Social engineering is the use of deception to manipulate people into doing something that helps an attacker: revealing a password, approving a payment, installing software, sharing confidential data or letting someone into a building. Instead of breaking through technical defenses, the attacker exploits trust, urgency, helpfulness or fear, usually by pretending to be someone the target knows or expects, such as a colleague, an executive, a supplier or IT support. Many serious security incidents start this way.
At a glance
- Social engineering targets people rather than systems, through email, text, phone, video, social media or in person.
- Phishing is the best-known form; others include pretexting, impersonation calls, help desk scams and payment fraud.
- Attacks often rely on urgency, authority or a believable story to cut normal checks short.
- Defenses combine technical controls, verification procedures and ongoing staff training.
- No single control prevents it; layered defenses reduce both how often it works and the damage when it does.
What problem it solves
Companies invest heavily in firewalls, endpoint protection and email filtering, and attackers respond by going around them. It is often easier to convince an accounts payable clerk to change a supplier’s bank details, or a help desk agent to reset a password, than to break into a well-protected system. A single successful request can hand over a working account, a large payment or sensitive data.
Understanding social engineering helps a company see that security is also a process and people question. It explains why awareness training, payment verification rules, help desk identity checks and phishing-resistant authentication matter as much as technical tools, and why incidents at peer companies so often begin with a convincing message or phone call rather than a sophisticated exploit.
How it works
Research. Attackers gather information from company websites, social media, job postings, past data breaches and earlier compromised accounts: who works where, who approves payments, which suppliers you use, how IT support communicates.
Pretext. They build a believable story, such as an urgent request from the CEO, a supplier changing bank details, IT support fixing a sign-in problem, or a delivery needing confirmation.
Contact. The approach arrives through the channel that suits the story. Phishing emails and text messages remain common; phone calls (vishing), messages on collaboration tools, fake login pages, and in-person visits are also used. Business email compromise (BEC) uses real or lookalike email accounts to request payments or data.
Exploitation. The target is pushed to act quickly: click, sign in, read out a code, approve a prompt, change details or wire money. The attacker then uses that access or information, often to go further into the company.
Defenses. Layers work together:
- Email filtering and sender authentication catch many messages before they arrive.
- Multi-factor authentication (MFA), especially phishing-resistant methods, limits what a stolen password is worth.
- Verification procedures, such as calling back a known number before changing bank details or resetting an account, break the attacker’s story.
- Security awareness training (SAT) and phishing simulation teach people to recognize and report attempts.
- Limiting access, so one tricked person can’t reach everything, contains the damage.
Social engineering is distinct from an insider threat, where someone with legitimate access causes harm, though a manipulated employee can become an unwitting insider.
When it matters for buyers
- After a peer company or supplier is hit. Payment fraud and account takeover incidents often prompt a review of procedures.
- When cyber insurance renews. Insurers commonly ask about training, MFA and payment verification controls, and some policies treat social engineering fraud differently from other losses, so check your coverage.
- When choosing a help desk or MSP. Ask how they verify callers before resetting passwords or MFA.
- When finance processes change. New suppliers, new payment systems or staff turnover in accounts payable are common openings.
- When rolling out new collaboration tools. Attackers follow users to chat and video platforms.
Our security awareness training overview covers programs that teach staff to spot and report these attempts.
Questions to ask vendors
- Does your training cover phone, text, chat and in-person scenarios, not just email?
- How are training and simulation content kept current with new attack styles?
- How does your help desk verify a caller’s identity before resetting passwords or MFA?
- What payment verification controls do you recommend or support for finance teams?
- How do users report suspicious contact, and what happens after they do?
- What metrics show whether staff behavior is improving?
How it differs from phishing
Phishing is one type of social engineering: deceptive messages, usually email or text, designed to get someone to click, sign in or share information. Social engineering is the wider category of manipulating people by any channel, including phone calls, impersonation in person, fake support requests and long-running pretexts that may involve no link or attachment at all. Defenses against phishing, such as email filtering, cover only part of the problem, which is why verification procedures and training aimed at every channel matter.
