Social Engineering
- In Turkish
- Sosyal Mühendislik
- Pronunciation
- SOH-shul en-juh-NEER-ing
In short
Social engineering is manipulating people, not breaking technology, to get information, access or money, often by posing as someone the victim trusts.
What is social engineering?
Attackers exploit trust, urgency, fear and helpfulness. A caller posing as IT support asks for a one-time code "to fix your account"; an email from the "CEO" asks for an urgent wire transfer; a message says a package is waiting and links to a fake site. Phishing is the most common form, but the same tricks work by phone (vishing), SMS (smishing) and in person.
Other techniques include pretexting, building a believable story to justify a request; baiting, leaving infected USB drives or offering free downloads; and tailgating, following an employee through a secure door. Increasingly, attackers use AI-generated voices and videos to impersonate real executives convincingly.
Many major breaches started this way. In 2020, attackers phoned Twitter employees, posed as internal IT and gained access to admin tools, then hijacked famous accounts to run a cryptocurrency scam. No amount of encryption helps if a person with access can be persuaded to use it for the attacker.
A common misconception is that only careless or untrained people fall for it. Good social engineering is well researched and arrives at a busy moment, so the best defenses are processes, not just awareness: verify requests through a separate known channel, require approval for payments and access changes, and use phishing-resistant authentication such as passkeys, which can't be read out over the phone.
Key takeaways
- Social engineering manipulates people instead of hacking systems.
- Phishing, vishing, smishing, pretexting, baiting and tailgating are common forms.
- Attackers exploit urgency, authority, fear and helpfulness.
- Many big breaches started with a convincing phone call or message.
- Verification processes and phishing-resistant login beat awareness alone.
Readers ask
What is the difference between social engineering and phishing?
Social engineering is the general practice of manipulating people. Phishing is one form of it, using fraudulent messages, usually email, to trick people into clicking links, opening files or entering credentials.
What is pretexting?
Creating a believable scenario, such as posing as an auditor, a new colleague or a supplier, to persuade someone to share information or grant access they otherwise wouldn't.
How can companies defend against social engineering?
Train people with realistic examples, but also build processes: confirm unusual requests through a known contact, require two people for payments, never share one-time codes, and use passkeys or security keys that can't be phished.
See also
- PhishingSecurity, p. 27Phishing is a social engineering attack in which criminals pose as a trusted company or person to trick people into revealing passwords, codes, or money.
- MalwareSecurity, p. 20Malware (malicious software) is any program designed to harm a computer or its user by stealing data, spying, damaging files or taking control of the system.
- PasskeySecurity, p. 25A passkey is a passwordless sign-in credential based on public-key cryptography, unlocked with a fingerprint, face scan, or device PIN, that resists phishing.
- Two-Factor AuthenticationSecurity, p. 46Two-factor authentication is a login method that requires two different kinds of proof, such as a password plus a code or security key, to confirm identity.
- Zero TrustSecurity, p. 49Zero trust is a security model that trusts no user, device, or network by default and verifies every request based on identity, device health, and context.
- RansomwareSecurity, p. 31Ransomware is malware that encrypts an organization's files or systems and demands a ransom for the key, often also threatening to leak stolen data.
Spotted a mistake or something missing on this page?Suggest an edit