Skip to main content
Book 07 · SecurityPage 39 of 50

Social Engineering

Pronunciation
SOH-shul en-juh-NEER-ing
Updated 2 min read

Share this page

Send the link, quote the definition with a link back, or show it as a card on your own site.

https://softwaredictionary.org/terms/social-engineering

In short

Social engineering is manipulating people, not breaking technology, to get information, access or money, often by posing as someone the victim trusts.

What is social engineering?

Attackers exploit trust, urgency, fear and helpfulness. A caller posing as IT support asks for a one-time code "to fix your account"; an email from the "CEO" asks for an urgent wire transfer; a message says a package is waiting and links to a fake site. Phishing is the most common form, but the same tricks work by phone (vishing), SMS (smishing) and in person.

Other techniques include pretexting, building a believable story to justify a request; baiting, leaving infected USB drives or offering free downloads; and tailgating, following an employee through a secure door. Increasingly, attackers use AI-generated voices and videos to impersonate real executives convincingly.

Many major breaches started this way. In 2020, attackers phoned Twitter employees, posed as internal IT and gained access to admin tools, then hijacked famous accounts to run a cryptocurrency scam. No amount of encryption helps if a person with access can be persuaded to use it for the attacker.

A common misconception is that only careless or untrained people fall for it. Good social engineering is well researched and arrives at a busy moment, so the best defenses are processes, not just awareness: verify requests through a separate known channel, require approval for payments and access changes, and use phishing-resistant authentication such as passkeys, which can't be read out over the phone.

Key takeaways

  • Social engineering manipulates people instead of hacking systems.
  • Phishing, vishing, smishing, pretexting, baiting and tailgating are common forms.
  • Attackers exploit urgency, authority, fear and helpfulness.
  • Many big breaches started with a convincing phone call or message.
  • Verification processes and phishing-resistant login beat awareness alone.

Readers ask

What is the difference between social engineering and phishing?

Social engineering is the general practice of manipulating people. Phishing is one form of it, using fraudulent messages, usually email, to trick people into clicking links, opening files or entering credentials.

What is pretexting?

Creating a believable scenario, such as posing as an auditor, a new colleague or a supplier, to persuade someone to share information or grant access they otherwise wouldn't.

How can companies defend against social engineering?

Train people with realistic examples, but also build processes: confirm unusual requests through a known contact, require two people for payments, never share one-time codes, and use passkeys or security keys that can't be phished.

See also

Spotted a mistake or something missing on this page?Suggest an edit

Read a random page
Open today's review
Switch to the dark theme
Read this page in Türkçe

More

Settings