Social engineering attacks exploit predictable human behavior to manipulate people into revealing sensitive information or granting unauthorized access. This content covers how attackers use email, text messaging, and in-person tactics to compromise individuals and organizations.
Social Engineering Techniques
No one really likes to be manipulated or controlled, but hackers are pros at it, and you really have to watch out for these social engineering techniques. We're going to get into some of the tactics that hackers use to be able to twist and manipulate people to get what they want.
The human brain is really quite amazing. There's a set of rules in our brain that guides us throughout the day, that tells us how we're supposed to respond in certain circumstances, and that programming comes at a very early age. Some of it is just part of being human, where other parts of it are the culture that we live in or the family that we grew up in, and it programs our brain to think a certain way. The human brain can actually be very predictable in how it behaves in certain circumstances.
What a hacker will do is leverage those rules, that set of rules that we operate off of, for their own malicious purposes. We call that social engineering. Social engineering is when someone can manipulate somebody else and leverage those rules to get them to do exactly what they want.
The first one up on our list is spam. Although I don't typically think of a hacker using spam to start gaining information about a system, it is certainly something that I see salespeople do constantly: using social engineering to try to manipulate things to get more money out of people, or to get people to buy something. So it is something that we do have to be careful of, and just managing spam can be very overwhelming. This is something to watch out for.
Something hackers definitely do, and that I see a lot of, is phishing, and I see a lot of people falling for phishing. This is the type of stuff where they send information out and they hope that you click a link, or they hope that you reply back to the email, so they can gather more information. What they're doing is just casting that line out there to find out if they can get some pieces of information back from you. I see a ton of this and I see it very effectively used.
They'll start doing what's called targeted phishing, or spear phishing, and this is where they start targeting individuals in a company. An example of this that I've seen is where they will target a company. They go and look at the execs, the list of execs on the company page, the company website, and then they'll figure out other people that work within the company, and they'll send out emails to people within the company pretending like they are the CEO or the CFO or the HR manager, or pretending to be one of these other people. They'll send a message to them and say something like, "Hey, I need this really urgent. I need this fast."
And then vice versa: I've also seen where they'll pretend to be somebody within the company, one of the employees, and they're emailing one of the accounting teams saying, "Hey, I need to change my direct deposit. Will you change the direct deposit of my paycheck to go to a different account?" I've definitely seen people fall for this before, so this can be a very effective method of doing it. Although we often will recognize this stuff right away, it just takes one or two successes for these hackers to continue to try to leverage and go after this. This can be really problematic in companies.
I've also seen similar attempts using text messages to get information or get somebody to do something. Smishing is similar to phishing with email, but through text messages, where they're trying to gather information through texting an individual.
Pretexting is where they're trying to get an individual to do something, to take some sort of order. Maybe they're portraying themselves as a police officer, or maybe they're portraying themselves as the CEO of the company, and they say, "Hey, you know what I really would like you to do is get some Google Play cards and send them to me right away. I've got this urgent need." I've seen people get tricked with this before and then send off Google Play cards to somebody that's tricking them, and then the money is lost. So texting is another way that hackers will use to trick individuals.
It doesn't always need to be virtual. It could be in person also. One example of this would be tailgating. Tailgating is where one person who is unauthorized follows an authorized person into a building or into an area, and therefore they're getting access to this area even though they're not supposed to have access to it.
A good story behind this is that I worked at a company that had badges, where you would have to badge into the elevator in order to get onto the floor. What happened is one employee badged into the area, and somebody else came into the elevator right after him. They went up to the second floor. The person that was authorized exited, and then the second person waited until the doors were almost closed and then pushed the open button and followed them into that area, and then actually stole some stuff. So this is an example of tailgating that can happen.
Piggybacking is something similar, except that in the example of piggybacking the authorized person knows the person is not authorized to go into the area but allows them into the area anyway. So the difference here is that with tailgating the authorized person is unaware that somebody is tailgating them, versus piggybacking, where they are aware that the person is not supposed to be in that location but for some reason is letting them into that location.
Then there's also shoulder surfing. This could be as simple as somebody looking over your shoulder when you're typing in a password, or when you have sensitive information up on your screen and somebody is there and looks over your shoulder and gathers that information. So these are some in-person things to watch out for.
One is quid pro quo. This is something for something: I'll give you something if you give me something back.
There's also impersonating that will happen, whether they impersonate the IT person, or a police officer, or one of the execs. They'll impersonate somebody to leverage a position in order to get something out of somebody.
There's also baiting. Baiting is where there's some sort of false premise. They're creating some sort of false scenario and tricking the person into divulging some sort of information or doing something that they normally wouldn't do.
And then we've talked about dumpster diving: going through the garbage, jumping into the dumpster, looking for sensitive information. Sometimes people will collect paperwork in a box before it goes to get shredded, and that is going to be sensitive information. So they're gaining sensitive information by going through the trash.
There are a lot of techniques that hackers can use to social engineer. They know how people work, how they operate, and they can leverage that. They can leverage these different mechanisms to actually facilitate their own needs. We would like to think that we could rise above this, and we can, through education, but the hackers do this on a daily basis, so they've gotten really good and really convincing at what they do. Some of it just seems really obvious to us. Some of it comes in through our email and seems really obvious and we get rid of it right away. But other stuff can be very tricky, and it's getting more sophisticated. Hackers are getting better and better at what they're doing.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →