What Is Social Engineering?

Also called: Social engineering attack

Related problems: Staff tricked into giving away passwords or approving payments; Callers impersonating IT or executives to get access; Help desk resetting accounts for people who aren't who they claim to be; Not sure how to train people against scams that keep changing

Social engineering is the use of deception to manipulate people into doing something that helps an attacker: revealing a password, approving a payment, installing software, sharing confidential data or letting someone into a building. Instead of breaking through technical defenses, the attacker exploits trust, urgency, helpfulness or fear, usually by pretending to be someone the target knows or expects, such as a colleague, an executive, a supplier or IT support. Many serious security incidents start this way.

At a glance

  • Social engineering targets people rather than systems, through email, text, phone, video, social media or in person.
  • Phishing is the best-known form; others include pretexting, impersonation calls, help desk scams and payment fraud.
  • Attacks often rely on urgency, authority or a believable story to cut normal checks short.
  • Defenses combine technical controls, verification procedures and ongoing staff training.
  • No single control prevents it; layered defenses reduce both how often it works and the damage when it does.

What problem it solves

Companies invest heavily in firewalls, endpoint protection and email filtering, and attackers respond by going around them. It is often easier to convince an accounts payable clerk to change a supplier’s bank details, or a help desk agent to reset a password, than to break into a well-protected system. A single successful request can hand over a working account, a large payment or sensitive data.

Understanding social engineering helps a company see that security is also a process and people question. It explains why awareness training, payment verification rules, help desk identity checks and phishing-resistant authentication matter as much as technical tools, and why incidents at peer companies so often begin with a convincing message or phone call rather than a sophisticated exploit.

How it works

Research. Attackers gather information from company websites, social media, job postings, past data breaches and earlier compromised accounts: who works where, who approves payments, which suppliers you use, how IT support communicates.

Pretext. They build a believable story, such as an urgent request from the CEO, a supplier changing bank details, IT support fixing a sign-in problem, or a delivery needing confirmation.

Contact. The approach arrives through the channel that suits the story. Phishing emails and text messages remain common; phone calls (vishing), messages on collaboration tools, fake login pages, and in-person visits are also used. Business email compromise (BEC) uses real or lookalike email accounts to request payments or data.

Exploitation. The target is pushed to act quickly: click, sign in, read out a code, approve a prompt, change details or wire money. The attacker then uses that access or information, often to go further into the company.

Defenses. Layers work together:

  • Email filtering and sender authentication catch many messages before they arrive.
  • Multi-factor authentication (MFA), especially phishing-resistant methods, limits what a stolen password is worth.
  • Verification procedures, such as calling back a known number before changing bank details or resetting an account, break the attacker’s story.
  • Security awareness training (SAT) and phishing simulation teach people to recognize and report attempts.
  • Limiting access, so one tricked person can’t reach everything, contains the damage.

Social engineering is distinct from an insider threat, where someone with legitimate access causes harm, though a manipulated employee can become an unwitting insider.

When it matters for buyers

  • After a peer company or supplier is hit. Payment fraud and account takeover incidents often prompt a review of procedures.
  • When cyber insurance renews. Insurers commonly ask about training, MFA and payment verification controls, and some policies treat social engineering fraud differently from other losses, so check your coverage.
  • When choosing a help desk or MSP. Ask how they verify callers before resetting passwords or MFA.
  • When finance processes change. New suppliers, new payment systems or staff turnover in accounts payable are common openings.
  • When rolling out new collaboration tools. Attackers follow users to chat and video platforms.

Our security awareness training overview covers programs that teach staff to spot and report these attempts.

Questions to ask vendors

  • Does your training cover phone, text, chat and in-person scenarios, not just email?
  • How are training and simulation content kept current with new attack styles?
  • How does your help desk verify a caller’s identity before resetting passwords or MFA?
  • What payment verification controls do you recommend or support for finance teams?
  • How do users report suspicious contact, and what happens after they do?
  • What metrics show whether staff behavior is improving?

How it differs from phishing

Phishing is one type of social engineering: deceptive messages, usually email or text, designed to get someone to click, sign in or share information. Social engineering is the wider category of manipulating people by any channel, including phone calls, impersonation in person, fake support requests and long-running pretexts that may involve no link or attachment at all. Defenses against phishing, such as email filtering, cover only part of the problem, which is why verification procedures and training aimed at every channel matter.

Frequently Asked Questions

Is phishing the same as social engineering?
Phishing is one type of social engineering, carried out through email, text messages or similar channels. Social engineering also includes phone calls, impersonation in person, fake help desk requests and other approaches that manipulate people rather than technology.
What are common types of social engineering?
Phishing emails, text message scams (smishing), phone scams (vishing), pretexting with an invented story, impersonating IT support or an executive, business email compromise aimed at payments, and physical tricks such as following staff through a secured door.
Can technology stop social engineering?
It can reduce it. Email filtering, sender authentication and phishing-resistant multi-factor authentication block or blunt many attempts. Attacks by phone or in person, or ones that use a real compromised account, often get past technical controls, so verification procedures and trained staff remain essential.
Why do attackers target the help desk?
Help desks exist to restore access quickly, which makes them a useful target. An attacker who convinces an agent to reset a password or enroll a new MFA device can take over an account. Strong caller identity checks reduce this risk.
Are AI-generated voices and videos a real concern?
Yes, increasingly. Cloned voices and convincing fake messages make impersonation easier. Procedures that require confirming sensitive requests through a separate, known channel help regardless of how convincing the request looks or sounds.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.