What Is Social Engineering? How These Attacks Work
Social engineering is the attack that never touches your software, because it does not have to. It asks a person, politely and plausibly, and the person says yes.

The IT help desk takes a call at 4:15 on a Thursday. The caller gives an employee name, the name of that employee's manager, and the office they work out of. All three are public if you know where to look. He is locked out before a customer call, he says, and could someone please reset it. Twelve minutes later a stranger is inside the company sign-in account with a new authentication app enrolled on a new phone. Nothing was hacked. Nobody typed a password into a fake page. A helpful person did their job slightly too well, and that is the whole attack.
What Is Social Engineering?
Social engineering is manipulation used to get information, access or money out of a person. NIST defines it as deceiving an individual into revealing sensitive information, obtaining unauthorized access, or committing fraud by associating with the individual to gain confidence and trust. CISA puts it more plainly: an attacker uses human interaction to obtain information about an organization or its systems, often by posing as somebody with a right to ask.
The definitions matter less than the target. Every other attack in the catalog of cyber security threats needs a flaw in something built: an unpatched server, a weak password, a misconfigured storage bucket. Social engineering needs a flaw in nothing. It needs a person doing what that person is paid to do, which is to answer the phone, open the attachment and process the invoice.
What the attacker wants is almost always one of five things:
- A password, or the one-time code that goes with it
- An approval, usually a multi-factor prompt tapped on a phone
- A file opened, so that something can run on the machine
- A payment sent, or a bank account changed on a real invoice
- Physical access, through a door somebody holds open
Notice that none of those require any technical skill from the attacker. They require a story, a phone number and patience. That is why social engineering survives every new defensive product, and why it will still be here when today's tools are obsolete.
How Social Engineering Attacks Work
A serious social engineering attack is not one message. It is a short project with stages, and the stages run in the same order whether the target is a retiree with a bank account or a payroll department at a hospital.
- ResearchNames, job titles, vendors, phone numbers and org charts, nearly all of it public
- Pretext builtA story that fits what the target already expects: an IT ticket, an invoice, a delivery, a security alert
- ContactEmail, text, a phone call or a person at the door, with a reason the request cannot wait
- The target actsA password typed, a prompt approved, a door held, a payment sent
- Access used and coveredA mailbox rule added, a device enrolled, the mail marked read again
- Verification breaks itOne callback on a number you already had ends the attack at stage three, every time
The research stage is why these attacks feel personal. A public LinkedIn page gives the reporting line, a press release gives the software the company just bought, an out-of-office reply gives the name of the person covering. None of that is stolen. It is assembled.
The scale is easier to see in complaint data than in vendor reports. The FBI's 2025 IC3 Annual Report recorded 1,008,597 complaints and $20.877 billion in losses for the year. Phishing and spoofing was the single most reported crime type at 191,561 complaints. Three of the other categories are social engineering wearing different clothes: tech and customer support fraud at 47,794 complaints and $2,134,675,818 lost, government impersonation at 32,424 complaints and $797,943,193, and business email compromise at 24,768 complaints and $3,046,598,558. Business email compromise is the expensive one because the request is a payment rather than a password, and there is no fake login page anywhere in it.
What Are the Four Types of Social Engineering?
The technique names multiply endlessly, but they fall into four families, and knowing which family you are looking at tells you what to check.
- Phishing, in every channel. A message impersonating a brand or a colleague, delivered by email, text, phone call, QR code or chat. It asks you to click, log in, call a number or reply.
- Pretexting. An invented identity and a reason to be in touch, usually sustained over more than one contact. The IT help desk call is pretexting. So is the vendor who needs to confirm bank details before the next payment run.
- Baiting and quid pro quo. An offer rather than a demand. A free download, a USB drive left in a lobby, a caller offering to fix a computer problem you did not know you had.
- Physical social engineering. Getting past a door or a desk in person: tailgating through a badge reader, arriving as a contractor, reading a screen over a shoulder.
Phishing is social engineering delivered by message, which is why phishing has its own vocabulary and its own defenses. The other three families are the ones people forget to plan for.
