Mastodon Mastodon Mastodon Mastodon

Social Engineering

Updated: · CyberSecureFox Editorial Team

Social engineering is the manipulation of people into revealing confidential information, granting access or performing actions that help an attacker, instead of hacking systems directly.

How social engineering works

Attackers exploit trust, fear, urgency, curiosity and the wish to help. Common techniques:

  • phishing – fake emails, messages and websites; by SMS (smishing) and by phone (vishing);
  • pretexting – a made-up story, for example a caller posing as IT support, a bank or the police;
  • baiting – infected USB sticks or “free” downloads;
  • tailgating – following an employee through a secured door;
  • impersonation of executives in business email compromise, now also with voice and video deepfakes.

Why social engineering matters for security

The human factor is involved in most breaches: it is often easier to talk someone into sharing a password than to find a technical flaw. In 2020 attackers phoned Twitter employees, obtained internal tool access and hijacked high-profile accounts. In 2023 the Scattered Spider group called MGM Resorts’ help desk, pretended to be an employee and got an account reset, which led to a ransomware attack that disrupted hotels and casinos for days.

How to defend

  • Verify unusual requests through a second, known channel – call back on an official number.
  • Establish strict identity checks for help desk password and MFA resets.
  • Use phishing-resistant two-factor authentication so a stolen password alone is not enough.
  • Train staff with realistic examples and make reporting suspicious contacts easy and blame-free.
Synonyms:
social engineering attack