It can occur through digital messages, voice conversations, in-person contact, or combinations of channels; the manipulated decision, rather than the communication technology, defines the technique.
Attackers may borrow trusted roles, exploit urgency or authority, build rapport over time, or combine a convincing story with compromised accounts and technical tools. Effective defenses reduce reliance on individual judgment by making sensitive requests independently verifiable and unusual activity easy to report.
Key points
Common formsPhishing, pretexting, impersonation, baiting, and physical-access techniques such as tailgating can all use social engineering.
Resilient processesUse independent verification, separation of duties, least privilege, safe account recovery, visitor controls, and clear escalation paths for sensitive requests.
When an attempt is reportedPreserve relevant messages, call details, account activity, or access records; assess whether information, credentials, money, or physical access was exposed.
Important limitationWarning signs and awareness training can reduce risk, but no person can reliably detect every credible deception; blaming recipients also discourages the early reporting that limits harm.