Many security breaches do not start with clever code. They start with a conversation: a phone call from “the IT department”, a message from a “colleague” asking for a quick favour, or a stranger who simply walks in behind an employee. This approach is called social engineering, and it works because it targets people rather than software.
Understanding how it works is one of the most useful security skills you can learn, because no firewall can fully protect someone who is persuaded to open the door.
What Is Social Engineering?
Social engineering is the use of deception and psychological manipulation to get someone to reveal information, grant access or take an action they would not normally take. The attacker’s goal might be a password, a bank transfer, access to a building or a piece of sensitive data.
The key idea is that humans are often the easiest path into a system. Technical defences can be strong, but a convincing story can sometimes bypass them entirely.
The Psychology Behind the Tricks
Social engineers rely on a small set of well-known human tendencies. Recognising them makes manipulation easier to spot:
- Authority: we tend to obey people who seem to be in charge, such as a manager, a police officer or a technician.
- Urgency: deadlines and threats (“your account will be closed today”) push us to act before thinking.
- Trust and likability: friendly, helpful people are rarely questioned.
- Reciprocity: if someone does us a small favour, we feel obliged to return it.
- Fear and curiosity: alarming warnings or tempting offers make us click, call or reply.
Common Social Engineering Techniques
Attacks come in many forms, both digital and physical. The table below summarises the most widely recognised ones.
| Technique | How it works | Typical example |
|---|---|---|
| Phishing | Fraudulent emails or messages that imitate a trusted sender | A message asking you to “verify” your account on a fake page |
| Vishing | Fraud carried out by phone call | A caller claiming to be from your bank asking for a code |
| Smishing | Fraud carried out by text message | A text about a missed delivery with a suspicious link |
| Pretexting | Inventing a believable scenario to extract information | Someone posing as support staff who “needs” your login details |
| Baiting | Offering something tempting to lure the victim | A USB drive left in a car park, or a “free” download |
| Tailgating | Following an authorised person into a restricted area | A stranger carrying boxes who asks you to hold the door |
How an Attack Usually Unfolds
Although each case is different, many social engineering attacks follow a similar pattern:
- Research: the attacker gathers information from public sources such as social media profiles, company websites and job listings.
- Contact: they approach the target using a believable identity or story.
- Pressure: they create urgency, fear or a sense of obligation so the target does not stop to verify.
- Request: they ask for something specific: a password, a payment, a file or physical access.
- Exit: once they have what they need, they disappear, often before the victim realises anything happened.
Notice how much of this depends on information people share openly. The more details about your job, colleagues and routines are public, the more convincing an impersonator can be.
Warning Signs to Watch For
Good social engineers sound natural, but certain patterns appear again and again:
- An unexpected request, especially one involving money, passwords or sensitive data.
- Strong pressure to act immediately or to keep the request secret.
- A request to skip the normal procedure “just this once”.
- Someone claiming authority but unwilling to be verified through an official channel.
- An offer that seems too good to be true.
- Requests for one-time codes or verification codes, which should never be shared with anyone.
Practical Habits That Protect You
You do not need to become suspicious of everyone. A few consistent habits stop most attacks:
- Pause before acting. Urgency is the attacker’s best tool, so slowing down removes their advantage.
- Verify through a separate channel. If someone asks for something sensitive, hang up and call back using a number you already know, or contact the person directly through a trusted route.
- Never share codes or passwords. Legitimate organisations do not ask for them by phone, email or chat.
- Limit what you share publicly. Details about your workplace, travel plans and contacts can be used to build a believable story.
- Use multi-factor authentication. Even if a password is stolen, a second factor can block access.
- Follow procedures. Verification steps exist for a reason. A polite refusal is always acceptable.
- Report suspicious contacts. Telling your IT or security team quickly helps protect everyone else.
Why Organisations Need a Security Culture
Because these attacks target people, training matters as much as technology. Organisations that encourage employees to question unusual requests, and that never punish someone for reporting a mistake, tend to detect problems earlier. A person who feels safe saying “I think I clicked something I should not have” gives the security team a chance to react in time.
Clear processes also help. When payments, password resets and access requests always follow a defined verification routine, a single convincing phone call is much less likely to succeed.
Conclusion
Social engineering succeeds by exploiting normal human traits such as trust, helpfulness and the instinct to respond to urgency. The best defence is awareness: know the common techniques, notice the warning signs, and verify before you act. Small habits, repeated consistently, make you a much harder target.
If you want to go deeper into how security works in practice, Cursa offers free online courses related to information security and cyber security that can help you build these skills step by step.



























