Social Engineering

Social Engineering

Social engineering refers to attacks in which criminals don't outsmart technology, but rather people. They deceive their victims so that they voluntarily hand over passwords, transfer money, or open a dangerous file.

Anyone wanting to break into a foreign computer system has two paths available. One leads through technical gaps, meaning errors in the software. The other leads through the people who use the system. Social engineering is this second path. The attacker uses deception to get the victim to open the door themselves: to reveal a password, initiate a transfer, or click on a file. The term comes from English and roughly means “manipulating people so they do what is wanted”.

The human as the weakest link in the security chain

Technical protective measures have improved significantly in recent years. Passwords are stored encrypted, software is continuously supplied with security updates. People, on the other hand, cannot be patched. They are helpful, under time pressure, and respect authority. Social engineering exploits exactly these traits.

For companies, this represents a cost risk in the millions. A well-known pattern is called the “CEO fraud”: An email appears to come from the executive board and demands an urgent, secret transfer abroad. Employees in accounting have already transferred double-digit million sums this way. No virus scanner in the world can detect an email that is technically completely harmless and contains nothing but a lie.

That is why social engineering regularly ranks high in security reports. A very large proportion of successful attacks begin with a human being deceived — not with someone cracking encryption. Security is therefore not a purely technical issue, but also a matter of training and workflows.

From pretext to bank transfer: the typical sequence

It begins with research. The attacker gathers publicly available information: names of supervisors, department structures, vacation photos, the name of the facility management service. Professional networks and company websites provide most of this for free. The more precise this preparation, the more credible the later story.

Then comes the pretext, known in professional jargon as “pretexting”. The attacker poses as someone normally trusted: IT support, a bank, a parcel service, a new colleague. Added to this is a means of pressure. Popular choices are tight deadlines, threatened account lockouts, or a request to please not tell anyone about it. Under time pressure, people check less carefully.

The variants have their own names. Phishing means deception via mass email, spear phishing means the same thing but tailored to a single person. Vishing runs via phone calls, smishing via text messages. Sometimes the attack is also entirely analog: someone carries two coffee cups and politely asks someone to hold the security door open for them. This is called tailgating.

When AI recreates the boss’s voice

Artificial intelligence has made social engineering significantly more dangerous. In the past, fraudulent emails often gave themselves away through clumsy grammar. Today, language models write flawless, polite business emails in any language and within seconds. This makes it possible to multiply the effort for tailored attacks almost without limit.

Even more delicate are deepfakes, meaning artificially generated voices and videos of real people. There are documented cases in which employees sat in a video conference with supposed colleagues and transferred millions. Every face in the call was fake. Today, a convincing voice copy can be created from just a few seconds of audio recording.

In everyday life, however, you usually encounter social engineering in unspectacular form: the text message about a waiting parcel, the call from “Microsoft Support”, the message with a new phone number and the greeting “Hi Mom”. The protection is always the same reflex. Don’t reply via the channel through which the message arrived, but call back yourself — using a number you already know. A second login step via an app or hardware key helps additionally, because a stolen password alone is then worthless.

Related Products

Latest News

Subscribe free. Unsubscribe the second it sucks.

High-signal news across AI, business, UX, and tech. Every morning.