Skip to content
Home

Social engineering (security)

Social engineering is the practice of manipulating people to disclose information or perform actions that compromise security; it complements technical attacks and exploits human trust.

Overview

Social engineering in security refers to techniques that exploit human behavior to gain unauthorized access to information, systems, or physical locations. Rather than attacking hardware or software directly, attackers manipulate trust, authority, curiosity, fear, or helpfulness to persuade targets to reveal credentials, transfer funds, or grant access.

Image gallery

1 Image

Common techniques

Practitioners use a range of approaches, often combined to increase effectiveness. Typical methods include:

  • Phishing: deceptive emails or messages that mimic legitimate sources to obtain credentials or deliver malware.
  • Pretexting: creating a fabricated scenario (a false identity or role) to solicit information or actions.
  • Baiting and quid pro quo: offering something desirable or pretending to provide help in exchange for information.
  • Tailgating and physical intrusion: following authorized personnel into restricted areas or exploiting lax physical controls.
  • Vishing and SMiShing: voice calls or text messages designed to trick targets into revealing secrets or performing transactions.

Why it works

Social engineering succeeds because it leverages predictable human responses. Attackers exploit cognitive biases such as deference to authority, the pressure of urgency, the desire to be helpful, and curiosity. Even well-equipped organizations remain vulnerable when individuals bypass procedures under stress or confusion.

History and context

Rooted in long-standing confidence tricks and scams, social engineering became a focus of information-security practice as networks and digital services spread. In computer security contexts it is often called "social hacking" because it can be used to bypass technical safeguards and gain initial access for further exploitation.

Consequences and examples

Successful social-engineering attacks can lead to data breaches, financial fraud, identity theft, ransomware infections, and espionage. Common attack vectors include fraudulent emails requesting password resets, fake IT-support calls, or a malicious USB left in a parking lot to be found and used by an employee. Many large incidents begin with a human-targeted manipulation rather than a direct software vulnerability.

Prevention and mitigation

Defenses combine policy, education, and technical controls. Effective measures include regular awareness training and simulated exercises, strong authentication such as multi-factor authentication (MFA), strict verification procedures for requests involving sensitive data or transfers, robust email filtering and link-handling policies, physical security controls, and a clear incident-response plan. Culture and reporting channels that encourage staff to question unusual requests reduce risk.

Distinctions and further reading

Social engineering differs from pure technical hacking by relying primarily on human interaction, though it is often used alongside malware and network attacks. It can be low-tech or highly targeted and research-led. For practical guidelines and recommended practices, see further reading.

Related articles

Author

AlegsaOnline.com Social engineering (security)

URL: https://en.alegsaonline.com/art/91428

Share

Sources