Types of Social Engineering Attacks
Here is the full set you will actually meet, with what each one asks for and the detail that gives it away.
| Technique | How it reaches you | What it asks for | The tell |
|---|---|---|---|
| Phishing | Email, in bulk | A password on a copied login page | A brand you may not use, a generic greeting |
| Spear phishing | Email, to one person | A password, a file opened, a payment | Your real name, role and current project |
| Whaling | Email, to executives | A wire transfer or a confidential file | Legal or board framing, marked private |
| Business email compromise | Email, sometimes voice | Money moved, or a bank account changed | A changed account on a genuine invoice |
| Vishing | Phone call | A one-time code read aloud, or a reset | The caller supplies urgency and takes the lead |
| Smishing | Text message | A tap on a short link | A package, a toll or a bank alert you did not expect |
| Quishing | QR code | A scan that opens a login page | A code added to a poster, meter or email |
| Pretexting | Any channel, over time | Access, information or a reset | A role that explains why they need it |
| Baiting | USB drive, download, ad | A file run on your machine | Something valuable for nothing |
| Quid pro quo | Phone call, chat | Remote access, in exchange for help | Unsolicited support for a problem you did not report |
| Scareware | Pop-up, ad, fake alert | A payment or a program installed | A countdown, a phone number, a virus warning |
| Watering hole | A site you already use | Nothing. You visit and it runs | No message at all, which is the point |
| Tailgating | In person, at a door | Access to the building | Full hands, a lost badge, a friendly nod |
| Deepfake impersonation | Video call, voice note | An urgent payment or approval | A voice or face you know making a request that breaks process |

Two entries on that list are newer than the rest. Quishing exists because a QR code hides its destination completely and most email filters cannot read one. Deepfake impersonation exists because voice cloning got cheap: IBM found that one in four malicious breaches were AI-enabled in its 2026 study, a 56 percent increase over the year before, and that those breaches cost $6 million on average against a global breach average of $4.99 million.
What Is an Example of Social Engineering?
The help desk call from the opening is the example worth studying, because it is the one that produced this year's largest breaches and because no email filter can see it.
CISA documented this pattern in detail in its advisory on Scattered Spider, which describes attackers posing as company IT and help desk staff over phone calls and SMS to obtain credentials and one-time passwords, sending repeated multi-factor prompts until an employee pressed accept, and convincing cellular carriers to move a target phone number to an attacker SIM card. The advisory's first mitigation is phishing-resistant multi-factor authentication, because a hardware key or a passkey cannot be read out over a phone.
The same technique shows up in the breach reports on this site. Voice phishing calls to employees preceded the intrusion described in the Exact Sciences report, which ended with 10.9 million verified records including health data.
Why Social Engineering Works
Not because the victims were careless. Because the request arrives through a channel that already carries real requests, at a moment when the target is busy, and it pulls one of six levers that work on everybody.
- Authority. The message is from the CEO, the bank, the IRS or IT. Questioning it feels like insubordination.
- Urgency. A deadline removes the pause in which you would have checked.
- Familiarity. The sender name, the logo, the signature block and the thread history are all real, because they were copied from a real message.
- Social proof. Everyone else has already completed the training, filed the form, approved the invoice.
- Fear of loss. The account will be closed, the package returned, the payment reversed.
- Helpfulness. The most underrated one. Most people who fall for social engineering were trying to help a colleague, a customer or a stranger with their hands full.
The channel matters more than it used to. The 2026 Verizon Data Breach Investigations Report found mobile social engineering success up 40 percent, and a phone hides both of the things a careful person checks: the full sender address and the real destination of a link. The same report found software flaws at 31 percent overtaking stolen credentials as the leading entry point for the first time, which is a useful corrective. Social engineering is not the only way in. It is the way in that no patch closes.
Social Engineering in Person and Over the Phone
Every security budget goes to the inbox, and two of the four families of attack never touch it.
Tailgating is the simplest: somebody walks in behind an employee holding a badge. It works because refusing feels rude, and because most offices have no plan for what a person is supposed to say. Baiting with hardware still works too, in the version where a USB drive appears in a lobby, a parking lot or a mailed envelope with a plausible label. Modern operating systems reduced the damage from a drive that runs on insertion, but a person who plugs it in and opens the document has done the attacker's work anyway.
The phone is the more serious problem, because it defeats the technical layer completely. There is no attachment to scan, no link to rewrite, no header to check. The caller controls the pace and hangs up before anybody compares notes, and a caller who already knows your manager and the software you use sounds internal. That is exactly what the research stage buys.
How to Prevent Social Engineering Attacks
CISA's own list of tells is worth keeping in mind for the message-based attacks: a sender address that resembles a real one with a character altered or missing, a generic greeting, a link whose real destination does not match the text when hovered, poor grammar or inconsistent formatting, and an unsolicited attachment. Those catch the bulk attacks. The verification rule catches the good ones.
If a social engineering attack succeeded against you, the response is the same as for any exposure of your data: change what was revealed, sign out of all sessions, check for mailbox rules and new devices, and work through what to do after a data breach for the account types involved.
