The fabricated context — the pretext — gives the target a reason to disclose information, grant access, transfer value, or perform another action. It can be delivered through email, text, voice, online interaction, or face-to-face contact.
A pretext may be brief, such as a supposed support request, or developed over several interactions. Attackers often combine accurate public or stolen details with urgency, authority, sympathy, or routine workplace language, so factual details within the story do not establish its legitimacy.
Key points
VerificationConfirm both the requester’s identity and their authority through trusted records or a separate channel, and verify unusual events or process changes with the responsible team.
Resilient processesMinimize exposed personal data, apply least privilege, document high-risk workflows, separate approval duties, and provide a safe way to pause and escalate questionable requests.
When discoveredPreserve communications and access records, identify information or actions already provided, notify affected process owners, and assess linked accounts, payments, facilities, or third parties.
Important limitationA convincing narrative is not evidence that a person acted carelessly, while an unusual legitimate request is not automatically malicious; controls should support verification without blame or premature accusation.