of users who verify AI-generated content at fewer than 1 in 3.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Workplace surveys through 2026 land in the same place from different angles. Resume Now&#8217;s December 2025 survey of 1,012 employed US adults found 35% rarely or only occasionally review AI output before using it, and 15% use AI tools for work without telling their manager. GoTo&#8217;s Pulse of Work 2026, covering 2,500 global employees and IT leaders, found 50% say they rely on AI too much and 28% say they have started trusting AI more than their own judgment.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An attacker does not need to defeat a verification step that most people are skipping. This is the same dynamic that makes <a href=\"https:\/\/threatcop.com\/blog\/how-does-human-error-relate-to-security-risks\/\"><strong><span style=\"text-decoration: underline;\">human error a leading driver of security risk<\/span><\/strong><\/a>, with one difference: the error is trusting a tool the organization chose and deployed. That is the whole mechanism of confidence exploitation, and it explains why an authoritative-sounding instruction inside an AI response can move someone past a control that a plainly worded email never would.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It also sets the ceiling on what training can achieve here. Telling people to verify everything produces verification of nothing, because the time cost is unbounded. Naming four or five decision types that require an independent check, and the source that check runs against, produces four or five checks.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_a_Culture_That_Questions_AI_Looks_Like_in_Practice\"><\/span><strong>What a Culture That Questions AI Looks Like in Practice<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A culture that questions AI is built on whether questioning is safe generally, not on whether the tool is AI. Organizations have spent years teaching people to comply with instructions that appear to carry authority. If challenging a director&#8217;s request is career-limiting, challenging an assistant that speaks with the same certainty will not happen either, whatever the policy says.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Four things make the difference, and none of them are a module:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>A named right to pause.<\/strong> A written rule that any employee may hold any request pending verification, with no requirement to justify the suspicion first.<\/li>\n\n\n\n<li><strong>Escalation that costs nothing.<\/strong> A reporting route where a false alarm produces a thank you rather than a follow-up conversation. People calibrate to the second occurrence, not the policy.<\/li>\n\n\n\n<li><strong>Leaders challenged in public.<\/strong> Someone senior visibly overriding or correcting an AI output in a meeting does more than a campaign, because it demonstrates the behavior is survivable.<\/li>\n\n\n\n<li><strong>Verification built into the workflow.<\/strong> A required second source on defined decisions, sitting inside the process rather than depending on individual conscientiousness.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">The underlying work is the same as any other <a href=\"https:\/\/threatcop.com\/blog\/how-to-build-a-strong-security-culture\/\"><strong><span style=\"text-decoration: underline;\">security culture program<\/span><\/strong><\/a>, with one addition. Employees need explicit permission to be wrong about an AI, because the social cost of doubting a machine in front of colleagues is higher than most security teams assume.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_Should_You_Measure_Instead_of_Click_Rate\"><\/span><strong>What Should You Measure Instead of Click Rate?<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Measure the behaviors this attack class actually requires, and demote click rate from headline number to one line among several. Click rate can stay as one line among several, but it should stop standing in for human risk on its own.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Behavior to measure<\/strong><\/td><td><strong>Metric<\/strong><\/td><td><strong>How to baseline it<\/strong><\/td><td><strong>Cadence<\/strong><\/td><\/tr><tr><td>Verification of AI output<\/td><td>Share of defined high-stakes outputs independently checked before action<\/td><td>Sample audit of decisions, not self-reporting<\/td><td>Monthly<\/td><\/tr><tr><td>Reporting anomalous AI behavior<\/td><td>Count of employee reports plus median time from observation to report<\/td><td>Reporting channel logs<\/td><td>Monthly<\/td><\/tr><tr><td>Untrusted content handling<\/td><td>Instances of external documents fed to tools holding sensitive access<\/td><td>Data loss prevention or platform logs<\/td><td>Monthly<\/td><\/tr><tr><td>Sanctioned tool usage<\/td><td>Share of AI work happening in approved tools, with voluntary disclosure of the rest<\/td><td>Anonymous survey plus discovery data<\/td><td>Quarterly<\/td><\/tr><tr><td>Challenge rate<\/td><td>Escalations raised that turn out to be benign<\/td><td>Same channel as incident reporting<\/td><td>Quarterly<\/td><\/tr><tr><td>Multi-vector susceptibility<\/td><td>Engagement