- Computer social engineering exploits human errors more than technical failures, becoming the main avenue for many cyberattacks.
- Criminals combine psychological tactics such as urgency, authority, or trust with various digital and physical channels.
- There are numerous types of attacks: phishing, smishing, vishing, baiting, scareware, pretexting, tailgating, watering hole attacks or DNS spoofing, among others.
- The best defense combines education, safe digital habits, good networking practices, and technical protection with robust software and policies.
Cyber social engineering is currently one of cybercriminals' favorite weapons. They don't need to break encryption or bypass state-of-the-art firewalls: all it takes is for someone to trust them enough to click where they shouldn't, open a malicious file, or reveal data they should never share.
Through carefully crafted deceptions , these attackers exploit our biases, emotions, and lapses in attention. They might start with a simple email , a phone call, a WhatsApp message, or even a physical visit to the office. Behind it all could be anything from large-scale identity theft to the starting point of a devastating cyberattack against a company or public organization.
When we talk about social engineering in computer science, we're referring to a psychological manipulation technique whereby an attacker convinces a person to perform actions that compromise their security or that of their organization. Instead of looking for flaws in the software or the network, the attacker focuses on the "weakest link": the user.
An email that appears to be from a colleague requesting confidential documents, a call from a fake tax agency threatening a fine, or the typical absurd offer from a supposed foreign millionaire are classic examples. All these cases have something in common: the attacker gains your trust or manipulates your emotions so that you're the one who opens the door.
In cybersecurity, social engineering is often referred to as "human hacking" because the direct target is the victim's mind, not the operating system or application. Criminals steal login credentials, credit card numbers, bank account details, identity information, or force the execution of malicious software that opens a company's network to more serious attacks, such as ransomware.
This approach is especially appealing to criminals because it avoids complex technical work : instead of breaking encryption or bypassing a firewall, they simply exploit people's curiosity, fear, or good faith. Reports from organizations like ISACA and IBM have been indicating for years that social engineering is one of the main causes of security breaches and also one of the most expensive to fix.
Interestingly, the term “social engineering” first appeared in 1945, coined by the philosopher Karl Popper, who used it to refer to the possibility of redesigning social processes and improving human coexistence, not to steal data. In cybersecurity, however, the concept has been reoriented toward the use of these same psychological dynamics for clearly malicious purposes.
A social engineering attack is rarely completely improvised. It typically follows a relatively structured cycle that gives the perpetrator a high probability of success, even if the interaction appears somewhat spontaneous.
The first step is usually the preparation or reconnaissance phase . The attacker gathers information about the target person or group: names, job titles, emails, phone numbers, work relationships, interests, social media profiles, behavioral patterns, etc. Sometimes a simple LinkedIn search is enough; other times, they rely on previous data leaks , forums, or even on-site observation, such as looking over the shoulder of someone typing their password in a coffee shop.
Next comes the infiltration . The attacker initiates contact and begins to build trust: they may pose as a colleague, supplier, support technician, bank, or well-known platform. They use the information gathered to make their story seem coherent and familiar, reducing the victim's suspicions.
Once the victim feels comfortable or pressured, the exploitation phase begins . This is when the desired outcome is achieved: the person shares their username and password, downloads a supposed report that is actually a virus , enters their bank details on a fake website, or grants physical access to a restricted area.
Finally, there is the withdrawal phase . Once the information has been obtained or the desired action carried out, the attacker disappears or changes location, attempting to cover their tracks and delay detection of the incident as much as possible. In some complex campaigns, the interaction lasts for weeks or months, as occurs in certain romance scams or scams that build trust.
Most of these attacks rely on human biases and emotions that affect us all, regardless of our level of technical expertise. Some of the most exploited elements are:
Intense emotions . When a situation provokes fear, euphoria, extreme curiosity, anger, or guilt, we tend to react before thinking . Criminals know this and design messages that trigger precisely these responses: “Your bank account has been blocked,” “You’ve won an exclusive prize,” “Look at these compromising photos”…
A sense of urgency . Phrases like "last chance," "you only have a few minutes to avoid the charge," or "your account will be deleted today" are designed to get you to act without checking anything . If you think you're going to lose money, access, or a great opportunity, you're much more likely to click on a link or hand over information without thinking twice.
Building trust . Gaining your trust is the foundation of success. To do this, attackers research your interests, language, and environment to appear as approachable people, colleagues, legitimate technicians, or representatives of respected organizations. The more credible the context seems, the fewer questions you'll ask.