Social Engineering Attacks on Businesses
For a company, social engineering is the reason "one employee was tricked" opens so many breach notices. It is also the hardest thing to buy a fix for, because the control that works is a process change rather than a product.
Key takeaways
- Social engineering attacks the person, not the software, so no patch and no filter fully stops it.
- Real attacks have stages: research, a pretext built from public information, contact with manufactured urgency, then the action.
- The four families are phishing in every channel, pretexting, baiting and quid pro quo, and physical access.
- Phishing and spoofing was the most reported crime type to the FBI in 2025 at 191,561 complaints, and business email compromise cost the most at over $3 billion.
- The help desk call that resets multi-factor authentication is the professional version, and identity proofing is the only thing that stops it.
- Verification out of band is the single rule that works against all of it, because it does not depend on spotting anything.
Common questions
What is a simple definition of social engineering?
Tricking a person into giving up information, access or money by pretending to be someone they have a reason to trust. It is a con, run with the tools of modern work: email, phone calls, text messages and video.
Which best defines social engineering?
The definition that puts the person at the center. Social engineering is not a software flaw, a virus or a hacking technique. It is manipulation of a human being to get something that the attacker could not take any other way, and the software involved is usually working exactly as designed.
Is phishing a type of social engineering?
Yes. Phishing is social engineering delivered as a message, and it is by far the most common form. Every phishing email, text and QR code is a social engineering attack, but plenty of social engineering happens by phone and in person, where no message exists to filter.
What is the difference between social engineering and hacking?
Hacking, in the technical sense, exploits a weakness in a system: an unpatched service, a weak password, a misconfiguration. Social engineering exploits a person, and it needs no weakness in any system at all. Most real intrusions combine the two, with the conversation opening the door and the technical work happening after.
What is pretexting?
An invented identity and a reason to be in touch, kept up across more than one contact. A caller claiming to be from IT, a vendor confirming bank details before a payment run, a recruiter asking about your systems for a job description. Pretexting is what makes a request feel routine.
Who is most at risk from social engineering?
Anyone who handles money, access or customer data as part of their job: finance, payroll, HR, IT support and executive assistants. For individuals, the FBI's 2025 complaint data shows people over 60 filed 201,266 complaints and lost $7.7 billion, more than any other age group.
Can technology stop social engineering?
Partly. Filters, secure email gateways and browser warnings remove most of the bulk attacks. Nothing filters a phone call, and nothing stops a person choosing to help. The technical controls that genuinely change outcomes work after the trick lands: phishing-resistant multi-factor authentication, and monitoring for the resets and new devices that follow.
Is social engineering illegal?
The deception itself is prosecuted through the crime it enables. In the United States that means wire fraud, identity theft and computer fraud statutes, plus state law. Authorized social engineering, meaning a penetration test with written permission from the organization, is legal and is how companies test these defenses.
What should I do if I fell for a social engineering attack?
Move fast, because the attacker window is usually minutes. Change any password you revealed, sign out of all sessions, check email for forwarding rules and your account for new devices or new MFA enrollments, and tell your IT or security team immediately. If money moved, call the bank now and file with the FBI at ic3.gov.
How do attackers research their targets?
Almost entirely from public sources: company websites, LinkedIn, press releases, job postings that name the software in use, out-of-office replies, and leaked address lists from old breaches. Nothing in the research stage requires breaking into anything, which is why it is invisible.
Does AI make social engineering worse?
It makes it cheaper and more fluent. Grammar mistakes were never a reliable tell and now they are gone entirely, voice cloning has made phone impersonation practical, and IBM's 2026 study found one in four malicious breaches were AI-enabled at a cost of $6 million each. The defenses do not change: a cloned voice still fails a callback to the number on file.
On this page
- What Is Social Engineering?
- How Social Engineering Attacks Work
- What Are the Four Types of Social Engineering?
- Types of Social Engineering Attacks
- What Is an Example of Social Engineering?
- Why Social Engineering Works
- Social Engineering in Person and Over the Phone
- How to Prevent Social Engineering Attacks
- Social Engineering Attacks on Businesses

Daniel Reyes
Daniel Reyes is a CISSP who spent twelve years in security operations, most recently leading a detection and response team for a mid-sized healthcare group in Texas. He reviews every resource and breach report on Cyber Security Firms for technical accuracy before it publishes.
Most of the people he has trained arrived having been told too much: a dozen acronyms, six vendors, and no clear idea which risk was theirs. His approach is to explain what an attack actually does before naming the tool that stops it, on the basis that most breaches start with something a reader could have recognised.