> You should probably go re-examine the summary of findings chart.
Those are not the same figures on the PDF listed. The PDF presented seems to be from 2019, and I can't tell because your images are presented out of context, but it looks like hey might be from a newer report?
The PDF linked has a summary of findings that shows in figure 4 that 52% of breaches included hacking, and that 33% included social attacks.
Assuming I've found the document you're using as a source[1] (it's nice to have a newer version, but I hardly think it's fitting to ask me to reexamine a summary of findings chart that I was not originally presented with), it does go into more recent information.
That said, figures 20[2] and 21 in the new report do shed some more light on what we're actually talking about, and brings up the difference between "incidents" and "breaches" in this report, and what they mean. They define an incident as something that compromised the integrity, confidentiality or availability of an asset, while a breach is something that results in a confirmed disclosure of information. While phishing (social) is top in breaches as a bit less than 40% and pretexting (social) also makes a good showing in the breach chart (figure 20[2]), the much more expansive category of incidents (figure 21[3]) is overwhelmingly dominated by DoS (hacking) at almost 60%.
While that may seem like splitting hairs, especially since the original comment mentioned breaches, it was in response to and in the context of iPhone users, which is end user security. These reports are about businesses, and note they're following the NAICS standard to categorize victim organizations. They source their data from paid external forensic investigations, direct recording by partners using VERIS, and converting partners existing schema of data into VERIS (paraphrasing Appendix A). I think this discussion is about people and security in general, and I don't think this data is about that, I think it's about companies and organizations.
Now, to be clear, on thinking about this more closely I fully believe that social engineering attacks likely could be the majority of attacks when taking into account end users, and I imagine quite a lot of end user malware and ransomware that is likely installed from email, but I'm not sure, and I'm not sure how much browser exploits account for that, or how much phones change the picture. If we were just considering home systems, the majority I assume are firewalled at this point, I would definitely assume social engineering, but with phones out hopping public ranges through data plans and sharing wifi at many businesses, I'm not sure how that may be changed.
In any case, I think it's completely valid to call out someone that makes a general factual statement such as "Most security breaches these days are social-engineered." without providing that evidence. It's not self evident, and there's a lot of data to look at, as we've seen.
1: https://enterprise.verizon.com/resources/reports/2021-data-b...
2: https://www.verizon.com/business/dam/img/resources/reports/2...
3: https://www.verizon.com/business/dam/img/resources/reports/2...