Tech

Recognising Social Engineering: When the Threat Is a Person, Not a Program

Share
A shadowy figure representing a social engineer manipulating a digital interface and phone

Key Takeaways

Social engineering targets human psychology, not computer systems or software.
Urgency, authority, and fear are the most common emotional levers attackers use.
Attacks can arrive by phone, email, text, social media, or in person.
Slowing down and verifying a request independently is your strongest defence.
Anyone can be a target — these attacks are not limited to corporate or technical users.

Social Engineering

Social engineering is a form of manipulation where an attacker uses psychological tactics to trick people into revealing sensitive information, granting access, or taking harmful actions. Unlike hacking into software, it targets human behaviour — specifically our tendencies to trust, help, and follow authority. These attacks can happen over the phone, by email, in person, or through text messages.

Security professionals categorise social engineering as a non-technical attack vector; it exploits cognitive biases rather than code vulnerabilities, making it effective regardless of how strong a target's technical defences are.

Modern security software can block malware, filter spam, and detect intrusions — but it cannot stop someone from being deceived. That is precisely why social engineering has become a preferred method for bad actors. Instead of breaking through a firewall, an attacker simply convinces someone on the other side to open the door.

The foundation of every social engineering attack is the exploitation of normal human instincts: the desire to be helpful, the tendency to trust authority figures, and the discomfort of conflict or confrontation. Attackers study these patterns and design their approaches around them. The result is that even technically sophisticated people are regularly caught off guard.

“The weakest link in the security chain is the human element. Social engineering bypasses all technologies, including firewalls, by going around them and targeting the person at the keyboard.”

— Kevin Mitnick, Former security consultant and author of 'The Art of Deception'

The Most Common Tactics to Recognise

Understanding how these attacks are structured is the first step to resisting them. Several recurring tactics appear across virtually every category of social engineering attack:

  • Pretexting: The attacker creates a fabricated scenario — a false identity or situation — to justify an unusual request. A caller might claim to be from your bank's fraud department and need to "confirm" your account number to protect you.
  • Urgency and fear: Messages that claim your account will be suspended, a package couldn't be delivered, or legal action is imminent are engineered to bypass rational thought. Panic is a tool.
  • Authority impersonation: Attackers pose as IT departments, government agencies, executives, or law enforcement. People are conditioned to comply with authority, even when something feels slightly wrong.
  • Quid pro quo: An offer of something — tech support, a gift, a prize — in exchange for information or access. These feel helpful but are transactional traps.
  • Baiting: A USB drive left in a car park, or a tempting file attachment, designed to exploit curiosity.

For a closer look at how these tactics play out in digital messages, see our article on phishing emails versus smishing texts.

85%

Of data breaches involving a human element

According to Verizon's Data Breach Investigations Report, the vast majority of breaches involve some form of human interaction, including social engineering.

$2.9B+

Lost to business email compromise annually

The FBI's Internet Crime Complaint Center (IC3) has consistently reported billions in losses each year attributed to business email compromise, a key social engineering method.

3 in 4

Organisations targeted by phishing in a given year

Industry security surveys regularly find that a large majority of organisations experience attempted phishing attacks annually, underscoring how widespread the tactic is.

How to Protect Yourself: Slow Down and Verify

Because social engineering works by creating emotional pressure, the single most effective countermeasure is simply pausing. Attackers depend on quick, unconsidered responses. A moment of deliberate scepticism dramatically reduces your risk.

When in Doubt, Stop and Verify

Any request that creates strong urgency — especially one involving money, passwords, or personal data — should trigger a pause, not immediate action. Contact the organisation directly using contact details from their official website, not from the message or call you received. A few minutes of verification is far less costly than the consequences of being deceived.

Practical habits that make a real difference include:

  1. Verify independently. If someone contacts you claiming to represent a bank, employer, or agency, hang up and call back using the number listed on the organisation's official website — not the number they gave you.
  2. Never give credentials on request. Legitimate organisations will not ask for your password, PIN, or full Social Security number over the phone or by email.
  3. Check the context. Did you initiate this interaction? Unsolicited contact — even from a recognisable name — warrants extra scrutiny.
  4. Talk to someone you trust. Before acting on a high-stakes request, describe the situation to a colleague, friend, or family member. Verbalising often surfaces the red flags you missed in the moment.

Tech Editorial Team is the collective byline for our editorial team and contributor network. Articles published under this byline or an editorial pen name are researched, written, and reviewed according to our editorial standards for clarity, consistency, and independence before publication.

View all articles by Tech Editorial Team →
Disclaimer: The content on this site is for informational purposes only and is not a substitute for professional advice. Always consult a qualified professional for guidance specific to your situation.