# What is Pretexting?

> Pretexting is a social-engineering technique in which an attacker invents or misrepresents a role, relationship, event, or need to make a request seem legitimate.

- Canonical URL: https://yellowcube.eu/glossary/pretexting/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

The fabricated context — the pretext — gives the target a reason to disclose information, grant access, transfer value, or perform another action. It can be delivered through email, text, voice, online interaction, or face-to-face contact.

A pretext may be brief, such as a supposed support request, or developed over several interactions. Attackers often combine accurate public or stolen details with urgency, authority, sympathy, or routine workplace language, so factual details within the story do not establish its legitimacy.

### Key points

- **Verification:** Confirm both the requester’s identity and their authority through trusted records or a separate channel, and verify unusual events or process changes with the responsible team.
- **Resilient processes:** Minimize exposed personal data, apply least privilege, document high-risk workflows, separate approval duties, and provide a safe way to pause and escalate questionable requests.
- **When discovered:** Preserve communications and access records, identify information or actions already provided, notify affected process owners, and assess linked accounts, payments, facilities, or third parties.
- **Important limitation:** A convincing narrative is not evidence that a person acted carelessly, while an unusual legitimate request is not automatically malicious; controls should support verification without blame or premature accusation.

### Related terms

[Social engineering](<https://yellowcube.eu/glossary/social-engineering/>) · [Phishing](<https://yellowcube.eu/glossary/phishing/>) · [Vishing](<https://yellowcube.eu/glossary/vishing/>) · [Business email compromise (BEC)](<https://yellowcube.eu/glossary/business-email-compromise/>) · [Identity theft](<https://yellowcube.eu/glossary/identity-theft/>)

### Sources

[Canadian Centre for Cyber Security: Social engineering](https://www.cyber.gc.ca/en/guidance/social-engineering-itsap00166) · [NIST glossary: Social Engineering](https://csrc.nist.gov/glossary/term/social_engineering) · [NIST SP 800-171 Rev. 3](https://csrc.nist.gov/pubs/sp/800/171/r3/final)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

