Social Engineering

Learn how attackers manipulate people and how to protect yourself.

What Is Social Engineering?

Social engineering is the use of manipulation, deception, or pressure to influence someone into revealing information, granting access, or performing an action that could create a security risk.

Common Social Engineering Techniques

Pretexting

An attacker creates a believable story or false identity to convince someone to provide information or take an action.

Impersonation

An attacker pretends to be a trusted person, company, technician, colleague, or authority figure.

Baiting

Baiting uses an appealing offer, reward, file, device, or other temptation to encourage unsafe behavior.

Quid Pro Quo

An attacker offers a supposed benefit or service in exchange for information, access, or an action.

Tailgating

Tailgating occurs when someone gains physical access to a restricted area by following an authorized person or taking advantage of social courtesy.

Common Warning Signs

How to Protect Yourself

  1. Pause when a request creates unusual pressure.
  2. Verify the person's identity independently.
  3. Never share passwords or authentication codes.
  4. Follow established security procedures.
  5. Do not allow unknown people to follow you into restricted areas.
  6. Be cautious about unexpected rewards, offers, and requests.
  7. Report suspicious activity through the appropriate channel.

Remember

Security is not only about technology. Attackers may target human trust, curiosity, fear, helpfulness, or urgency. Taking a moment to verify a request can prevent many attacks.

Test Your Social Engineering Awareness →