Social engineering is the practice of manipulating people into giving away information, access or money, instead of breaking into systems directly. The attacker plays a role, such as a bank officer, an IT help desk agent, a supplier or a senior executive, and uses urgency, authority or helpfulness to get the victim to act. Phishing is its most common form.
The US Cybersecurity and Infrastructure Security Agency (CISA) puts it simply in its joint phishing guidance with the NSA, FBI and MS-ISAC: social engineering is “the attempt to trick someone into revealing information (e.g., a password) or taking an action that can be used to compromise systems or networks.” The target is a person’s judgement, not a software bug, which is why firewalls and antivirus can’t stop it on their own.
The psychology social engineers use
Almost every social engineering attack pulls on one or more of these levers:
- Authority. The message or caller claims to be a boss, a bank, the police or a regulator, and people tend to comply with authority.
- Urgency. A deadline of minutes or hours leaves no time to check.
- Fear. A blocked account, a legal case or a hacked computer makes people act before they think.
- Helpfulness. A colleague who is locked out, a supplier with a late invoice, a new joiner who needs access. Most people want to help.
- Greed or curiosity. A refund, a prize, a job offer or a file named “salary revisions”.
- Familiarity. Using names, projects and details found online so the request feels routine.
The main types of social engineering attacks
Phishing
Fake emails, texts or websites that copy a trusted brand to steal logins, card details or money. The FBI’s Internet Crime Complaint Center received 191,561 phishing and spoofing complaints in 2025, more than for any other crime, according to its 2025 Internet Crime Report. We break phishing down further in 10 types of phishing attacks.
Spear phishing and whaling
Messages written for one person or a small team, using details from LinkedIn, company websites or earlier leaks. Whaling aims the same approach at senior executives, whose approval can move large sums.
Business email compromise
A spoofed or hijacked executive or supplier account asks finance to pay an invoice or change bank details. IC3 recorded about $3.05 billion in reported BEC losses in 2025. The Anti-Phishing Working Group’s Q2 2026 trends report describes one group, Scripted Sparrow, that uses fake executive coaching invoices and a forged reply chain between the “coaching firm” and a company executive to make the request look approved.
Vishing and smishing
The same tricks by phone call or text message. Calls are hard to verify in the moment, and a confident voice can carry a lot of authority. Read more in our guide to what vishing is and how voice phishing calls work.
Pretexting
The attacker builds a believable story, the pretext, before asking for anything. A well known recent example is the help desk call. CISA’s advisory on Scattered Spider describes how the group researches employees, then makes several calls to the IT help desk while posing as them, to learn the reset process and finally get passwords reset or MFA moved to a device the attackers control.
Baiting and quid pro quo
Baiting leaves something tempting, such as a USB drive labelled “payroll” or a free download, for the victim to pick up. Quid pro quo offers a service in exchange, such as “tech support” that fixes a problem you didn’t have in return for remote access. IC3 logged 47,794 tech support scam complaints in 2025, with about $2.13 billion in losses.
Tailgating and impersonation in person
Following an employee through a secure door, or turning up as a courier, contractor or auditor. Physical access often leads straight to network access.
The four stages of an attack
- Research. Collect names, roles, email formats, suppliers, phone numbers and recent events from public sources and leaks.
- The hook. Make first contact through the right channel with a story that fits the target.
- The play. Build trust, apply pressure and get the action: a password, an approval, a payment, a download.
- The exit. End the contact without raising suspicion, often leaving the victim unaware for days.
Real examples from India
“Digital arrest” scams are social engineering at its most extreme. Callers pose as police, CBI or customs officers, accuse the victim of a crime and keep them on a video call until they pay. The Ministry of Home Affairs said in a Lok Sabha reply published by PIB that I4C had blocked more than 1,700 Skype IDs and 59,000 WhatsApp accounts used for these scams.
Fake KYC messages and calls are another daily example. The Reserve Bank of India warned the public again in February 2024 about frauds in the name of KYC updates that use threats of account blocking.
How to recognise and stop social engineering
The common thread is a request that bypasses the normal process under pressure. Three habits stop most attacks:
- Pause. Urgency is a tactic. A real bank, boss or police officer can wait ten minutes.
- Verify on a channel you choose. Call back on a number you already have, or walk over to the person.
- Never hand over secrets. OTPs, passwords, PINs and remote access are never needed by the person asking.
For organisations, the controls that matter most are a strict callback rule for payments and resets, phishing-resistant MFA, regular simulations across email, SMS and phone, and an easy way for staff to report. We go through them in 5 ways to stop social engineering attacks.
In India, report suspected fraud calls and messages on Chakshu on Sanchar Saathi, and report money lost on 1930 or at cybercrime.gov.in.
FAQ
What is the difference between social engineering and phishing?
Social engineering is the wider idea: manipulating people into giving information, access or money. Phishing is one method of it, using fake emails, texts or websites that copy a trusted brand. Pretexting, help desk calls, baiting, tailgating and BEC are other social engineering methods. Every phishing attack is social engineering, but not every social engineering attack is phishing.
What are the warning signs of a social engineering attempt?
Watch for pressure to act immediately, requests for secrecy, a request that skips the usual approval process, and anyone asking for an OTP, password, PIN or remote access. Contact through an unexpected channel, such as a WhatsApp message from your CEO, is another sign. Any one of these is reason to stop and verify through a number or person you already know.
Why does social engineering work on smart, careful people?
Because it targets moments, not intelligence. Attackers choose times when people are busy, tired or worried, and build stories that match their real work: a supplier they really use, a project they really run. Under pressure, anyone can follow a routine request. That is why fixed rules, such as always calling back, work better than relying on judgement alone.