There are cases where, in addition to emotional manipulation, social engineering is used in a very "physical" way, for example, by spying on credentials in a company break room, collecting documents from an unattended printer, or searching for abandoned USB drives in meeting rooms. Here, persuasion is combined with simple opportunity.
Principles of manipulation most commonly used by attackers
Social engineering relies heavily on principles studied by social psychology. These mechanisms of influence are so ingrained in our relationships that we often don't notice them until it's too late.
The principle of reciprocity states that when someone does us a favor, we tend to want to return it. A criminal might offer help, information, or a small benefit (a useful document, temporary access, a discount) and later ask for something in return: “Since I helped you with this, could you send me the complete client list so I can cross-reference the data?”
We've seen this kind of urgency before: impossible deadlines, imminent threats, or offers that expire in minutes. It's a very common tactic in phishing emails and SMS messages with malicious links. By accelerating the decision-making process, the attacker weakens your critical defenses.
Consistency is exploited when someone has agreed to do small, seemingly innocuous tasks and, little by little, is asked to take on more sensitive actions. An employee might start by forwarding routine internal reports and end up, almost without realizing it, authorizing payments or sharing critical access because they want to be consistent with their initial collaboration.
The principle of rapport and trust emerges when the attacker appears friendly, shares hobbies, viewpoints, or even flirts with the victim. This familiarity reduces mistrust. In high-value environments (management positions, personnel with classified access, purchasing managers), this strategy is sometimes combined with sextortion : intimate conversations or compromising material are used for blackmail.
Authority is evident every day in CEO fraud or in emails impersonating executives, public agencies, or support services. If the person requesting something appears to have rank, an official seal, or a corporate logo, an employee is more likely to obey without question.
Finally, social validation or peer pressure leads us to accept requests that would seem strange if we believed we were the only ones receiving them. If several colleagues in an email thread appear to agree, or if "everyone is doing it," resistance drops dramatically. This bias is also used extensively in disinformation and fake news campaigns.
Cybercriminals combine these psychological techniques with different channels and formats to reach their victims. Many cyberattacks include some element of social engineering, even if they are known by another name (viruses, ransomware, etc.).
Phishing is probably the most well-known form of social engineering. It involves sending messages that mimic legitimate communications from banks, payment platforms, messaging companies, social networks, government agencies, or even coworkers.
In mass phishing or spam phishing, emails or messages are launched on a large scale with little personalization, hoping that only a small percentage of users will fall for it. Spear phishing , on the other hand, targets specific individuals using real data about their position, company, or activities, while whaling directly targets high-profile figures such as executives, politicians, or celebrities.
The most classic channel is email phishing , with links to fake websites or attachments containing malware. But there are many other variations that have become popular:
- vishingVoice calls, sometimes automated, where the caller pretends to be from the bank, technical support, or another institution. The goal is to get the victim to reveal codes, passwords, or authorize transactions.
- SmishingText messages (SMS or instant messaging) that include dangerous links or phone numbers to call. They often appeal to a sense of urgency: packages being held, prizes, account blocks, etc.
- Phishing on social networks (sometimes called Angler phishing when it impersonates customer service): fake profiles or accounts that impersonate brands, banks, or even friends to redirect the victim to private conversations and extract information or send malicious links.
- Phishing in search engines: fraudulent sites that appear as ads or well-positioned results in search engines, pretending to be banks, online stores, or official services.
- Session phishingFake login pop-ups appear while you're browsing, asking you to authenticate for the real website when you're actually handing your data over to an attacker.
Baiting or bait attacks
In baiting attacks, the criminal tempts the victim with something seemingly free or very attractive : premium software, discount vouchers, exclusive content, sweepstakes, "miracle" tools, etc. The hook is designed to arouse curiosity or greed.
A typical example is leaving an infected USB drive in a strategic location, such as a parking lot, a library, or a company break room. Anyone who finds it might be tempted to plug it in "to see what's on it," causing the automatic infection of their computer or the entire internal network.
Another common tactic involves email attachments promising important reports, invoices, job offers, or gifts. The victim opens the file and, unknowingly, executes malicious code that allows attackers to take partial or complete control of the device.
Pretexting, physical infraction, and tailgating
Pretexting involves constructing an elaborate false scenario to justify a request. The attacker might present themselves as a supplier, auditor, maintenance technician, or even a colleague from another location. Thanks to previously gathered information, their story sounds extremely plausible.
