Skip to content
Cybersecurity

Social Engineering

Social engineering is a set of psychological manipulation techniques used by cybercriminals to persuade people to reveal confidential information or perform specific actions that compromise security.

What is Social Engineering?

Social Engineering Definition

Social engineering is a set of psychological manipulation techniques used to persuade people to perform specific actions or reveal confidential information. In the context of cybersecurity, social engineering is often used by attackers to gain unauthorized access to systems, data, or organizational resources by exploiting human psychology rather than technical security vulnerabilities.

How Does Social Engineering Work?

Social engineering works by exploiting human emotions, behaviors, and psychological tendencies such as:

  • Trust
  • Fear
  • Greed
  • Curiosity
  • Sense of duty
  • Desire to help others
  • Time pressure

Attackers manipulate these traits to persuade victims to take desired actions.

Types of Social Engineering Attacks

  • Phishing: Sending fraudulent emails to extract data.

  • Pretexting: Creating a false scenario to obtain information.

  • Baiting: Luring the victim with a false reward or benefit.

  • Quid pro quo: Offering something in exchange for information.

  • Tailgating: Unauthorized entry to a secured area behind someone else.

  • Vishing: Phone phishing.

  • Impersonation: Pretending to be another person or organization.

Goals of Social Engineering

  • Obtaining confidential information (e.g., passwords, personal data)
  • Access to secured systems or areas
  • Installing malware
  • Identity theft
  • Extorting money
  • Industrial espionage
  • Sabotage

Social Engineering Attack Examples

  • Email from “IT department” asking to change password by clicking a link
  • Phone call from “bank” asking to confirm account details
  • USB drive with malware left in a public place
  • Fake employee trying to gain physical access to the office

Social Engineering and Cybersecurity

Social engineering poses a serious threat to cybersecurity because:

  • It exploits the “weakest link” - humans
  • It can bypass advanced technical security measures
  • It is difficult to detect by traditional security systems
  • It constantly evolves, adapting to new technologies and trends

How to Recognize a Social Engineering Attack?

  • Unexpected requests for confidential information
  • Time pressure or threats
  • Offers too good to be true
  • Unusual or suspicious requests from “supervisors”
  • Requests to bypass standard security procedures
  • Inconsistencies in communication (e.g., language errors, strange email addresses)

Protection Methods Against Social Engineering

  • Employee education and training
  • Implementing strong security policies
  • Verifying caller identity
  • Caution when opening attachments and links
  • Regular security audits
  • Using multi-factor authentication
  • Cultivating a security culture in the organization

Consequences of Successful Social Engineering Attacks

  • Loss of confidential data
  • Financial losses
  • Privacy breaches
  • Organizational reputation damage
  • Business operation disruption
  • Costs related to incident response and damage repair
  • Potential legal consequences

AI-Powered Attacks

Artificial intelligence enhances social engineering:

  • Deepfake audio: Voice cloning for vishing attacks
  • Deepfake video: Fake video calls from “CEO”
  • AI-generated phishing: Highly personalized, grammatically perfect messages
  • Real-time translation: Attacks crossing language barriers

Business Email Compromise (BEC) 2.0

More sophisticated BEC attacks:

  • Compromised mailbox monitoring before attack
  • Perfect timing and context
  • Multi-channel coordination (email + phone)
  • Cryptocurrency and wire fraud

Explore Our Services

Want to protect your organization against social engineering? Check out:

Social engineering remains one of the most effective tools in cybercriminals’ arsenal. Effective defense against social engineering attacks requires a combination of education, awareness, and appropriate security procedures to protect both individuals and organizations from manipulation and fraud.

Frequently asked questions

+ What is social engineering in simple terms?

Social engineering is the psychological manipulation of people to make them reveal confidential information, transfer money, install malware, or take other actions that benefit the attacker. Where technical attacks exploit software vulnerabilities, social engineering exploits human psychology — trust, urgency, fear, helpfulness, authority. Verizon DBIR 2025 attributes ~36% of breaches to social engineering. Famous examples: Twitter Bitcoin scam (2020), Uber breach (2022), MGM Resorts ransomware (2023), Hong Kong deepfake CFO transfer ($25M, 2024). In 2024-2026, AI tools (voice cloning, deepfakes, AI-written phishing) have dramatically increased the scale and sophistication of social engineering.

+ What are the main types of social engineering?

Eight common techniques: (1) **Phishing** — malicious emails impersonating trusted senders, (2) **Spear phishing** — personalised phishing targeting specific individuals, (3) **Whaling** — phishing aimed at executives, (4) **BEC (Business Email Compromise)** — fraudulent wire transfer requests via spoofed or compromised executive emails ($2.9B+ losses 2024 per FBI), (5) **Vishing** — voice phishing over the phone, (6) **Smishing** — SMS phishing, (7) **Pretexting** — invented scenario to extract information (impersonating IT support, vendor, auditor), (8) **Baiting** — leaving malicious USB drives or downloads where targets find them. Other variants: tailgating (physical follow-in), quid pro quo (offering something for information), watering hole (compromising sites the target visits).

+ What psychology principles do social engineers exploit?

Robert Cialdini's six principles of influence underpin most social engineering: (1) **Authority** — claiming to be IT, police, executive, regulator, (2) **Urgency / scarcity** — 'your account will be closed in 24 hours', 'limited time offer', (3) **Reciprocity** — small favour creates psychological pressure to return, (4) **Social proof** — 'everyone is doing it', 'your colleagues already complied', (5) **Commitment / consistency** — small initial agreement leads to bigger asks, (6) **Liking** — personalised, friendly tone. Plus exploitation of emotions: **fear** (compliance violations, account compromise), **greed** (lottery, investment scams), **curiosity** (clickbait, leaked documents), **helpfulness** (fake support requests). Effective defences require both technical controls and ongoing user awareness.

+ How is AI changing social engineering in 2026?

AI has transformed social engineering at scale: (1) **AI-generated phishing** — ChatGPT, Claude, Gemini write grammatically perfect phishing in any language, eliminating language flaws that flagged many attacks, (2) **Voice cloning** (ElevenLabs, similar) — realistic vishing using 30 seconds of public audio of an executive, (3) **Deepfake video** — Hong Kong 2024 case: finance worker transferred $25M after deepfake video conference impersonating the CFO, (4) **Automated personalisation** — AI scrapes LinkedIn and corporate websites at scale, enabling spear phishing for the price of mass phishing, (5) **Conversational phishing** — AI-powered chatbots maintain consistent multi-turn deception. Defences: shift from 'spot the typo' awareness to behaviour-based controls (out-of-band confirmation for any wire transfer, voice/video verification protocols), executive-specific protection programmes.

+ What is BEC (Business Email Compromise)?

BEC is the most damaging form of social engineering, focused on tricking organisations into wire transfers or sensitive data disclosure. Two flavours: (1) **Email account compromise** — attacker actually controls a real executive's mailbox via phishing or password reuse, monitors email patterns, then sends fraudulent transfer requests at the right moment, (2) **CEO impersonation** — attacker spoofs or look-alikes the CEO's email (`ceo@compamy.com` instead of `company.com`) and pressures finance staff with urgency. Average BEC loss in 2025: $137,000 per incident. FBI IC3 reports $2.9B+ in BEC losses in 2024 alone. Defences: domain locking, DMARC enforcement, mandatory out-of-band verification for any wire transfer over a threshold, executive security training, AI-based email anomaly detection (Abnormal, Tessian, Proofpoint Email Fraud Defense).

+ How do you defend against social engineering?

Layered defence — no single control is sufficient: (1) **Phishing-resistant MFA** (FIDO2, passkeys) — eliminates the value of stolen credentials, (2) **Email security** with sandbox detonation and impersonation detection (Defender for O365, Proofpoint), (3) **DMARC at p=reject** — blocks domain spoofing of your own organisation, (4) **User awareness training** with monthly phishing simulations and click-rate metrics — top performers reduce click rates from 30% to under 5%, (5) **Out-of-band verification** for high-stakes actions (wire transfers, password resets, MFA changes), (6) **Reporting button** in email client — fast user reporting + SOC review, (7) **EDR/XDR** to catch malware that slips past email filters, (8) **Incident response plan** for BEC — fast bank and law enforcement contact can recover funds in the first 24-72 hours.

+ What is the role of security awareness training?

Security awareness training is the human-centred control complementing technical controls. Effective programmes include: (1) **Initial onboarding** — every new employee gets baseline training, (2) **Annual refreshers** — short, scenario-based modules, (3) **Monthly phishing simulations** — measured click rates, immediate education for clickers, (4) **Role-based training** — finance team gets BEC-specific training, executives get whaling awareness, IT gets vendor impersonation, (5) **Microlearning** — short videos, gamified modules, (6) **Simulated incidents** — tabletop exercises and red-team-style social engineering tests. Top platforms: KnowBe4, Proofpoint Security Awareness, Hoxhunt, Mimecast Awareness, Living Security. Effectiveness: well-run programmes reduce successful phishing by 50-90%; without consistent reinforcement, awareness decays in 3-6 months.

Tags:

social engineering manipulation phishing human factor security awareness

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist