# What is Social Engineering?

> Social engineering is an umbrella term for attacks that use deception, impersonation, influence, or manufactured pressure to persuade a person to disclose information, grant access, transfer value, or perform another action that weakens security.

- Canonical URL: https://yellowcube.eu/glossary/social-engineering/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

It can occur through digital messages, voice conversations, in-person contact, or combinations of channels; the manipulated decision, rather than the communication technology, defines the technique.

Attackers may borrow trusted roles, exploit urgency or authority, build rapport over time, or combine a convincing story with compromised accounts and technical tools. Effective defenses reduce reliance on individual judgment by making sensitive requests independently verifiable and unusual activity easy to report.

### Key points

- **Common forms:** Phishing, pretexting, impersonation, baiting, and physical-access techniques such as tailgating can all use social engineering.
- **Resilient processes:** Use independent verification, separation of duties, least privilege, safe account recovery, visitor controls, and clear escalation paths for sensitive requests.
- **When an attempt is reported:** Preserve relevant messages, call details, account activity, or access records; assess whether information, credentials, money, or physical access was exposed.
- **Important limitation:** Warning signs and awareness training can reduce risk, but no person can reliably detect every credible deception; blaming recipients also discourages the early reporting that limits harm.

### Related terms

[Phishing](<https://yellowcube.eu/glossary/phishing/>) · [Pretexting](<https://yellowcube.eu/glossary/pretexting/>) · [Tailgating](<https://yellowcube.eu/glossary/tailgating/>) · [Security awareness training](<https://yellowcube.eu/glossary/security-awareness-training/>) · [Identity theft](<https://yellowcube.eu/glossary/identity-theft/>)

### Sources

[NIST glossary: Social Engineering](https://csrc.nist.gov/glossary/term/social_engineering) · [Canadian Centre for Cyber Security: Social engineering](https://www.cyber.gc.ca/en/guidance/social-engineering-itsap00166) · [NIST SP 800-171 Rev. 3](https://csrc.nist.gov/pubs/sp/800/171/r3/final)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

