Attack technique

Social Engineering

The manipulation of people into revealing sensitive information or taking unsafe actions by exploiting trust, emotion, and human psychology rather than technical flaws.

Definition

Social engineering is a category of attack that targets people rather than technology. Instead of breaking through firewalls or exploiting software bugs, the attacker manipulates a person into handing over credentials, transferring money, granting access, or installing malware. It works by exploiting predictable human responses such as trust in authority, fear of consequences, the urge to be helpful, curiosity, and the pressure of a deadline. Because the human is often the most accessible point of entry into an organization, social engineering underpins the majority of modern breaches.

Social engineering typically unfolds in stages. The attacker first gathers information about the target, often from public sources such as social media, company websites, and data leaks. They then craft a pretext, a believable cover story, and make contact through email, phone, text message, a chat app, or even in person. Once trust or urgency is established, they push the victim toward the goal: clicking a malicious link, revealing a password or one-time code, approving a payment, or letting someone into a restricted area. The final step often involves covering tracks so the intrusion goes unnoticed.

The tactics take many forms. Phishing, spear-phishing, and whaling deliver deceptive messages by email; vishing uses phone calls; smishing uses SMS; and quishing uses malicious QR codes. Business email compromise impersonates an executive or supplier to authorize fraudulent transfers. Other techniques include pretexting (inventing a scenario to extract information), baiting (leaving infected media or offering something enticing), and tailgating (physically following an authorized person through a secure door). What unites them all is the deliberate exploitation of human judgment.

Social engineering matters because it sidesteps even strong technical controls. An attacker who convinces an employee to approve a login prompt or share a verification code can defeat defenses that would otherwise hold. Defending against it requires a layered approach: ongoing security awareness training, clear verification procedures for sensitive requests, phishing-resistant multi-factor authentication, and a culture where employees feel safe reporting suspicious contact rather than staying quiet. Technology helps filter and detect attacks, but informed and supported people remain the decisive defense.

At a glance

Severity
High
Prevalence
Very common, underlies most breaches
Primary targets
Anyone with access to information, money, or physical spaces

How it works

  1. 1

    Information gathering: the attacker researches the target using public sources such as social media, company websites, and data leaks.

  2. 2

    Pretext: they craft a believable cover story designed to establish trust or urgency.

  3. 3

    Contact: they reach the target through email, phone, text message, chat, or even in person.

  4. 4

    Manipulation: once trust or urgency is established, they push the victim toward the goal, such as clicking a link, revealing a code, or approving a payment.

  5. 5

    Cover tracks: the final step often involves covering tracks so the intrusion goes unnoticed for as long as possible.

Warning signs

  • Unusual request that creates urgency, fear, or a strong desire to help
  • Contact from someone claiming authority who discourages verification
  • A request that bypasses normal process or asks you to keep something secret
  • Unfamiliar person seeking physical access to a restricted area
  • Pressure to act before you have time to think or check with someone else

How to defend

  • Verify unusual or sensitive requests through an independent, known channel
  • Follow clear procedures for verifying identity before granting access or information
  • Use phishing-resistant multi-factor authentication wherever possible
  • Build a culture where reporting suspicious contact is encouraged, not punished
  • Take part in ongoing security awareness training across every channel attackers use

Real-world example

A receptionist at an Indonesian government office is approached by someone claiming to be a contractor who forgot their access badge. Under time pressure and wanting to be helpful, the receptionist holds the door open, allowing the person to walk into a restricted area without ever being verified.

How Claro helps

Claro helps organizations measure and reduce their exposure to social engineering across every channel attackers actually use. It runs realistic phishing, vishing, and WhatsApp simulations to reveal where people are most susceptible, then delivers targeted micro-module training and just-in-time awareness to those who need it. A built-in reporting loop rewards employees who flag suspicious messages, while per-user and per-department risk scoring shows leadership exactly how human risk is trending over time. The goal is genuine behavior change, not training box-ticking, so the workforce becomes a reliable line of defense.

Frequently asked questions

What is Social Engineering?

Social engineering is the manipulation of people, rather than technology, into giving up information or taking unsafe actions. It exploits trust, urgency, fear, and authority, and underlies most phishing, vishing, and pretexting attacks.

What is the difference between social engineering and hacking?

Hacking typically targets technology, such as software vulnerabilities or network weaknesses. Social engineering targets people, manipulating human psychology like trust, fear, and urgency to achieve the same goals, such as gaining access or stealing information.

What are the main types of social engineering?

Common forms include phishing, spear-phishing, and whaling by email; vishing by phone; smishing by SMS; pretexting, where an attacker invents a scenario to extract information; baiting, which offers something enticing; and tailgating, physically following someone through a secure door.

Why does social engineering work even with strong technical security?

It sidesteps technical controls entirely by convincing a person to take the harmful action themselves, such as approving a login or sharing a code. No firewall or antivirus can stop an authorized user from voluntarily handing over access.

How can organizations reduce social engineering risk?

Layered defenses work best: ongoing security awareness training, clear verification procedures for sensitive requests, phishing-resistant multi-factor authentication, and a culture where employees feel safe reporting suspicious contact rather than staying quiet.

What is social engineering called in Bahasa Indonesia?

It is usually referred to as social engineering in English even by Indonesian practitioners. The literal translation rekayasa sosial exists but in Indonesian it more commonly denotes a sociology concept, so security teams writing internal policy should use the English term or qualify it as rekayasa sosial dalam keamanan siber.

Reduce your human risk

Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.

Request a demo