In many cases, this is combined with physical intrusion . A criminal might enter an office building wearing a courier company vest, carrying a delivery note, and exuding confidence. If no one verifies their true identity, they can move around the premises, view screens, collect documents, or connect USB devices to company computers.
Tailgating or piggybacking is another classic technique: the attacker simply follows an authorized person as they enter through a restricted access door, taking advantage of the customary courtesy of "holding the door for the person behind." Once inside, the opportunity to gather information or plant malicious devices is enormous.
Quid pro quo: “I give you something, you give me your data”
In quid pro quo attacks, the perpetrator offers a concrete benefit in exchange for information . This could be participation in a supposed paid market research study, a prize-winning survey , free technical support, or access to a very attractive job offer.
The victim, enticed by the potential prize or "great opportunity," relaxes and shares personal data, credentials, or even installs apps recommended by the perpetrator. In many cases, the promised reward never arrives : the only one who wins is the criminal.
Some campaigns combine social engineering with more technical networking and malware techniques . One example is DNS spoofing or poisoning attacks. By manipulating name resolution records, the attacker ensures that when you type a legitimate URL, your browser ends up on a fake page designed to steal credentials.
So-called "watering hole attacks" target websites frequently visited by the intended victims, such as industry portals, supplier websites, or specialized news sites. The attacker finds a vulnerability on the site, compromises it, and injects malware or malicious code that exploits visitors, especially those whose systems are not up to date.
Scareware is another widespread tactic: pop-up windows or programs that masquerade as security tools and report false infections or hacks. Frightened, the user pays for a supposed solution or enters their data to "clean the system," when in reality they are installing more malware or handing over their information directly to the attackers.
Less common but equally dangerous methods
In addition to the more well-known techniques, some rather creative social engineering campaigns have been documented. For example, fax phishing , where victims received an email supposedly from their bank asking them to print a form, fill it out with their credentials, and fax it to a number controlled by the criminals.
There have also been cases of malware distribution via traditional mail , such as in Japan, where infected CDs were sent to bank customers using physical addresses stolen from the bank itself. Inserting the disc into the computer executed spyware that captured sensitive information.
Many historical malware incidents have succeeded because users, tricked by convincing messages, opened attachments or links that appeared legitimate. Email worms are a textbook example.
The infamous LoveLetter worm (also known as ILOVEYOU) crashed email servers in the early 2000s. Victims received a message with a romantic subject line and an attachment that claimed to be a love letter. The emotional component worked so well that millions of people opened the file, allowing the worm to automatically forward itself to their entire address book.
Another example is Mydoom , which spread through messages that mimicked technical notifications from email servers. Because they appeared to be legitimate system alerts, many users trusted them and opened the attachments. Something similar happened with the Swen worm , which pretended to be an official Microsoft patch to fix Windows vulnerabilities, tricking many people into actually installing the worm itself.
Social engineering also relies on the fear of being discovered . Some Trojans have spread by offering supposedly illegal tools: credit card number generators, tricks to inflate online account balances, or programs to spy on communications. When the file turns out to be malware, many victims prefer not to report it so as not to expose their own unethical intentions.
In other scenarios, attackers have targeted job seekers using online job portals. They sent fake job offers that included Trojan attachments. Because the download was linked to a secret job search, infected employees avoided discussing the incident with their companies for fear of retaliation.
The first line of defense against these deceptions is learning to recognize the warning signs before acting. Essentially, it's about curbing your impulse and calmly analyzing the situation—the exact opposite of what the attacker wants.
It's helpful to ask yourself a few questions whenever something "smells fishy." For example: Am I experiencing a very intense emotion (fear, curiosity, euphoria) after reading this message or answering this call? If your emotional state has spiked, it's a sign that manipulation may be underway.
Another key point is to check if the sender is truly legitimate . Pay attention to email domains ( [email protected] is not the same as [email protected] ), spelling, logo quality, and shortened links or URLs with slight variations. Social media is full of cloned accounts that copy photos and names of friends or brands.
It's also worth checking: Did my friend, colleague, or bank really send me this ? If in doubt, it's best to call the official number directly or speak to them in person before doing anything. Many accounts may have been hacked without the owner's knowledge.
In the case of websites, you should look for suspicious details : strange URLs, translation errors, low-quality images, outdated logos, forms that ask for more data than usual, or the absence of HTTPS on pages that request credentials or banking information.
