Social Engineering

Attackers target people, not just computers.

Social engineering is manipulation. Attackers use trust, urgency, fear, authority, curiosity, or helpfulness to get someone to reveal information, approve access, send money, or bypass normal procedures.

The Basics

What social engineering looks like.

Social engineering can happen by email, phone, text, chat, video call, in person, or through social media. The method changes, but the goal is usually the same: pressure someone into doing something they would not normally do.

Authority

"This is the CEO." "This is IT." "This is law enforcement." Attackers pretend to be someone who can give orders.

Urgency

"I need this now." "Your account will close." "A warrant has been issued." Time pressure is used to prevent verification.

Trust

Attackers may use real names, job titles, public information, or previous conversations to sound legitimate.

Examples

Common workplace social engineering attempts.

Fake IT support call

A caller says they are from IT and need your password, MFA code, or remote access to fix a problem.

Executive gift card request

A text appears to come from a supervisor asking you to buy gift cards while they are "in a meeting."

Vendor bank change

An email claims a vendor changed banking details and asks accounts payable to send the next payment to a new account.

Tailgating

Someone follows an employee through a locked door by carrying boxes, acting rushed, or pretending they forgot a badge.

Help desk impersonation

An attacker calls the help desk pretending to be an employee who lost access and needs a password reset.

Fake document share

A message says a coworker shared a file, but the link leads to a fake login page.

Recognize It

Warning signs to watch for.

One warning sign may not prove something is malicious, but several together should make you stop and verify before acting.

  • They pressure you to act immediately.
  • They ask you to keep the request secret.
  • They ask for passwords, MFA codes, gift cards, cryptocurrency, or payment changes.
  • They want you to bypass normal approval or purchasing procedures.
  • They contact you from a new number, personal email, or unusual account.
  • They get frustrated when you say you need to verify.

What To Do

Stop, verify, and report.

  1. Pause before acting. Social engineering relies on speed. Slowing down helps you think clearly.
  2. Use a different channel. Verify the request using a known phone number, official system, or in-person confirmation.
  3. Do not share secrets. Never provide passwords, MFA codes, recovery codes, or security answers to someone who contacts you.
  4. Follow normal procedures. Payment changes, purchases, password resets, and access approvals should use approved workflows.
  5. Report suspicious contact. Tell IT, your supervisor, security, or the designated reporting contact.
  6. If you made a mistake, report fast. Quick reporting can help reset accounts, block payments, and limit damage.

Simple Rule

Verification is not rude. It is professional.

Employees should feel comfortable saying, "I need to verify this through our normal process." A legitimate coworker, vendor, executive, or IT employee should understand.