Social engineering is the practice of manipulating people rather than machines to break into an organization. Instead of hunting for a software flaw, an attacker studies how a specific employee thinks, what they are afraid of, and who they trust, then uses that insight to talk their way past controls a firewall was never built to stop.
The distinction matters because it changes where defense must live. A patched server closes a technical hole. A well-crafted phone call to a help desk does not need one; it needs a plausible story and an employee who wants to be helpful. Verizon’s 2026 DBIR found the human element present in 62% of breaches even as automated scanning and exploit tooling have accelerated. Once an attacker operates with a real employee’s credentials, security tools built to flag anomalies see something that looks exactly like normal business activity.
How Social Engineering Works
Every credible social engineering campaign runs through a lifecycle security researchers have documented for decades: reconnaissance, pretext, pressure, and payoff. Skilled attackers rarely skip a step.
It starts with homework. Attackers scrape LinkedIn profiles, press releases, conference bios, and out-of-office replies to build an org chart nobody intended to publish, mapping who reports to whom, which vendor handles payroll, and when executives travel. In the MGM Resorts breach of September 2023, Scattered Spider, also tracked as UNC3944, found an employee’s details on LinkedIn and used them to impersonate that person in a call to the IT service desk, a single conversation that led to a ransomware deployment costing MGM roughly $100 million.
With intelligence in hand, the attacker builds a pretext: a new hire needing a password reset, a vendor chasing an overdue invoice, or an executive stuck in a meeting needing a favor handled quietly. The story is built to survive a quick check rather than a thorough audit.
Then comes pressure. Urgency, authority, and likability are the three levers that show up constantly. Common tactics include claims like this needs to happen before the wire cutoff, I am calling on behalf of the CEO, or I really need your help with this. One 2025 analysis of phishing telemetry found the median time between an email landing in an inbox and a user clicking the link was under 60 seconds, measuring how little deliberation most people get before they act.
The final step is the payoff: a captured password, an approved MFA push, or a wire transfer routed to an attacker-controlled account. From there the adversary pivots by moving laterally, escalating privileges, or exfiltrating data. What follows is often the easy part; getting in the door is where the real manipulation lies.
What Attackers Try to Get From Their Victims
Credential theft is the primary headline, but it is rarely the finish line. A stolen password is a means to something more valuable, and experienced attackers usually have a specific target in mind before the first call is made.
Domain credentials and single sign-on tokens are the most sought-after prize because they open the most doors for the least effort. Right behind them sits multi-factor authentication itself, specifically the approval code or push notification that defeats primary passwords. That is why MFA fatigue attacks, where an adversary bombards a user with prompts until they approve one out of annoyance, have become a signature move for advanced groups.
Beyond account access, attackers target specific high-value assets across an organization:
- Login credentials including domain usernames, administrative passwords, and single sign-on tokens.
- Multi-factor authentication approvals to bypass secondary verification systems.
- Personally identifiable information used to orchestrate identity fraud operations.
- Banking and corporate credit card details to route unauthorized direct financial transfers.
- Intellectual property such as client lists, internal roadmaps, and unreleased financials that hold high value for competitors.
- Direct network footholds through VPN or RDP credentials that let attackers skip external reconnaissance entirely.
- Physical keycard access to enter restricted corporate buildings or server rooms.
The FBI IC3 logged $3.04 billion in business email compromise losses in 2025, with 86% of that money moving through wire transfer or ACH, serving as a direct reminder that moving funds rapidly before double-checks occur remains a primary goal.
Common Types of Social Engineering Attacks
Phishing
Phishing remains the workhorse of social engineering because it scales effortlessly. Attackers send mass emails engineered to look like legitimate communications from banks, SaaS vendors, or delivery services to route recipients to cloned login pages. Verizon’s 2025 DBIR found phishing present in 57% of social engineering incidents analyzed, with global daily volume estimated at 3.4 billion phishing emails. Generative AI has sharpened this threat; tools that once produced typo-riddled lures now generate polished messages. A 2025 analysis found AI-written phishing emails earned a 42% higher click-through rate than human-written counterparts.
