Social Engineering: How Attackers Exploit Human Trust and How to Resist

Social engineering tricks people instead of breaking systems. Learn the common tactics, the psychology behind them and simple habits that stop most attacks.

Share on Linkedin Share on WhatsApp

Estimated reading time: 7 minutes

Article image Social Engineering: How Attackers Exploit Human Trust and How to Resist

Many security breaches do not start with clever code. They start with a conversation: a phone call from “the IT department”, a message from a “colleague” asking for a quick favour, or a stranger who simply walks in behind an employee. This approach is called social engineering, and it works because it targets people rather than software.

Understanding how it works is one of the most useful security skills you can learn, because no firewall can fully protect someone who is persuaded to open the door.

What Is Social Engineering?

Social engineering is the use of deception and psychological manipulation to get someone to reveal information, grant access or take an action they would not normally take. The attacker’s goal might be a password, a bank transfer, access to a building or a piece of sensitive data.

The key idea is that humans are often the easiest path into a system. Technical defences can be strong, but a convincing story can sometimes bypass them entirely.

The Psychology Behind the Tricks

Social engineers rely on a small set of well-known human tendencies. Recognising them makes manipulation easier to spot:

  • Authority: we tend to obey people who seem to be in charge, such as a manager, a police officer or a technician.
  • Urgency: deadlines and threats (“your account will be closed today”) push us to act before thinking.
  • Trust and likability: friendly, helpful people are rarely questioned.
  • Reciprocity: if someone does us a small favour, we feel obliged to return it.
  • Fear and curiosity: alarming warnings or tempting offers make us click, call or reply.

Common Social Engineering Techniques

Attacks come in many forms, both digital and physical. The table below summarises the most widely recognised ones.

TechniqueHow it worksTypical example
PhishingFraudulent emails or messages that imitate a trusted senderA message asking you to “verify” your account on a fake page
VishingFraud carried out by phone callA caller claiming to be from your bank asking for a code
SmishingFraud carried out by text messageA text about a missed delivery with a suspicious link
PretextingInventing a believable scenario to extract informationSomeone posing as support staff who “needs” your login details
BaitingOffering something tempting to lure the victimA USB drive left in a car park, or a “free” download
TailgatingFollowing an authorised person into a restricted areaA stranger carrying boxes who asks you to hold the door

How an Attack Usually Unfolds

Although each case is different, many social engineering attacks follow a similar pattern:

  1. Research: the attacker gathers information from public sources such as social media profiles, company websites and job listings.
  2. Contact: they approach the target using a believable identity or story.
  3. Pressure: they create urgency, fear or a sense of obligation so the target does not stop to verify.
  4. Request: they ask for something specific: a password, a payment, a file or physical access.
  5. Exit: once they have what they need, they disappear, often before the victim realises anything happened.

Notice how much of this depends on information people share openly. The more details about your job, colleagues and routines are public, the more convincing an impersonator can be.

Warning Signs to Watch For

Good social engineers sound natural, but certain patterns appear again and again:

  • An unexpected request, especially one involving money, passwords or sensitive data.
  • Strong pressure to act immediately or to keep the request secret.
  • A request to skip the normal procedure “just this once”.
  • Someone claiming authority but unwilling to be verified through an official channel.
  • An offer that seems too good to be true.
  • Requests for one-time codes or verification codes, which should never be shared with anyone.

Practical Habits That Protect You

You do not need to become suspicious of everyone. A few consistent habits stop most attacks:

  • Pause before acting. Urgency is the attacker’s best tool, so slowing down removes their advantage.
  • Verify through a separate channel. If someone asks for something sensitive, hang up and call back using a number you already know, or contact the person directly through a trusted route.
  • Never share codes or passwords. Legitimate organisations do not ask for them by phone, email or chat.
  • Limit what you share publicly. Details about your workplace, travel plans and contacts can be used to build a believable story.
  • Use multi-factor authentication. Even if a password is stolen, a second factor can block access.
  • Follow procedures. Verification steps exist for a reason. A polite refusal is always acceptable.
  • Report suspicious contacts. Telling your IT or security team quickly helps protect everyone else.

Why Organisations Need a Security Culture

Because these attacks target people, training matters as much as technology. Organisations that encourage employees to question unusual requests, and that never punish someone for reporting a mistake, tend to detect problems earlier. A person who feels safe saying “I think I clicked something I should not have” gives the security team a chance to react in time.

Clear processes also help. When payments, password resets and access requests always follow a defined verification routine, a single convincing phone call is much less likely to succeed.

Conclusion

Social engineering succeeds by exploiting normal human traits such as trust, helpfulness and the instinct to respond to urgency. The best defence is awareness: know the common techniques, notice the warning signs, and verify before you act. Small habits, repeated consistently, make you a much harder target.

If you want to go deeper into how security works in practice, Cursa offers free online courses related to information security and cyber security that can help you build these skills step by step.

NTFS, exFAT, FAT32 and APFS: Choosing the Right File System for a Drive

Understand what a file system does and how NTFS, exFAT, FAT32, APFS and ext4 differ, so you can format drives without losing compatibility.

Text Encoding Explained: ASCII, Unicode and Why You Sometimes See Strange Symbols

Learn how computers store text, what ASCII and Unicode actually are, why UTF-8 became the standard, and how to fix files that display garbled characters.

Idempotency in APIs: Why Retrying a Request Should Be Safe

Learn what idempotency means in backend development, which HTTP methods provide it, and how idempotency keys prevent duplicate operations.

What Is a CDN? How Content Delivery Networks Make Websites Fast

Learn what a CDN is, how edge caching and cache headers work, what a cache hit means, and when a CDN helps — or does not.

Semantic Versioning Explained: What a Number Like 2.4.1 Actually Tells You

MAJOR.MINOR.PATCH is a promise, not decoration. Learn to read version numbers and understand dependency range symbols.

What Is a Virtual Machine? Virtualization Explained for Beginners

Learn what a virtual machine is, how hypervisors work, how VMs differ from containers, and when to use each one.

How HTTPS Works: Certificates, the TLS Handshake and What the Padlock Really Means

A beginner-friendly walkthrough of HTTPS: what TLS certificates prove, how the handshake works, and what the browser padlock does not guarantee.

Big O Notation Explained: How to Talk About Code Efficiency

A beginner-friendly guide to Big O notation: what it measures, the most common complexity classes, and how to reason about the cost of your code.