Cybersecurity Glossary

What is Social Engineering?

Social engineering manipulates people into acting for an attacker: disclosing information, transferring money, opening a file, granting access or bypassing a security rule. The attack does not target a supposed “human weakness,” but trust, workflows and decision-making situations. Technical and organizational gaps are what make the deception consequential.

How does social engineering work?

  1. Research: The attacker investigates people, responsibilities, suppliers, language and current events.
  2. Pretext: A plausible role and situation are constructed, such as support, management, a bank or a new colleague.
  3. Contact and trust: An email, message, call or in-person approach uses familiar details.
  4. Pressure and action: Urgency or authority is intended to shorten normal verification.
  5. Exploitation: Credentials, payment, remote access or an opened file enable the next attack step.
  6. Cleanup and reuse: The attacker deletes messages, maintains the story or uses the compromised account against more contacts.

Which forms exist?

FormApproach
PhishingMessages lead to fake logins, malicious attachments or fraudulent replies.
Spear phishingA targeted message incorporates a person's role, project or relationship.
Vishing and smishingDeception over a telephone call, text message or messenger.
PretextingAn invented identity and story justify an unusual request.
BaitingAn apparent prize, download or found storage device triggers curiosity.
TailgatingA person follows authorized staff into a protected area.
Support and MFA fraudThe attacker obtains an account reset or pressures someone to approve a login request.

Campaigns combine channels. An email may announce a call, while the caller already knows an invoice number and names. Deepfake audio or video can increase credibility, but it rarely replaces a careful pretext and an exploitable process.

Which psychological principles are exploited?

Authority (“management requires it”), urgency (“today”), scarcity, fear, helpfulness, curiosity and reciprocity shorten deliberate review. Social proof is created when other colleagues supposedly agreed already. Good processes anticipate these normal human responses and require independent confirmation for risky actions.

How can an attempt be recognized?

  • A request unexpectedly changes channel, bank details, telephone number or the usual process.
  • Verification or a callback using known contact details is refused or portrayed as too slow.
  • Someone asks for a password, MFA code, remote access or approval of a login you did not initiate.
  • Display name, actual domain, reply address and link destination do not fully match.
  • Unusual secrecy, an emotional threat or reward is used to justify an exception.

Perfect language does not prove authenticity, and spelling mistakes do not prove an attack. What matters is whether identity, context and requested action can be verified through an independent, previously known channel.

How can organizations protect themselves?

LayerControls
ProcessDual control and callbacks for payments, master-data changes, account recovery and sensitive disclosure.
IdentityPhishing-resistant MFA, separate administration accounts, least privilege and secure recovery.
Email and endpointsSPF/DKIM/DMARC, filtering, sandboxing, macro and execution controls, and timely updates.
PeopleRole-specific exercises, short current examples and a culture in which verification is encouraged.
ResponseA visible reporting route, rapid analysis and the ability to retract messages or tokens centrally.

Awareness matters, but it must not be the last and only control. One mistake should not immediately enable a large payment or complete account takeover.

What should happen after a successful attack?

  1. Report the contact immediately and preserve the message, headers, phone number and time.
  2. For exposed credentials, revoke sessions and tokens, reset the password, re-enroll MFA and review account activity.
  3. For payments, contact the bank, payment provider and responsible internal functions without delay.
  4. Investigate affected devices and accounts; check forwarding, mailbox rules and further recipients.
  5. Assess legal, privacy and notification obligations and warn other potential targets.

Rapid reporting matters more than blame. People who fear consequences wait longer, giving the attacker more time.

How are social-engineering tests conducted?

Authorized exercises define the objective, permitted channels, excluded groups, handling of credentials, stopping conditions and contacts. Useful metrics cover reporting, response time, process bypass and technical controls, not clicks alone. Results should improve processes and enable focused learning rather than shame individual employees. Physical deception, call recording and processing of personal data require particularly careful legal and organizational coordination.

Penetration Tests

Uncover Security Vulnerabilities

Professional penetration testing for your business

Web Apps
Networks
Mobile Apps
10% New Customer Discount
Plan Now

Thank you for your feedback! We will review it and optimize this content.

Do you have feedback on Social Engineering? Tell us!