Two things at play - ClickFix (website asks user to press Windows key + R, run a command) is *incredibly successful*, and just phoning the helpdesk and asking for password reset. The GenAI research stuff being pushed out by security and AI vendors is completely absent in the real world trenches.
Cyber insurer (Chatham house forbids me from saying who) at BH CISO summit: “so far this year 0 payouts for claims even remotely connected to a AI-driven breach, 85% of payouts related to social engineering”. Sobering statistic.