Spear Phishing
Spear phishing trades volume for precision. Rather than blasting generic emails, the attacker researches one person, analyzing their job title, recent projects, and active vendor relationships to craft a tailored message referencing specific details. A finance manager might receive an email citing an actual invoice number tied to a real supplier, sent from a domain one character off from the legitimate web address. Because it is highly tailored, it clears basic filters and drives most high-value business email compromise cases.
Vishing
Voice phishing puts a live human voice behind the manipulation. Attackers spoof caller ID to display an internal extension or a trusted vendor’s phone number, then talk a target through a fabricated emergency, such as an IT issue requiring immediate remote access. Industry research recorded a 442% surge in vishing volume between the first and second halves of 2024, and major corporate breaches trace back to a single vishing call made to a service desk lacking strong identity verification.
Smishing
SMS-based phishing exploits the high trust and fast open rates associated with text messages, especially on small screens where suspicious web links are harder to inspect. Fake package-delivery alerts, toll-road payment notices, and bank fraud warnings are dominant lures. Smishing tied to fake toll-collection scams spiked an estimated 2,900% between 2023 and 2024 as criminal groups automated the technique. A text’s tight character limit leaves little room for inconsistencies that might tip off a careful reader.
Pretexting
Pretexting is the invented scenario that makes other techniques work, relying on a fabricated identity convincing enough that the target volunteers information rather than having it stolen. A caller posing as an internal auditor requesting account verification or an email claiming to be from HR asking an employee to confirm banking details before payroll cutover are core examples of pretexting. Verizon’s 2025 data shows pretexting appears in roughly half of all tracked social engineering incidents, driven largely by its role in financial fraud.
Baiting
Baiting appeals to curiosity or self-interest rather than fear. A physical USB drive labeled 2026 Executive Salary Review left in a parking lot or a torrent offering cracked software exploits a basic impulse: people want to see what is inside. Once the drive is plugged in or the file executed, malware runs with whatever privileges the host device holds. While lower-tech than voice cloning or AI phishing, it persists effectively against organizations that leave endpoint USB ports unblocked.
Quid Pro Quo
Quid pro quo attacks dangle a service in exchange for access. A classic version involves a caller working through an enterprise directory claiming to be IT support running a routine security check, offering to fix a non-existent technical problem if the employee provides a login credential. It plays directly on an employee’s natural instinct to cooperate with internal technical staff.
Tailgating
Tailgating, also known as piggybacking, is the physical form of social engineering. An attacker without a badge follows an authorized employee through a secured entrance, often holding bulky boxes or pretending to be on an urgent phone call so that holding the door feels like basic politeness rather than a security breach. Facilities with badge readers lacking physical mantraps stay exposed, making this tactic a reliable performer in physical penetration tests.
Social Engineering Examples
The Scattered Spider intrusion into MGM Resorts illustrates how a single vishing call can cascade into a full operational shutdown. In September 2023, an attacker who researched an employee on LinkedIn called the IT help desk, impersonated that employee to obtain a password reset, and used the resulting access to deploy ransomware. Slot machines, digital room keys, ATMs, and payment systems across Las Vegas properties went dark for days, culminating in a $100 million direct financial impact and a $40 million commitment to security remediation.
Business email compromise often plays out through quieter scripts. A finance employee receives an urgent message appearing to originate from the Chief Executive Officer requesting a rapid wire transfer to close a confidential acquisition. The email instructs the worker to bypass the two-person approval process due to time constraints, utilizing pure impersonation to short-circuit standard verification controls without relying on malware.
Deepfake technology has introduced synthetic visual and audio elements to these playbooks. In early 2024, an employee at the engineering firm Arup’s Hong Kong office joined a video call with what appeared to be the company CFO and several colleagues. All other participants were AI-generated recreations built from publicly available video and audio footage. Convinced the interaction was real, the employee authorized transfers totaling roughly $25 million before the fraud was discovered.
Physical social engineering relies on simple interpersonal dynamics. An individual in a delivery uniform with full arms approaches a badge-secured entrance as an employee walks through, politely asking them to hold the door open. Declining feels overly hostile, so the employee complies, defeating access control hardware costing tens of thousands of dollars through ordinary politeness.