rate across email, voice, SMS, and document-based scenarios<\/td><td>Simulation, scored per employee<\/td><td>Quarterly<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Two of these do the heavy lifting. Challenge rate is the only metric on the list that goes up when the program is working, which makes it uncomfortable to report and useful to track, because a workforce that never escalates anything is not a workforce with nothing to escalate. And reporting speed is the only one that changes an outcome mid-incident, which is why <a href=\"https:\/\/threatcop.com\/blog\/what-is-incident-reporting-culture\/\"><strong><span style=\"text-decoration: underline;\">incident reporting culture<\/span><\/strong><\/a> deserves separate measurement from susceptibility. The broader case for behavior-based rather than completion-based <a href=\"https:\/\/threatcop.com\/blog\/metrics-for-measuring-the-impact-of-security-training\/\"><strong><span style=\"text-decoration: underline;\">security training metrics<\/span><\/strong><\/a> applies without modification.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Introducing these without losing board continuity takes about two quarters. Run the new metrics alongside click rate rather than in place of it, so the committee that has watched one number fall for three years can see the new lines move before the old one is demoted. Baseline each behavior before any training lands against it, since a metric introduced after an intervention cannot attribute the change it reports.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Three of the six are cheap to start. Verification rate needs a sample audit of decisions already being made, not new tooling. Anomalous AI reports need a reporting channel that accepts something other than a forwarded email. Challenge rate is a count of escalations you are probably already receiving and not recording as a positive.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The other three depend on visibility you may not have yet. Untrusted content handling needs data loss prevention or platform logs. Sanctioned tool usage needs discovery data plus an amnesty for voluntary disclosure. Multi-vector susceptibility needs a simulation platform that can run scenarios outside email. Start with the cheap three, report them for a quarter, and use the gaps they expose to argue for the rest.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A board-ready view fits on one slide: susceptibility by vector, verification rate on the decisions that matter, median time from observation to report, and the direction each moved against last quarter. That is four numbers a non-technical director can interrogate, which is more than a single percentage has ever allowed.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_to_Run_a_Simulation_for_an_Attack_With_No_Link\"><\/span><strong>How to Run a Simulation for an Attack With No Link<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Build the simulation around the decision rather than the click, because an attack with no link gives the employee nothing to click on. The scoring question changes from whether someone clicked to whether someone verified, escalated, or proceeded.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Three scenario types cover most of the exposure:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>The seeded document.<\/strong> Circulate a file that carries a visible, benign-looking instruction addressed to an assistant, for example, a line asking the tool to forward a summary to an external address. Score whether the recipient notices it before feeding the file to a tool, and whether they report it.<\/li>\n\n\n\n<li><strong>The confident wrong answer.<\/strong> Present an AI-styled output containing an instruction that conflicts with policy, such as a vendor bank detail change presented as already validated. Score whether the person verifies against an independent source before acting.<\/li>\n\n\n\n<li><strong>The helpful data request.<\/strong> Ask a team to supply a reference dataset for an internal AI project, routed from a plausible but unverified internal-looking source. Score whether anyone confirms the requester and the classification of the data.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Run these with the same rules that govern any credible simulation program: baseline before training, score per employee rather than per organization, and keep results non-punitive so that reporting stays honest. The delivery mechanics are no different from the <a href=\"https:\/\/threatcop.com\/blog\/best-practices-for-employee-training\/\"><strong><span style=\"text-decoration: underline;\">best practices for employee training<\/span><\/strong><\/a> already in use for phishing, and multi-vector platforms such as <a href=\"https:\/\/threatcop.com\/threatcop-security-awareness-training\"><strong><span style=\"text-decoration: underline;\">Threatcop&#8217;s awareness training<\/span><\/strong><\/a> are built to run scenarios that do not depend on an inbox.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One caution. Do not score these on a pass rate and report the aggregate as an improvement. The value is in the distribution: which roles proceeded without verifying, and which teams escalated.