Verder naar navigatie Doorgaan naar hoofdinhoud Ga naar de voettekst

Social engineering:
a growing risk for insurers

04 augustus 2026

 

What recent breaches teach the insurance industry

For years, organisations have invested heavily in protecting themselves against phishing emails. Advanced email filtering, secure email gateways and employee awareness training have all helped reduce the effectiveness of traditional phishing campaigns.

As a result, threat actors have evolved.

Across the Benelux, insurance companies I work with are increasingly reporting concerns around social engineering attacks that no longer rely solely on email. Instead, attackers are exploiting something far harder to secure: human trust. At the same time, we are seeing a significant increase in the volume of these attacks, driven in part by the use of AI agents to automate and scale social engineering campaigns.

Voice phishing, or vishing, has emerged as one of the most effective techniques available to modern threat actors. Combined with AI-generated content, deepfake technology and publicly available information, these attacks are becoming increasingly difficult to identify and stop. Our latest annual cyber threat intelligence report found 30% of corporate impersonation attacks now involve deepfakes, which highlights how AI is making social engineering attacks more convincing and scalable.

At the same time, the threat landscape is changing.

We’re increasingly seeing real-time deepfakes, evolving insider risk scenarios, and sophisticated tactics targeting remote workforces. These include individuals being compensated to perform specific actions that leave little or no trace in digital logs, as well as laptop farms operating through seemingly legitimate IP addresses to evade traditional detection mechanisms.

For insurers, the implications are significant. Insurance forms part of the wider financial services sector, which was the second most targeted industry globally in 2025.

 

Why insurers represent a high-value target

Insurers are particularly attractive targets because they hold far more than financial data. Claims information, medical records, income details, fraud investigations and other highly sensitive personal data provide criminals with a richer source of information than is typically available within other financial institutions. As a result, the consequences of a breach can be severe, both for affected customers and for the insurer’s reputation.

The Odido incident demonstrated how access to customer service environments can result in the exposure of large volumes of sensitive customer information. Approximately 6.39 million customer accounts were reportedly affected when attackers gained access to customer service systems and extracted personal data.

But the challenge for insurers extends beyond data itself.

Insurance operations depend on trust-based interactions between customers, brokers, claims handlers, contact centres, service providers and third parties. Many of these interactions occur under time pressure and often involve sensitive requests, making social engineering particularly effective.

Attackers understand this dynamic.

Rather than attempting to break through sophisticated security controls, they increasingly focus on manipulating employees into granting access or revealing information.

 

The attack may start with a phone call

One of the most effective elements of a vishing attack is its simplicity.

A threat actor gathers publicly available information through Open-Source Intelligence (OSINT), identifies suitable targets and then uses a trusted pretext to establish contact. Common impersonations include IT support teams, service desks, suppliers or internal colleagues. The following scenario illustrates a pattern commonly seen at the root of these attacks.

ICT Picture

We’re using a training scenario in our workshops where an employee receives what appears to be a legitimate internal communication before receiving a phone call from someone claiming to be IT support. The employee is then asked to approve a multi-factor authentication request. Once approved, the attacker gains access to the account and, within minutes, can begin viewing, copying and exporting data.

From the employee's perspective, the request appears routine.

From the attacker's perspective, the objective has already been achieved.

The more your employees share, the more can be abused by criminals.

What makes this scenario particularly concerning is that it reflects tactics already observed in real-world incidents, including the attack that impacted Odido.

Why traditional awareness training is no longer enough

Many organisations have spent years training employees to identify suspicious emails.

Far fewer have prepared their workforce for a convincing phone call from an attacker impersonating a trusted individual.

The challenge becomes even greater when AI enters the equation.

Modern attackers can spoof telephone numbers and increasingly leverage deepfake voice technology to imitate executives, colleagues or service providers. In some cases, relatively, short samples of publicly available audio may be sufficient to generate highly convincing synthetic voices capable of bypassing instinctive trust mechanisms.

This means employees can no longer rely solely on recognising a familiar voice or phone number.

 

“As threat actors increasingly exploit human trust, organisations should regularly review and strengthen their verification processes. However, effective security is not about creating a culture of suspicion. Employees should be able to perform their work in a relaxed and productive way while remaining alert when situations demand it. We therefore focus on helping people recognise warning signs, follow established procedures, and respond appropriately when risks emerge.”

Alex Douven, Insurance Lead, Fox-IT (part of NCC Group)

 

Lessons insurers can take from social engineering attacks

When speaking with insurance clients across the Benelux region, a common theme emerges: organisations typically focus on preventing technical compromise while underestimating the role of customer service, support teams and operational staff play in enhancing overall cyber resilience.

Social engineering attacks exploit operational processes rather than technical vulnerabilities.

This is one of the reasons why, in our insurance whitepaper, we advocate for greater collaboration across departments and with external partners. As attacks increasingly exploit people, processes and trust, reducing risk can no longer be achieved by technology teams alone. Read more in our whitepaper here.

As a result, insurers should critically assess several areas:

1. Review identity verification procedures

Many organisations still rely on verification questions that can easily be answered through LinkedIn profiles, company websites or previously leaked data.

Information such as job titles, reporting lines and employment history should never form the basis of identity verification. Verification processes should assume that attackers can obtain publicly available information.

2. Reassess IT helpdesk and service desk privileges

Attackers frequently target service desks because they represent a gateway to password resets, account recovery, and Multi Factor Authentication (MFA) enrolment.

Access management processes should include independent validation, escalation controls and secondary approvals before sensitive actions are performed.

3. Reduce publicly available intelligence

Threat actors routinely conduct reconnaissance before making contact.

Organisations should evaluate how much information about employees, organisational structures and operational processes is publicly accessible and how it could be used by cyber criminals. The more information available, the easier it becomes for attackers to create believable scenarios.

4. Test people and processes, not just technology

One of the most effective ways to evaluate resilience is through controlled social engineering assessments and vishing simulations.

These exercises provide valuable insight into how employees respond under realistic conditions while helping build confidence in handling suspicious requests. By experiencing realistic attack scenarios first-hand in a safe environment, employees gain a deeper understanding of the risks, creating a lasting impact and intrinsic motivation to adopt more secure behaviours.

5. Strengthen identity and access controls

Technical controls should reinforce human verification with conditional access, device compliance and step up authentication for high risk actions such as password resets, MFA enrolment, privileged access requests and changes to customer records. CISOs should also ensure monitoring is tuned to signs of account misuse after social engineering, including irregular travel or expense requests, unusual sessions, new device registration, mailbox rule creation and changes to recovery settings. This reduces the risk that one successful phone call leads to unrestricted access or large scale data exposure.

Building resilience against the human attack surface

Cyber security discussions within insurance organisations often focus on technology, compliance and risk frameworks.

Those elements are essential, but today's attackers increasingly target the human layer of the organisation.

The reality is that a well-crafted phone call can sometimes achieve what malware and technical exploitation cannot.

The organisations best positioned to defend themselves are those that recognize social engineering as a business risk rather than simply a security issue. They combine robust verification procedures, continual awareness training, realistic testing exercises and technical controls that can detect, challenge and contain suspicious access attempts before they result in material harm.

Because in a world of AI-generated impersonation and increasingly sophisticated social engineering, the voice on the other end of the phone may not be who it claims to be.

 

Learn more 

Download Fox-IT’s quick reference card for all the do’s and don’ts for every stage of a cyber incident, including an offline contacts sheet.

Or visit our Social Engineering services website to learn more about our approach to strengthening human defences against social engineering threats.