Phishing vs. Social Engineering
Using these terms interchangeably is a fundamental error that misdirects how organizations allocate training and defensive resources.
Social engineering is the umbrella discipline encompassing the psychological manipulation of people to bypass security controls across any medium. Phishing is a specific execution channel within that broader category, defined as the delivery of deceptive digital messages, primarily email, to carry out the manipulation.
Every phishing attack relies on social engineering principles, but not every social engineering attack involves phishing. Physical tailgating involves no digital messages, and a vishing call exploiting caller ID spoofing never touches an inbox. Organizations that equate the two often build awareness programs focused almost entirely on email links while ignoring vishing scripts, tailgating, and in-person pretexting, leaving open gaps where attackers actively operate.
Why Social Engineering Is So Effective
Firewalls do not get manipulated into holding a door open; people do because specific cognitive shortcuts are hardwired into everyday workplace interactions. Attackers deliberately target these behavioral tendencies:
- Deference to authority makes employees reluctant to question requests that appear to come from senior executives or legal counsel.
- Manufactured urgency shrinks the window for critical thinking, driving sub-60-second click times on malicious links.
- The desire to be helpful causes workers to view refusing an unusual request as poor teamwork or bad customer service.
- Fear of negative consequences like job disruption or account suspension pressures victims into compliance.
The core vulnerability emerges after the manipulation succeeds. A stolen credential does not trigger an automated alarm like a malware payload does. To defensive systems, a compromised credential looks like a legitimate user logging in from an ordinary device. Tools built to detect external technical intrusions struggle to distinguish a legitimate user from an attacker holding valid credentials, explaining why the 2026 DBIR found credential-based access present in 39% of breaches.
What Happens After a Successful Social Engineering Attack
Initial manipulation represents the opening move rather than the final objective. Once an adversary gains an initial foothold, the attack sequence escalates rapidly through defined stages:
- Account Takeover: The attacker alters password settings, registers secondary devices for MFA push approvals, and creates hidden inbox redirection rules to conceal ongoing activity from the legitimate account owner.
- Lateral Movement: The adversary navigates internal networks toward domain controllers, financial systems, and cloud storage using built-in administrative utilities to blend in with routine IT operations.
- Data Exfiltration: Sensitive customer databases, personal files, and corporate intellectual property are staged and uploaded to external servers controlled by the attacker.
- Ransomware Deployment or Financial Fraud: Depending on motivation, the attacker either deploys network-wide encryption tools to halt business operations or monitors mailboxes for active invoices to modify banking payout details right as payments execute.
How to Prevent Social Engineering Attacks
Verify Unexpected Requests
Establish explicit out-of-band communication rules for non-routine actions involving money, credential changes, or system access. If an email claiming to be from an executive requests an urgent transfer, verify the request by calling that individual at a pre-established internal number rather than using contact information provided within the message.
Use Multi-Factor Authentication
Deploy robust multi-factor authentication, prioritizing authentication protocols that resist modern bypass techniques. Standard push approvals and SMS codes can be compromised via MFA fatigue or real-time phishing proxies. Enterprise adoption of FIDO2 and WebAuthn hardware passkeys, which bind authentication directly to specific domain addresses, provides structural protection against credential relay attacks.
Apply Least-Privilege Access
Implement strict role-based access control to restrict what a single compromised account can reach. Across a large enterprise, individual credential compromise is an operational reality; least-privilege architecture ensures that a breached user account cannot be leveraged to navigate laterally across the entire network.
Train Employees Around Real Attack Scenarios
Replace basic annual compliance reviews with frequent, realistic security simulations. Effective programs run vishing drills, test resistance to MFA fatigue bombing, and demonstrate synthetic deepfake scenarios. Practicing responses in low-stakes environments builds muscle memory for identifying live attacks.
Make Suspicious Activity Easy to Report
Establish clear, non-punitive reporting mechanisms so employees immediately flag suspicious calls, emails, or physical encounters. Early reporting allows security operations teams to isolate impacted accounts, revoke active session tokens, and contain lateral movement before major damage occurs.
