Shoulder Surfing and Human-Targeted Attacks Still Outpacing Technology-Based Threats in India, Warns Seqrite

Pune: Seqrite, the enterprise security arm of Quick Heal Technologies Limited, a global provider of cybersecurity solutions, today cautioned organisations and citizens that human-targeted attacks – including shoulder surfing, phishing, vishing, smishing, impersonation and digital honey traps – continue to outpace purely technology-led threats in India. While attacks are becoming more automated and AI-assisted, the most successful campaigns still begin by exploiting a person’s trust, attention, fear or routine behaviour.

Seqrite’s India Cyber Threat Report 2026 found that social engineering remains the top attack vector reported by organisations, ahead of malware and web-application attacks. The findings underline a persistent reality: sophisticated security technologies can be undermined when an attacker persuades an employee to disclose information, scan a malicious QR code, approve a login prompt, share an OTP, install a fake app or open a deceptive attachment.

“Shoulder surfing” is one of the most overlooked examples of this human-centric threat landscape. In offices, airports, co-working spaces, cafés, bank branches and public transport, attackers or opportunistic observers can watch users enter PINs, passwords, UPI credentials or confidential information on their devices. Even small fragments of information – an employee ID, a one-time password, a meeting subject line, a tax document or a visible screen notification – can be combined with public data and social engineering to build a convincing fraud or intrusion attempt.

Seqrite’s analysis also identified a rise in human-focused campaigns that operate without relying on traditional malware at the outset. Digital honey traps, for example, use AI-generated profiles, realistic photographs and crafted personal conversations on social media, dating platforms and messaging apps to establish trust before seeking workplace information, internal documents or private content. In observed cases, victims were later exposed to blackmail or coercion after sharing sensitive information.

Similarly, attackers are exploiting the familiarity of public services, brands and everyday transactions. The report documents fake government-service apps and websites that mimic trusted interfaces, including traffic-challan and High-Security Registration Plate services, to harvest OTPs, payment details, personal identifiers and device permissions. Fraudsters use urgency-driven language such as “final notice,” “fine imposed” or “account blocked” to override caution and force immediate action.

While technology remains essential, it must reinforce human judgement rather than assume it. Seqrite advises organisations to adopt layered security that integrates endpoint protection, identity monitoring, email and web controls, threat intelligence and behavioural analytics. The report found that behaviour-based security technologies, including next-generation antivirus and anti-ransomware engines, identified more than 34 million anomalous detections during the reporting period, highlighting the value of detecting suspicious activity that may evade traditional signatures.

Seqrite urges organisations to strengthen the human layer of cybersecurity through continuous awareness programmes, phishing and vishing simulations, role-based training, phishing-resistant multi-factor authentication and behaviour-driven access policies. Employees should be encouraged to challenge unexpected requests, independently verify the identity of callers and senders, and report suspicious activity without fear of blame. Clear-screen practices, privacy filters, device-locking discipline and caution while entering credentials in public spaces can also reduce exposure to shoulder-surfing risks. Advanced, AI-powered security solutions such as Quick Heal AntiFraud.AI add an additional shield of protection against growing scams.

Disclaimer: The above press release has been provided by value360india. CXO Digital Pulse holds no responsibility for its content in any manner. Reproduction or Copying in part or whole is not permitted unless approved by author.

- Advertisement -

Disclaimer: The views expressed in this feature article are of the author. This is not meant to be an advisory to purchase or invest in products, services or solutions of a particular type or, those promoted and sold by a particular company, their legal subsidiary in India or their channel partners. No warranty or any other liability is either expressed or implied.
Reproduction or Copying in part or whole is not permitted unless approved by author.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles

Share your details to download the Research Report 2026

Share your details to download the CISO Handbook 2026

Share your details to download the report 2026

Share your details to download the Cybersecurity Report 2025

Share your details to download the CISO Handbook 2025

Sign Up for CXO Digital Pulse Newsletters

Share your details to download the Research Report

Share your details to download the Coffee Table Book

Share your details to download the Vision 2023 Research Report

Download 8 Key Insights for Manufacturing for 2023 Report

Sign Up for CISO Handbook 2023

Download India’s Cybersecurity Outlook 2023 Report

Unlock Exclusive Insights: Access the article

Download CIO VISION 2024 Report

Share your details to download the report

Share your details to download the CISO Handbook 2024

Fill your details to Watch