It's also worth questioning any offer that seems too good to be true . Miracle sweepstakes, investments with guaranteed returns, easy jobs with high salaries, or unexpected prizes in exchange for little effort are usually pure bait.
In addition to detection, it is essential to adopt security routines that hinder the success of these attacks. This involves both everyday behaviors and technical measures.
Secure communication and account management habits
One of the most effective tips is to avoid clicking on links received via email, SMS, or messaging, especially when they appear to be links to banks, corporate websites, or customer areas. It's preferable to manually type the address into your browser or search for the official website using a search engine, always verifying that it's the correct domain.
Multi-factor authentication (MFA) adds an extra layer of protection: even if someone steals your password through social engineering, they'll still need the temporary code, SMS, app token, or biometric data to gain access. Enabling MFA for email, social media, online banking, and critical services drastically reduces the impact of a potential credential theft.
It's also essential to use strong, unique passwords for each service, combining length, numbers, uppercase and lowercase letters, and symbols. Since memorizing dozens of strong passwords is impractical, the most practical solution is to use a password manager that securely stores and generates them.
On social media, it's advisable to limit the amount of personal data you share publicly: birthdates, pet names, schools, frequented places, etc. This information is often used to guess answers to security questions or to design highly personalized attacks.
Finally, it's advisable to be especially cautious with purely online friendships . It's not uncommon for a friendly or romantic relationship that begins online to turn out to be a carefully orchestrated scam based on trust and emotion.
Good network practices and environmental protection
At the network level, a basic rule is to not allow strangers to connect to your main home or office Wi-Fi . If you want to offer a connection to guests, the ideal solution is to use a separate guest network with limited permissions and isolation from other devices.
Using a VPN (virtual private network) adds a significant level of protection, especially when connecting from public or unsecured networks. The traffic is encrypted, and even if someone intercepts the data, what they see will be unreadable. Furthermore, it makes it much harder to track the user across different services.
Don't forget the often overlooked devices: home routers, IoT devices, network printers , in-car infotainment systems, IP cameras, etc. A misconfiguration or outdated firmware on any of these can provide an attacker with an entry point and a wealth of information to tailor their social engineering campaigns.
Device security and constant updates
On the device side, the key is to have comprehensive security software (not just basic antivirus) that includes protection against phishing, ransomware, Trojans, spyware, and other threats. These solutions can block malicious links, suspicious downloads, and anomalous behavior in real time.
It's crucial not to leave computers and mobile phones unlocked in public or semi-public spaces. In work environments, locking your session when you get up from your chair should be an automatic habit. Just a few seconds of physical access can be enough to steal information or install unwanted software.
Likewise, it's essential to keep all software up to date : operating system, browser, office applications, plugins, and also the firmware of routers and other connected devices. Many malware and social engineering campaigns exploit vulnerabilities that are already known and patched, but which remain present in systems that users haven't updated.
Services that monitor data breaches for email addresses or domains let you know if any of your accounts have appeared in a recent breach. If so, it's advisable to change passwords and review login credentials as soon as possible to reduce the risk of exploitation through social engineering attacks based on that data.
It's important to remember that social engineering isn't limited to the digital world. Many attacks combine physical and online techniques . A criminal might knock on an office door pretending to be a technician from a well-known company, gain access to a server room, and, once inside, use a pre-programmed USB drive to compromise the entire network.
Similarly, there are disinformation campaigns that combine social media, traditional media, messaging, and face-to-face conversations to shape political opinions or voting decisions. In these cases, large-scale manipulation relies on the same principles of social validation, authority, and emotional appeal as a simple bank phishing scam, but targeting thousands or millions of people.
Therefore, cybersecurity and critical thinking education is not just a technical matter: it is a basic civic skill . Teaching employees, families, and especially young people to question information, verify sources, and recognize signs of manipulation greatly reduces the impact of these campaigns.
Computer social engineering has shown that you don't need to "hack machines" when you can manipulate the people who use them. From phishing emails to physical intrusions, historical worms, and watering hole attacks, the common denominator is the systematic exploitation of our trust, fears, and biases. Investing in protective technologies is necessary, but it only truly works when combined with prudent digital habits, ongoing training, and a culture of reasonable skepticism toward any unexpected requests for data or sensitive actions. This mix of tools and human judgment is what makes the difference between becoming another victim or stopping the deception in time.