Use Technical Controls Alongside Training
Combine human awareness with layered technical defenses. Enforcing strict DMARC, DKIM, and SPF email authentication protocols, using automated link sandboxing, deploying endpoint detection software, and monitoring identity logs for anomalous activity catches malicious traffic before it reaches end users.
How to Spot a Social Engineering Attack
Recognizing psychological manipulation requires identifying distinct operational red flags:
- Unusual urgency claiming an account faces immediate suspension or that a wire transfer must occur within minutes.
- Requests to bypass standard protocol asking you to ignore established financial, verification, or dual-approval controls just this once.
- Slightly altered domain names or phone numbers where an attacker registers web addresses or spoofs numbers that differ from legitimate sources by a single character.
- Unrequested MFA prompts arriving on your mobile device when you are not actively attempting to log into a service.
- Vague administrative claims from callers asserting internal authority who cannot provide verifiable callback credentials within the organization.
- Unsolicited file attachments containing macro-enabled documents, encrypted archives, or compressed executables paired with urgent text.
What to Do If You Have Already Responded
When a social engineering attempt succeeds, speed of containment is the primary factor limiting total damage. Fear of disciplinary action often delays reporting, allowing adversaries time to solidify access.
Report the incident to your internal security or IT team immediately upon realizing a mistake has occurred. Security operations teams rely on rapid notification to revoke active session tokens, reset compromised credentials, and inspect network logs for lateral movement.
Next, reset passwords for the affected account and any secondary accounts sharing similar credentials, then force a global logout of all active sessions through your account security settings. Disconnect affected workstations or mobile devices from Wi-Fi and Ethernet networks to stop local malware from spreading laterally across the network. If financial details or transfers were compromised, contact banking institutions instantly to attempt a wire recall or freeze active transactions.
Social Engineering in the Age of AI
Generative AI has not altered the underlying psychological drivers of social engineering, but it has removed scale and speed limitations. Large language models allow attackers to generate fluent, contextually accurate, and error-free messages across multiple languages in seconds. The FBI IC3 attributed more than $30 million in 2025 BEC losses directly to AI-enabled schemes, part of $900 million tied to broader AI-related cybercrime that year.
Voice cloning and synthetic media have altered the credibility of digital interactions. Using short samples of publicly available audio, such as conference recordings or earnings calls, attackers generate synthetic voices realistic enough to bypass basic phone verification. Video deepfakes have reached similar quality levels, enabling multi-party fake video calls to execute complex wire fraud.
Verizon’s 2026 DBIR observed the median attacker using AI across roughly 15 distinct stages of an attack chain, noted primarily as an accelerator for existing techniques rather than a tool creating entirely new attack types. Core defenses, including out-of-band verification, strict multi-person approval policies, and least-privilege access, remain effective against AI-driven threats when executed consistently.
Frequently Asked Questions
What is social engineering in information security?
It is the manipulation of human behavior to trick individuals into revealing confidential data, approving transfers, or granting system access by exploiting trust, urgency, or authority rather than exploiting software vulnerabilities.
What is an example of social engineering?
In the 2023 MGM Resorts breach, an attacker researched an employee on LinkedIn, called the corporate IT help desk pretending to be that employee, and convinced support staff to execute a password reset, granting access that led to a major ransomware deployment.
Is phishing a type of social engineering?
Yes. Phishing is a specific message-based vector within the broader domain of social engineering, which also includes phone-based vishing, text-based smishing, in-person pretexting, and physical tailgating.
What are the most common social engineering attacks?
Phishing represents the highest overall message volume, but spear phishing, vishing, pretexting, and business email compromise drive a disproportionate share of total financial losses.
Why is social engineering dangerous?
It captures legitimate user credentials, allowing an attacker to navigate internal network environments looking like a real employee, which circumvents automated intrusion detection tools.
How can organizations prevent social engineering?
Organizations build resistance by combining FIDO2 hardware authentication, out-of-band verification protocols, strict least-privilege permissions, and frequent training covering modern vishing and deepfake scenarios.