What Is Social Engineering?

Social engineering is the use of deception, pressure, fear, curiosity, or trust to influence someone into revealing information or taking an unsafe action.

How Social Engineering Attacks Develop

Many attacks follow a predictable pattern designed to lower suspicion and encourage a quick emotional response.

01

Research

Public information may be collected from social media, company websites, data leaks, or online profiles.

02

Build Trust

The attacker creates a believable identity or story that appears familiar, official, or helpful.

03

Create Pressure

Fear, urgency, authority, excitement, or curiosity is used to reduce careful thinking.

04

Trigger an Action

The target is encouraged to click a link, open a file, send information, approve a login, or transfer money.

Types of Social Engineering Attacks

These attacks can arrive through email, text messages, phone calls, websites, social media, or face-to-face conversations.

EMAIL

Phishing

Fraudulent emails are designed to look like messages from trusted organizations or familiar people.

  • Unexpected password-reset notices
  • Fake account suspension warnings
  • Suspicious invoices or attachments
TARGETED

Spear Phishing

A personalized phishing attempt uses details about a specific person, organization, role, or project.

  • Uses the target's name or position
  • May reference coworkers or projects
  • Often appears highly believable
TEXT

Smishing

Smishing uses text messages to encourage a person to visit a dangerous website, call a fake number, or reveal information.

  • Fake delivery notifications
  • Unpaid toll or fee warnings
  • Fraudulent bank security alerts
VOICE

Vishing

Vishing occurs when attackers use phone calls or voice messages while impersonating trusted organizations.

  • Caller ID may be spoofed
  • Requests for verification codes
  • Threats involving accounts or taxes
IDENTITY

Pretexting

The attacker invents a believable situation or identity to convince someone that a request is legitimate.

  • Fake technical support requests
  • Impersonation of employees or vendors
  • False identity-verification stories
REWARD

Baiting

A tempting reward, download, prize, device, or offer is used to encourage unsafe behavior.

  • Free software or media downloads
  • Fake prizes and giveaways
  • Unknown removable storage devices
EXCHANGE

Quid Pro Quo

An attacker offers help, a service, or a benefit in exchange for information or access.

  • Fake technical assistance
  • Offers to fix nonexistent problems
  • Requests for login or device access
PHYSICAL

Tailgating

An unauthorized person follows an authorized individual into a restricted building or secure area.

  • Pretending to forget an access badge
  • Carrying boxes to appear harmless
  • Following employees through secure doors

Emotions Attackers Try to Exploit

Social engineering is effective because people naturally respond to authority, urgency, fear, helpfulness, curiosity, and the possibility of receiving a reward.

Urgency
Authority
Fear
Curiosity
Helpfulness
Reward

Social Engineering Warning Signs

One warning sign may not prove that a message is fraudulent, but several warning signs together should be treated seriously.

Message Inspection
Sender security-team@account-alert.example
Subject URGENT: Account Will Be Closed
Request Verify Password Immediately
Link Unknown External Website

Unusual Urgency

The sender insists that you act immediately or face a serious consequence.

Unexpected Language

The tone, wording, formatting, or greeting seems different from the supposed sender.

Sensitive Requests

The message asks for passwords, authentication codes, financial details, or remote access.

Suspicious Links

The visible link text does not match the destination or uses an unfamiliar domain.

Unexpected Attachments

The message includes a file you were not expecting or provides little explanation.

Payment Changes

A sender suddenly requests gift cards, wire transfers, cryptocurrency, or new payment instructions.

Build a Strong Human Firewall

Technology can block many threats, but careful verification and good judgment remain essential.

01

Pause Before Acting

Slow down when a message creates fear, excitement, or pressure. Urgency is commonly used to prevent careful thinking.

02

Verify Independently

Contact the person or organization using a known phone number, saved contact, official app, or manually entered website address.

03

Protect Authentication Codes

Never share passwords, one-time passcodes, recovery codes, or authentication approvals with an unexpected caller or message sender.

04

Use Multifactor Authentication

Enable multifactor authentication and carefully review every login approval notification before accepting it.

05

Inspect Links Carefully

Check the complete destination before opening links. Access important accounts through bookmarks or official applications.

06

Report Suspicious Activity

Report suspicious messages to the organization, email provider, school, employer, or security team responsible for the affected account.

What Should You Do After a Mistake?

Clicking a suspicious link or sharing information does not mean the situation is hopeless. Acting quickly can reduce the potential damage.

Use a trusted device when changing passwords or reviewing important accounts.

1

Disconnect When Necessary

If an unknown person has remote control of a device, disconnect the device from the network.

2

Change Compromised Passwords

Update affected passwords and any other accounts where the same password was reused.

3

Review Account Activity

Check recent logins, connected devices, security settings, financial transactions, and recovery details.

4

Notify the Proper Organization

Contact the affected service, financial institution, employer, school, or security team through official channels.

Trust, Then Verify

Legitimate organizations should not pressure you to reveal passwords, one-time verification codes, or sensitive financial information through an unexpected message.

HUMAN FIREWALL PROTECTED

Strengthen Your Cybersecurity Awareness

Explore additional cybersecurity topics and learn how technical protections work together with safe user behavior.