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Where_People_Security_Management_Fits_Against_AI_Attacks\"><\/span><strong>Where People Security Management Fits Against AI Attacks<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/threatcop.com\/people-security-management\"><strong><span style=\"text-decoration: underline;\">People Security Management<\/span><\/strong><\/a> treats employee behavior as a security domain with baselines, owners, and metrics rather than as a training obligation, which is the frame this attack class requires. Threatcop built the approach with input from 33 security leaders across Indian industry and published it as a guide of CISO interviews, so it reads as a program structure rather than a feature list.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The cycle runs in three stages relevant here. Assess establishes a behavioral baseline through multi-vector simulation, which is where TSAT operates and where scenarios that never touch email get scored. Aware builds recognition of the specific behaviors the baseline exposed, delivered through TLMS with role-based and multi-language content. Empower turns the workforce into a detection layer through TPIR.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The reporting piece matters most against AI social engineering. An employee who notices an assistant behaving oddly has nothing to report under a phishing button, because there is no phishing email. TPIR&#8217;s WhatsApp and SMS reporting channels give people a route to raise something suspicious that never arrived in an inbox, which is increasingly how these attacks present. AI-driven simulation templates keep the scenarios aligned with lures currently in use, including synthetic voice and agent impersonation.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_to_Change_Before_Your_Next_Awareness_Report\"><\/span><strong>What to Change Before Your Next Awareness Report<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The awareness metric most organizations report improved every year while the attack surface it tracks became a smaller share of the problem. That is not a failure of the metric&#8217;s design. It is a failure to notice that the delivery mechanism moved from a link a person clicks to a document a tool reads.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Three changes fit inside a single quarter. Add verification rate and anomalous AI reports to the report alongside click rate. Run one seeded-document scenario against the roles that handle external files, and score it on escalation. Then check whether your reporting channel accepts a report that is not a phishing email, because if it does not, your workforce currently has no way to tell you what they saw. <a href=\"https:\/\/threatcop.com\/people-security-management\"><strong><span style=\"text-decoration: underline;\">Start with a multi-vector baseline<\/span><\/strong><\/a> and build the program from what it shows.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Frequently_Asked_Questions\"><\/span><strong>Frequently Asked Questions<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n<style>#sp-ea-15274 .spcollapsing { height: 0; overflow: hidden; transition-property: height;transition-duration: 300ms;}#sp-ea-15274.sp-easy-accordion>.sp-ea-single {margin-bottom: 10px; border: 1px solid #e2e2e2; }#sp-ea-15274.sp-easy-accordion>.sp-ea-single>.ea-header a {color: #444;}#sp-ea-15274.sp-easy-accordion>.sp-ea-single>.sp-collapse>.ea-body {background: #fff; color: #444;}#sp-ea-15274.sp-easy-accordion>.sp-ea-single {background: #eee;}#sp-ea-15274.sp-easy-accordion>.sp-ea-single>.ea-header a .ea-expand-icon { float: left; color: #444;font-size: 16px;}<\/style><div id=\"sp_easy_accordion-1788865008\"><div id=\"sp-ea-15274\" class=\"sp-ea-one sp-easy-accordion\" data-ea-active=\"ea-click\" data-ea-mode=\"vertical\" data-preloader=\"\" data-scroll-active-item=\"\" data-offset-to-scroll=\"0\"><div class=\"ea-card ea-expand sp-ea-single\"><h3 class=\"ea-header\"><a class=\"collapsed\" id=\"ea-header-152740\" role=\"button\" data-sptoggle=\"spcollapse\" data-sptarget=\"#collapse152740\" aria-controls=\"collapse152740\" href=\"#\" aria-expanded=\"true\" tabindex=\"0\"><i aria-hidden=\"true\" role=\"presentation\" class=\"ea-expand-icon eap-icon-ea-expand-minus\"><\/i> What is a zero-click prompt injection attack?<\/a><\/h3><div class=\"sp-collapse spcollapse collapsed show\" id=\"collapse152740\" data-parent=\"#sp-ea-15274\" role=\"region\" aria-labelledby=\"ea-header-152740\"> <div class=\"ea-body\"><p>It is an attack where hidden instructions reach an AI assistant through content it processes automatically, with no action from the user. EchoLeak, CVE-2025-32711 with a CVSS score of 9.3, exfiltrated Microsoft 365 data after a crafted email was processed during routine summarization. The recipient never opened the email.<\/p><p>It is an attack where hidden instructions reach an AI assistant through content it processes automatically, with no action from the user. EchoLeak, CVE-2025-32711 with a CVSS score of 9.3, exfiltrated Microsoft 365 data after a crafted email was processed during routine summarization. The recipient never opened the email.