Cybersecurity firm Seqrite has released its India Cyber Threat Report 2026, warning that human-targeted attacks continue to outpace purely technology-driven threats across the country. Despite growing investment in automated defences, the report finds that most successful cyberattacks still begin by exploiting people rather than systems.
Social engineering tops the list
According to the report, social engineering remains the most reported attack vector in India, ranking ahead of both malware and web application attacks. Techniques such as phishing, vishing, smishing, impersonation and “shoulder surfing” are proving more effective than purely technical exploits, since they target trust, routine and attention rather than software vulnerabilities.
Shoulder surfing hides in plain sight
One of the more overlooked risks flagged is shoulder surfing, where attackers or bystanders observe people entering PINs, passwords, or UPI credentials in public spaces such as offices, airports, cafés, and banks. Even small details, such as an employee ID or a visible OTP, can be combined with other publicly available information to enable fraud.
AI-driven honey traps and fake government apps
The report also highlights a rise in AI-assisted deception. Fraudsters are using AI-generated profiles and photographs to build fake relationships on dating and messaging platforms, later using the trust gained to extract sensitive workplace or personal information, sometimes leading to blackmail. Separately, fake apps and websites that mimic government services, such as traffic challan portals, are being used to harvest OTPs and payment details through urgency-driven messaging.
Technology still matters, but isn’t enough
Seqrite notes that behaviour-based detection tools, including next-generation antivirus and anti-ransomware engines, flagged over 34 million anomalous detections during the reporting period. However, the company argues that technology should support human judgement rather than replace it.
Building the human firewall
To counter these threats, Seqrite recommends continuous awareness training, phishing and vishing simulations, phishing-resistant multi-factor authentication and behaviour-driven access controls. It also urges simple, everyday habits, such as using privacy screen filters and locking devices, to reduce exposure.
