Overview
Social engineering uses psychological manipulation to deceive individuals into revealing confidential information or taking actions that compromise security. It targets human trust and behavior rather than technical vulnerabilities — and succeeds regardless of how strong an organization’s technical defenses are.
Terminology
| Term | Definition |
|---|---|
| Social Engineering | Psychological manipulation used to deceive individuals into compromising security |
| Phishing | Fraudulent messages impersonating legitimate senders to steal information or credentials |
| Pretexting | Creating a fabricated identity or scenario to manipulate a target into compliance |
| Baiting | Luring a target with something enticing to trigger a security compromise |
| Tailgating | Physically following an authorized person into a restricted area |
| Quid Pro Quo | Offering something of value in exchange for sensitive information |
| Vishing | Voice-based phishing conducted over the phone |
| Spear Phishing | Targeted phishing directed at a specific individual or organization |
Core Concepts
Social Engineering Techniques
| Technique | Description | Example |
|---|---|---|
| Phishing | Fake emails or messages designed to appear legitimate | Email appearing to be from IT requesting a password reset |
| Pretexting | Attacker assumes a false identity with a fabricated scenario | Caller pretending to be HR or tech support |
| Baiting | Offer of something enticing to lure the target into a compromise | Infected USB drive left in a parking lot |
| Tailgating | Physically following someone into a restricted area without authorization | Walking in behind a badge-holding employee |
| Quid Pro Quo | Offering a benefit in exchange for sensitive information | Offer of “free IT support” in exchange for login credentials |
Why Social Engineering Works
Social engineering succeeds because it exploits human psychology rather than technical weaknesses:
- Exploits trust, urgency, authority, and fear
- Bypasses technical security controls entirely
- Effective against any organization regardless of technical security maturity
- Humans are the most consistent vulnerability in any security program