<\/p><\/div><\/div><\/div><div class=\"ea-card sp-ea-single\"><h3 class=\"ea-header\"><a class=\"collapsed\" id=\"ea-header-152741\" role=\"button\" data-sptoggle=\"spcollapse\" data-sptarget=\"#collapse152741\" aria-controls=\"collapse152741\" href=\"#\" aria-expanded=\"false\" tabindex=\"0\"><i aria-hidden=\"true\" role=\"presentation\" class=\"ea-expand-icon eap-icon-ea-expand-plus\"><\/i> Can employees prevent prompt injection?<\/a><\/h3><div class=\"sp-collapse spcollapse \" id=\"collapse152741\" data-parent=\"#sp-ea-15274\" role=\"region\" aria-labelledby=\"ea-header-152741\"> <div class=\"ea-body\"><p>Not directly. Instructions and data share one channel inside a model's context window, so no user behavior removes the risk. What employees can control is which untrusted content they feed to tools that hold sensitive access, and whether they report an assistant taking actions the task did not call for.<\/p><\/div><\/div><\/div><div class=\"ea-card sp-ea-single\"><h3 class=\"ea-header\"><a class=\"collapsed\" id=\"ea-header-152742\" role=\"button\" data-sptoggle=\"spcollapse\" data-sptarget=\"#collapse152742\" aria-controls=\"collapse152742\" href=\"#\" aria-expanded=\"false\" tabindex=\"0\"><i aria-hidden=\"true\" role=\"presentation\" class=\"ea-expand-icon eap-icon-ea-expand-plus\"><\/i> How many employees verify AI output before using it?<\/a><\/h3><div class=\"sp-collapse spcollapse \" id=\"collapse152742\" data-parent=\"#sp-ea-15274\" role=\"region\" aria-labelledby=\"ea-header-152742\"> <div class=\"ea-body\"><p>A global study by KPMG and the University of Melbourne found 66% of employees trust large language model output without checking it, with more than half reporting work mistakes caused by over-reliance. Resume Now's survey of employed US adults found 35% rarely or only occasionally review AI output before use.<\/p><\/div><\/div><\/div><div class=\"ea-card sp-ea-single\"><h3 class=\"ea-header\"><a class=\"collapsed\" id=\"ea-header-152743\" role=\"button\" data-sptoggle=\"spcollapse\" data-sptarget=\"#collapse152743\" aria-controls=\"collapse152743\" href=\"#\" aria-expanded=\"false\" tabindex=\"0\"><i aria-hidden=\"true\" role=\"presentation\" class=\"ea-expand-icon eap-icon-ea-expand-plus\"><\/i> What should replace click rate as the main awareness metric?<\/a><\/h3><div class=\"sp-collapse spcollapse \" id=\"collapse152743\" data-parent=\"#sp-ea-15274\" role=\"region\" aria-labelledby=\"ea-header-152743\"> <div class=\"ea-body\"><p>Use a small set of behaviors instead of a single number: verification rate on defined high-stakes decisions, reports of anomalous AI behavior with median time to report, challenge rate, and susceptibility across email, voice, SMS, and document-based scenarios. Click rate stays as one line rather than the headline.<\/p><\/div><\/div><\/div><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>AI social engineering attacks the trust between an employee and the AI tools they work with, rather than the employee alone. The shift matters for measurement. Click rate scores whether a person clicked a link, and the leading attacks in this class need no link, no click, and sometimes no action from the employee at [&hellip;]<\/p>\n","protected":false},"author":18,"featured_media":15277,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[424],"tags":[],"class_list":["post-15272","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>AI Social Engineering: Why Click Rate No Longer Measures the Risk<\/title>\n<meta name=\"description\" content=\"AI social engineering targets the trust between staff and AI tools. See why click rate misses these attacks and which behaviors to measure instead.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/threatcop.com\/blog\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"AI Social Engineering: Why Click Rate No Longer Measures the Risk\" \/>\n<meta property=\"og:description\" content=\"AI social engineering targets the trust between staff and AI tools. See why click rate misses these attacks and which behaviors to measure instead.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/threatcop.com\/blog\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\/\" \/>\n<meta property=\"og:site_name\" content=\"Threatcop\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/people\/Threatcop\/100083109892339\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-08T11:59:43+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-08T11:59:45+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Panel-Banner-3.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1920\" \/>\n\t<meta property=\"og:image:height\" content=\"1080\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"Pavan Kushwaha\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatcop\" \/>\n<meta name=\"twitter:site\" content=\"@threatcop\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Pavan Kushwaha\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"13 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\\\/\"},\"author\":{\"name\":\"Pavan Kushwaha\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/person\\\/c64cf2683a1d80076b8269165b41d53d\"},\"headline\":\"AI Social Engineering: Why Click Rate No Longer Measures the Risk\",\"datePublished\":\"2026-09-08T11:59:43+00:00\",\"dateModified\":\"2026-09-08T11:59:45+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\\\/\"},\"wordCount\":2689,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Panel-Banner-3.webp\",\"articleSection\":[\"AI &amp; Cybersecurity\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/threatcop.com\\\/blog\\\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\\\/\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\\\/\",\"name\":\"AI Social Engineering: Why Click Rate No Longer Measures the Risk\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Panel-Banner-3.webp\",\"datePublished\":\"2026-09-08T11:59:43+00:00\",\"dateModified\":\"2026-09-08T11:59:45+00:00\",\"description\":\"AI social engineering targets the trust between staff and AI tools. See why click rate misses these attacks and which behaviors to measure instead.