Pretexting
A social engineering tactic where an attacker invents a false scenario to trick a target into revealing information or granting access.
Definition
Pretexting is a social engineering technique in which an attacker constructs a fabricated scenario, or pretext, to convince a target that they have a legitimate reason to request sensitive information, credentials, or physical access. It relies on impersonation and a plausible narrative rather than technical exploitation.
A pretexting attack typically begins with research: the attacker studies the target organization's structure, vendors, and internal jargon so the story holds up under light scrutiny. The attacker then contacts the victim by phone, email, or in person, posing as an IT technician, auditor, vendor, or senior executive, and asks for something that seems routine, such as a password reset, an invoice approval, or badge access. Because the request is wrapped in a believable context, the victim often complies without verifying the caller's identity through a separate channel.
Pretexting matters because it targets human trust rather than software vulnerabilities, which means firewalls and antivirus tools offer no protection against it. In Indonesian organizations, where hierarchy and politeness norms can make employees reluctant to challenge someone claiming to be a superior or an official auditor, pretexting can be especially effective. Financial institutions and government agencies are frequent targets because a single successful pretext can unlock access to customer data or internal systems.
The most reliable defense is a habit of independent verification: employees should confirm unusual requests through a known phone number or internal system rather than the contact details provided by the requester. Organizations should also establish clear procedures for sensitive actions, such as requiring a second approver for access changes or fund transfers. Regular awareness training that includes realistic pretexting scenarios helps employees recognize the warning signs, such as urgency, unusual requests, and reluctance to be verified.
At a glance
- Severity
- Medium-High
- Prevalence
- Common, especially paired with vishing and BEC
- Primary targets
- Employees who can approve access, payments, or information requests
How it works
- 1
Research: the attacker studies the target organization's structure, vendors, and internal jargon so the story holds up under scrutiny.
- 2
Contact: they reach the victim by phone, email, or in person, posing as an IT technician, auditor, vendor, or senior executive.
- 3
Fabricated scenario: the pretext frames a routine-sounding request, such as a password reset, invoice approval, or badge access.
- 4
Compliance: because the request is wrapped in a believable context, the victim complies without verifying identity through a separate channel.
- 5
Access or information gained: the attacker uses whatever was handed over, credentials, funds, or physical access, to advance the attack.
Warning signs
- Caller or visitor claiming authority, such as an auditor, executive, or vendor, who discourages verification
- A request that seems routine but was not expected or scheduled
- Reluctance to be verified through a known internal number or process
- Use of internal jargon or names to sound legitimate without matching normal procedure
- Pressure to bypass a standard approval step
How to defend
- Confirm unusual requests through a known phone number or internal system, not contact details the requester provides
- Require a second approver for access changes and fund transfers
- Include realistic pretexting scenarios in regular awareness training
- Establish clear procedures for verifying identity before granting access or information
- Encourage employees to question requests that skip normal process, regardless of who is asking
Real-world example
A caller phones a bank branch claiming to be an internal auditor conducting an urgent compliance check, and asks a teller to confirm a customer's account details over the phone. The tone is authoritative and the jargon convincing, but the teller pauses, calls the compliance department's known number instead, and learns no audit was scheduled.
How Claro helps
Claro's phishing and vishing simulations can include pretexting scenarios so employees practice recognizing fabricated stories before facing a real one, with results feeding into each user's risk profile.
Frequently asked questions
What is the difference between pretexting and phishing?
Phishing is usually a message, often email, with a link or attachment. Pretexting is the broader technique of fabricating a believable scenario to justify a request, and it can be delivered by phone, email, or in person, sometimes as part of a phishing or vishing attack.
Why is pretexting effective in Indonesian workplaces?
Hierarchy and politeness norms can make employees reluctant to challenge someone claiming to be a superior or an official auditor, which pretexting deliberately exploits.
How can I tell if a request is a pretext?
Watch for urgency, an unusual or unscheduled request, reluctance to be verified through a known channel, and use of internal terms that sound right but do not match normal procedure.
Does verifying through a separate channel really stop pretexting?
Yes, in almost all cases. Since pretexting relies on the target trusting the contact details or context supplied by the attacker, confirming through an independently known number or system removes that advantage.
Related terms
Social Engineering
The manipulation of people into revealing sensitive information or taking unsafe actions by exploiting trust, emotion, and human psychology rather than technical flaws.
Vishing
Vishing is a voice-based social engineering attack where a caller impersonates a trusted party over the phone to trick victims into revealing sensitive information or authorizing fraudulent actions.
Callback Phishing
A phishing attack that avoids malicious links entirely, instead pressuring the victim to call a phone number where a live scammer completes the attack.
Business Email Compromise
A targeted financial fraud where an attacker poses as a trusted executive, supplier, or colleague over email to trick an employee into transferring money or sensitive data.
Reduce your human risk
Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.
Request a demo