Verder naar navigatie Doorgaan naar hoofdinhoud Ga naar de voettekst

Social engineering:
a growing risk for insurers

04 augustus 2026

 

What recent breaches teach the insurance industry

For years, organisations have invested heavily in protecting themselves against phishing emails. Advanced email filtering, secure email gateways and employee awareness training have all helped reduce the effectiveness of traditional phishing campaigns.

As a result, threat actors have evolved.

Across the Benelux, insurance companies I work with are increasingly reporting concerns around social engineering attacks that no longer rely solely on email. Instead, attackers are exploiting something far harder to secure: human trust.

Voice phishing, or vishing, has emerged as one of the most effective techniques available to modern threat actors. Combined with AI-generated content, deepfake technology and publicly available information, these attacks are becoming increasingly difficult to identify and stop. Our latest annual cyber threat intelligence report found 30% of corporate impersonation attacks now involve deepfakes, which highlights how AI is making social engineering attacks more convincing and scalable.

At the same time, the threat landscape is moving beyond digital-only tactics. We’re now seeing real time deepfakes, changing insider risk dynamics and advanced techniques involving remote workers, including individuals being paid to film specific actions that may not appear in digital logs, as well as laptop farms that use seemingly legitimate IP addresses to bypass detection.

For insurers, the implications are significant. Insurance forms part of the wider financial services sector, which was the second most targeted industry globally in 2025.

 

Why insurers represent a high-value target

Insurance organisations hold precisely the type of information cyber criminals want.

Customer records often contain names, addresses, dates of birth, contact information, medical records, life expectancy, financial details and claims-related data. The concentration of personal information within a single organisation creates substantial value for attackers. The Odido incident demonstrated how access to customer service environments can result in the exposure of large volumes of sensitive customer information. Approximately 6.39 million customer accounts were reportedly affected when attackers gained access to customer service systems and extracted personal data.

But the challenge for insurers extends beyond data itself.

Insurance operations depend on trust-based interactions between customers, brokers, claims handlers, contact centres, service providers and third parties. Many of these interactions occur under time pressure and often involve sensitive requests, making social engineering particularly effective.

Attackers understand this dynamic.

Rather than attempting to break through sophisticated security controls, they increasingly focus on manipulating employees into granting access or revealing information.

 

The attack may start with a phone call

One of the most effective elements of a vishing attack is its simplicity.

A threat actor gathers publicly available information through Open-Source Intelligence (OSINT), identifies suitable targets and then uses a trusted pretext to establish contact. Common impersonations include IT support teams, service desks, suppliers or internal colleagues. The following scenario illustrates a pattern commonly seen at the root of these attacks.

ICT Picture

We’re using a training scenario in our workshops where an employee receives what appears to be a legitimate internal communication before receiving a phone call from someone claiming to be IT support. The employee is then asked to approve a multi-factor authentication request. Once approved, the attacker gains access to the account and, within minutes, can begin viewing, copying and exporting data.

From the employee's perspective, the request appears routine.

From the attacker's perspective, the objective has already been achieved.

The more your employees share, the more can be abused by criminals.

 

Why traditional awareness training is no longer enough

Many organisations have spent years training employees to identify suspicious emails.

Far fewer have prepared their workforce for a convincing phone call from an attacker impersonating a trusted individual.

The challenge becomes even greater when AI enters the equation.

Modern attackers can spoof telephone numbers and increasingly leverage deepfake voice technology to imitate executives, colleagues or service providers. In some cases, relatively, short samples of publicly available audio may be sufficient to generate highly convincing synthetic voices capable of bypassing instinctive trust mechanisms.

This means employees can no longer rely solely on recognizing a familiar voice or phone number.

 

"Verification processes must become more important than trust. But balance is important as well. Employees should be able to perform their work in a relaxed and productive way while remaining alert when situations demand it. We train people to recognize warning signs, follow strict procedures, and respond appropriately when risks emerge.”

Alex Douven, Insurance Lead, Fox-IT (part of NCC Group)

 

Lessons insurers can take from social engineering attacks

When speaking with insurance clients across the Benelux region, a common theme emerges: organisations typically focus on preventing technical compromise while underestimating the role of customer service, support teams and operational staff play in enhancing overall cyber resilience.

Social engineering attacks exploit operational processes rather than technical vulnerabilities.

As a result, insurers should critically assess several areas:

1. Review identity verification procedures

Many organisations still rely on verification questions that can easily be answered through LinkedIn profiles, company websites or previously leaked data.

Information such as job titles, reporting lines and employment history should never form the basis of identity verification. Verification processes should assume that attackers can obtain publicly available information.

2. Reassess IT helpdesk and service desk privileges

Attackers frequently target service desks because they represent a gateway to password resets, account recovery, and Multi Factor Authentication (MFA) enrolment.

Access management processes should include independent validation, escalation controls and secondary approvals before sensitive actions are performed.

3. Reduce publicly available intelligence

Threat actors routinely conduct reconnaissance before making contact.

Organisations should evaluate how much information about employees, organisational structures and operational processes is publicly accessible and how it could be used by cyber criminals. The more information available, the easier it becomes for attackers to create believable scenarios.

4. Test people and processes, not just technology

One of the most effective ways to evaluate resilience is through controlled social engineering assessments and vishing simulations.

These exercises provide valuable insight into how employees respond under realistic conditions while helping build confidence in handling suspicious requests.

5. Strengthen identity and access controls

Technical controls should reinforce human verification with conditional access, device compliance and step up authentication for high risk actions such as password resets, MFA enrolment, privileged access requests and changes to customer records. CISOs should also ensure monitoring is tuned to signs of account misuse after social engineering, including irregular travel or expense requests, unusual sessions, new device registration, mailbox rule creation and changes to recovery settings. This reduces the risk that one successful phone call leads to unrestricted access or large scale data exposure.

Building resilience against the human attack surface

Cyber security discussions within insurance organisations often focus on technology, compliance and risk frameworks.

Those elements are essential, but today's attackers increasingly target the human layer of the organisation.

The reality is that a well-crafted phone call can sometimes achieve what malware and technical exploitation cannot.

The organisations best positioned to defend themselves are those that recognize social engineering as a business risk rather than simply a security issue. They combine robust verification procedures, continual awareness training, realistic testing exercises and technical controls that can detect, challenge and contain suspicious access attempts before they result in material harm.

Because in a world of AI-generated impersonation and increasingly sophisticated social engineering, the voice on the other end of the phone may not be who it claims to be.

 

Learn more 

Download Fox-IT’s quick reference card for all the do’s and don’ts for every stage of a cyber incident, including an offline contacts sheet.

Or visit our Social Engineering services website to explore our approach to strengthening human defences against social engineering threats.