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/threatcop.com\\\/blog\\\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\\\/#primaryimage\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Panel-Banner-3.webp\",\"contentUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Panel-Banner-3.webp\",\"width\":1920,\"height\":1080,\"caption\":\"AI social engineering\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"AI Social Engineering: Why Click Rate No Longer Measures the Risk\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/\",\"name\":\"Threatcop\",\"description\":\"Cybersecurity Blogs, News, Updates, and Articles\",\"publisher\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#organization\",\"name\":\"Threatcop\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/threatcop-logo-black-1.png\",\"contentUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/threatcop-logo-black-1.png\",\"width\":432,\"height\":102,\"caption\":\"Threatcop\"},\"image\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/people\\\/Threatcop\\\/100083109892339\\\/\",\"https:\\\/\\\/x.com\\\/threatcop\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/threatcop\\\/\",\"https:\\\/\\\/www.instagram.com\\\/threatcop_official\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/person\\\/c64cf2683a1d80076b8269165b41d53d\",\"name\":\"Pavan Kushwaha\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/08\\\/for-blog3.jpg\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/08\\\/for-blog3.jpg\",\"contentUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/08\\\/for-blog3.jpg\",\"caption\":\"Pavan Kushwaha\"},\"description\":\"Pavan Kushwaha is the Founder &amp; CEO of Kratikal and Threatcop and a Certified Information Systems Auditor (CISA). His cybersecurity journey began in 2013 after a firsthand encounter with a sophisticated phishing attack, inspiring him to build Kratikal with his NIT Allahabad peers. Today, he leads globally recognized solutions that reduce human risk using behavioral science, automated risk detection, and agentic AI security. He specializes in penetration testing and building secure security architectures for modern enterprises. An information security researcher and author of multiple cybersecurity books, he has trained 15,000+ professionals across 130+ countries. He has filed patents (pending) for innovations in real-time email trust and people security, turning security awareness into measurable, repeatable risk reduction.\",\"sameAs\":[\"https:\\\/\\\/threatcop.com\\\/\",\"https:\\\/\\\/www.linkedin.com\\\/in\\\/pavan-kushwaha\\\/\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"AI Social Engineering: Why Click Rate No Longer Measures the Risk","description":"AI social engineering targets the trust between staff and AI tools. See why click rate misses these attacks and which behaviors to measure instead.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/threatcop.com\/blog\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\/","og_locale":"en_US","og_type":"article","og_title":"AI Social Engineering: Why Click Rate No Longer Measures the Risk","og_description":"AI social engineering targets the trust between staff and AI tools. See why click rate misses these attacks and which behaviors to measure instead.","og_url":"https:\/\/threatcop.com\/blog\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\/","og_site_name":"Threatcop","article_publisher":"https:\/\/www.facebook.com\/people\/Threatcop\/100083109892339\/","article_published_time":"2026-09-08T11:59:43+00:00","article_modified_time":"2026-09-08T11:59:45+00:00","og_image":[{"width":1920,"height":1080,"url":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Panel-Banner-3.webp","type":"image\/webp"}],"author":"Pavan Kushwaha","twitter_card":"summary_large_image","twitter_creator":"@threatcop","twitter_site":"@threatcop","twitter_misc":{"Written by":"Pavan Kushwaha","Est. reading time":"13 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/threatcop.com\/blog\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\/#article","isPartOf":{"@id":"https:\/\/threatcop.com\/blog\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\/"},"author":{"name":"Pavan Kushwaha","@id":"https:\/\/threatcop.com\/blog\/#\/schema\/person\/c64cf2683a1d80076b8269165b41d53d"},"headline":"AI Social Engineering: Why Click Rate No Longer Measures the