What Is Social Engineering?
Social engineering is the use of manipulation, deception, or pressure to influence someone into revealing information, granting access, or performing an action that could create a security risk.
Common Social Engineering Techniques
Pretexting
An attacker creates a believable story or false identity to convince someone to provide information or take an action.
Impersonation
An attacker pretends to be a trusted person, company, technician, colleague, or authority figure.
Baiting
Baiting uses an appealing offer, reward, file, device, or other temptation to encourage unsafe behavior.
Quid Pro Quo
An attacker offers a supposed benefit or service in exchange for information, access, or an action.
Tailgating
Tailgating occurs when someone gains physical access to a restricted area by following an authorized person or taking advantage of social courtesy.
Common Warning Signs
- Someone creates unusual urgency or pressure.
- A person asks for confidential information unexpectedly.
- Someone claims to have authority but cannot be independently verified.
- You are offered an unexpected reward or benefit.
- A request conflicts with normal security procedures.
- Someone discourages you from checking with another person.
- You are asked to bypass normal access controls.
How to Protect Yourself
- Pause when a request creates unusual pressure.
- Verify the person's identity independently.
- Never share passwords or authentication codes.
- Follow established security procedures.
- Do not allow unknown people to follow you into restricted areas.
- Be cautious about unexpected rewards, offers, and requests.
- Report suspicious activity through the appropriate channel.
Remember
Security is not only about technology. Attackers may target human trust, curiosity, fear, helpfulness, or urgency. Taking a moment to verify a request can prevent many attacks.