Overview

Social engineering uses manipulation and social norms to gain access to information, a location, or a system that would normally be off-limits.

Key concepts

  • Phishing family: phishing, spear phishing, whaling, smishing, vishing
  • Deception & physical: pretexting, baiting, tailgating, shoulder surfing, impersonation

How it works

Phishing family (message-based)

TypeHow it targets
PhishingBroad attack using fake emails, messages, or websites to trick many people at once.
Spear phishingTargeted at a specific person, group, or organization — often lower-level roles, to gain trust and basic credentials.
WhalingA spear-phishing attack aimed specifically at executives or other high-value individuals.
SmishingPhishing delivered through text messages/SMS.
VishingPhishing performed through phone calls, voicemail, or voice messages.

Deception & physical tactics

TypeHow it works
PretextingCreating a believable false story or identity to gain information or access.
BaitingOffering something desirable (free software, a reward) to trick someone into an unsafe action.
TailgatingAn unauthorized person physically follows an authorized person into a restricted area.
Shoulder surfingLooking at someone else's screen to gain confidential information.
ImpersonationPretending to be a trusted person, employee, organization, or IT support worker.

Protecting against social engineering

  • Verify unexpected requests using a trusted, separate contact method.
  • Check email addresses, links, attachments, and urgent language carefully.
  • Never share passwords, MFA codes, or confidential information through unexpected communications.
  • Report suspicious messages or calls, even if you're not sure.