Risk","datePublished":"2026-09-08T11:59:43+00:00","dateModified":"2026-09-08T11:59:45+00:00","mainEntityOfPage":{"@id":"https:\/\/threatcop.com\/blog\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\/"},"wordCount":2689,"commentCount":0,"publisher":{"@id":"https:\/\/threatcop.com\/blog\/#organization"},"image":{"@id":"https:\/\/threatcop.com\/blog\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\/#primaryimage"},"thumbnailUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Panel-Banner-3.webp","articleSection":["AI &amp; Cybersecurity"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/threatcop.com\/blog\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/threatcop.com\/blog\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\/","url":"https:\/\/threatcop.com\/blog\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\/","name":"AI Social Engineering: Why Click Rate No Longer Measures the Risk","isPartOf":{"@id":"https:\/\/threatcop.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/threatcop.com\/blog\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\/#primaryimage"},"image":{"@id":"https:\/\/threatcop.com\/blog\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\/#primaryimage"},"thumbnailUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Panel-Banner-3.webp","datePublished":"2026-09-08T11:59:43+00:00","dateModified":"2026-09-08T11:59:45+00:00","description":"AI social engineering targets the trust between staff and AI tools. See why click rate misses these attacks and which behaviors to measure instead.","breadcrumb":{"@id":"https:\/\/threatcop.com\/blog\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/threatcop.com\/blog\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/threatcop.com\/blog\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\/#primaryimage","url":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Panel-Banner-3.webp","contentUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Panel-Banner-3.webp","width":1920,"height":1080,"caption":"AI social engineering"},{"@type":"BreadcrumbList","@id":"https:\/\/threatcop.com\/blog\/ai-social-engineering-why-click-rate-no-longer-measures-the-risk\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/threatcop.com\/blog\/"},{"@type":"ListItem","position":2,"name":"AI Social Engineering: Why Click Rate No Longer Measures the Risk"}]},{"@type":"WebSite","@id":"https:\/\/threatcop.com\/blog\/#website","url":"https:\/\/threatcop.com\/blog\/","name":"Threatcop","description":"Cybersecurity Blogs, News, Updates, and Articles","publisher":{"@id":"https:\/\/threatcop.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/threatcop.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/threatcop.com\/blog\/#organization","name":"Threatcop","url":"https:\/\/threatcop.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/threatcop.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/08\/threatcop-logo-black-1.png","contentUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/08\/threatcop-logo-black-1.png","width":432,"height":102,"caption":"Threatcop"},"image":{"@id":"https:\/\/threatcop.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/people\/Threatcop\/100083109892339\/","https:\/\/x.com\/threatcop","https:\/\/www.linkedin.com\/company\/threatcop\/","https:\/\/www.instagram.com\/threatcop_official\/"]},{"@type":"Person","@id":"https:\/\/threatcop.com\/blog\/#\/schema\/person\/c64cf2683a1d80076b8269165b41d53d","name":"Pavan Kushwaha","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2025\/08\/for-blog3.jpg","url":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2025\/08\/for-blog3.jpg","contentUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2025\/08\/for-blog3.jpg","caption":"Pavan Kushwaha"},"description":"Pavan Kushwaha is the Founder &amp; CEO of Kratikal and Threatcop and a Certified Information Systems Auditor (CISA). His cybersecurity journey began in 2013 after a firsthand encounter with a sophisticated phishing attack, inspiring him to build Kratikal with his NIT Allahabad peers. Today, he leads globally recognized solutions that reduce human risk using behavioral science, automated risk detection, and agentic AI security. He specializes in penetration testing and building secure security architectures for modern enterprises. An information security researcher and author of multiple cybersecurity books, he has trained 15,000+ professionals across 130+ countries. He has filed patents (pending) for innovations in real-time email trust and people security, turning security awareness into measurable, repeatable risk reduction.","sameAs":["https:\/\/threatcop.com\/","https:\/\/www.linkedin.com\/in\/pavan-kushwaha\/"]}]}},"_links":{"self":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts\/15272","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/comments?post=15272"}],"version-history":[{"count":3,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts\/15272\/revisions"}],"predecessor-version":[{"id":15279,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts\/15272\/revisions\/15279"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/media\/15277"}],"wp:attachment":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/media?parent=15272"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/categories?post=15272"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/tags?post=15272"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}