DefinitionSocial engineering is the psychological manipulation of people into handing over information, access or money, or into taking actions that compromise security. Instead of exploiting technical flaws, it exploits trust, fear, haste and respect for hierarchy.
How it works
The attacker builds a believable context and makes a request that, in that context, seems reasonable. The most common triggers are predictable:
- Authority: the request appears to come from an executive, IT support or a government agency.
- Urgency: short deadlines and threats of account lockout or loss.
- Willingness to help: a colleague or supplier "in trouble" who needs an exception.
- Curiosity and gain: prizes, supposedly confidential documents, special offers.
Common techniques
- Phishing, smishing and vishing: via email, text message or phone.
- Pretexting: a made-up story to justify the request, such as a fake audit.
- CEO fraud: an urgent and confidential transfer request, now also using voice deepfakes.
- Fake support scam: a call to obtain MFA codes or persuade the victim to install remote access software.
- Baiting and tailgating: a USB drive left as bait, or physical entry into a restricted area right behind an employee.
Social engineering vs phishing
Social engineering is the broad concept; phishing is the most common way to apply it. A call from "support" asking for a code involves no email or link, but it is social engineering all the same.
Defense combines prepared people with processes that do not depend on perception: confirmation through a second channel for payments and bank detail changes, identity verification before resetting passwords or MFA, and a simple channel to report attempts. These controls stop the scam even when the voice, email or video looks authentic.
Frequently asked questions
What is the difference between social engineering and phishing?
Social engineering is any manipulation of people to obtain access, data or money. Phishing is a social engineering technique carried out through messages, websites or calls that imitate a trusted source.
Does training solve social engineering?
It reduces the risk but does not eliminate it. Training must be recurring and backed by processes, such as second-channel confirmation, that stop the scam even when someone is fooled.