TechKnowSurge
CompTIA A+ Core 2 2.4 Cisco CCST IT 5.2 Cisco CyberOps Associate 2.7 CompTIA Network+ 4.2
VideoNetworkFree

Social Engineering Techniques

Social engineering attacks exploit predictable human behavior to manipulate people into revealing sensitive information or granting unauthorized access. This content covers how attackers use email, text messaging, and in-person tactics to compromise individuals and organizations.

Complete this video to capture a CTF flag worth 1 point.

About this video

Social engineering exploits the predictable, rule-based nature of human psychology — patterns shaped by culture, upbringing, and basic behavioral instincts — to manipulate people into doing things that serve an attacker's goals. Rather than targeting systems directly, attackers target people, using those deeply ingrained behavioral tendencies as an entry point into networks, facilities, and sensitive data. Email remains one of the most common vectors. Spam can be used to probe or overwhelm targets, while phishing casts a wide net hoping recipients will click malicious links or reply with useful information. Spear phishing narrows that focus to specific individuals within an organization, with attackers impersonating executives or colleagues to manufacture urgency — requesting wire transfers, payroll changes, or other high-value actions. Similar tactics extend to text messaging through smishing, which mirrors phishing over SMS, and pretexting, where attackers construct a false identity or scenario to pressure a target into compliance. Physical environments present their own set of threats. Tailgating occurs when an unauthorized individual follows an authorized person into a secured area without their knowledge, while piggybacking involves the same scenario except the authorized person knowingly permits entry. Shoulder surfing is as straightforward as it sounds — observing someone enter a password or view sensitive data in a shared space. Beyond these, attackers also employ quid pro quo schemes, impersonation of authority figures such as IT staff or law enforcement, baiting through false premises, and dumpster diving to recover improperly discarded documents containing sensitive information. Attackers who rely on social engineering study human behavior professionally and refine their approaches over time, making their methods increasingly convincing and difficult to detect. Awareness of the full range of techniques — across digital, verbal, and physical channels — is a critical layer of any organization's security posture.

What you'll learn

What's covered

Social Engineering Techniques

Aligned to

CompTIA A+ Core 2
2.4 Explain common social-engineering attacks, threats, and vulnerabilities.
Cisco CCST IT
5.2 Recognize how to avoid becoming a victim of social engineering attacks.
Cisco CyberOps Associate
2.7 Describe social engineering attacks (manual and generative AI).
CompTIA Network+
4.2 Summarize various types of attacks and their impact to the network.

Key terms

Social Engineering
A manipulation technique that exploits human psychology to trick individuals into revealing confidential information.
Phishing
A social engineering attack that uses deceptive emails or messages to trick users into revealing sensitive information.
Spear Phishing
A targeted phishing attack directed at a specific individual or organization using personalized information.
Smishing
A social engineering attack delivered via SMS text messages that tricks recipients into clicking malicious links, calling fraudulent numbers, or revealing sensitive information such as account credentials or financial data.
Pretexting
A social engineering technique in which an attacker fabricates a convincing scenario — such as impersonating IT support, a vendor, or an authority figure — to manipulate a target into performing an action or disclosing sensitive information.
Tailgating
A physical social engineering technique where an unauthorized person follows an authorized individual into a restricted area without their knowledge.
Piggybacking
A physical social engineering technique where an unauthorized person gains entry to a restricted area with the knowing consent of an authorized individual.
Shoulder Surfing
A social engineering technique where an attacker observes a target's screen or keyboard to steal sensitive information such as passwords.
Baiting
A social engineering technique that lures a target with a false premise or enticing offer to trick them into divulging information or taking an unintended action.
Quid Pro Quo
A social engineering technique where an attacker offers a service or benefit in exchange for information or access from the target.
Impersonation
A social engineering technique where an attacker pretends to be a trusted person or authority figure to manipulate a target into granting access or revealing information.
Dumpster Diving
A social engineering technique where an attacker searches through discarded materials such as trash or recycling to find sensitive information.

Transcript

No one really likes to be manipulated or controlled, but hackers are pros at it, and you really have to watch out for these social engineering techniques. We're going to get into some of the tactics that hackers use to be able to twist and manipulate people to get what they want.

What social engineering is

The human brain is really quite amazing. There's a set of rules in our brain that guides us throughout the day, that tells us how we're supposed to respond in certain circumstances, and that programming comes at a very early age. Some of it is just part of being human, where other parts of it are the culture that we live in or the family that we grew up in, and it programs our brain to think a certain way. The human brain can actually be very predictable in how it behaves in certain circumstances.

What a hacker will do is leverage those rules, that set of rules that we operate off of, for their own malicious purposes. We call that social engineering. Social engineering is when someone can manipulate somebody else and leverage those rules to get them to do exactly what they want.

Email

The first one up on our list is spam. Although I don't typically think of a hacker using spam to start gaining information about a system, it is certainly something that I see salespeople do constantly: using social engineering to try to manipulate things to get more money out of people, or to get people to buy something. So it is something that we do have to be careful of, and just managing spam can be very overwhelming. This is something to watch out for.

Something hackers definitely do, and that I see a lot of, is phishing, and I see a lot of people falling for phishing. This is the type of stuff where they send information out and they hope that you click a link, or they hope that you reply back to the email, so they can gather more information. What they're doing is just casting that line out there to find out if they can get some pieces of information back from you. I see a ton of this and I see it very effectively used.

They'll start doing what's called targeted phishing, or spear phishing, and this is where they start targeting individuals in a company. An example of this that I've seen is where they will target a company. They go and look at the execs, the list of execs on the company page, the company website, and then they'll figure out other people that work within the company, and they'll send out emails to people within the company pretending like they are the CEO or the CFO or the HR manager, or pretending to be one of these other people. They'll send a message to them and say something like, "Hey, I need this really urgent. I need this fast."

And then vice versa: I've also seen where they'll pretend to be somebody within the company, one of the employees, and they're emailing one of the accounting teams saying, "Hey, I need to change my direct deposit. Will you change the direct deposit of my paycheck to go to a different account?" I've definitely seen people fall for this before, so this can be a very effective method of doing it. Although we often will recognize this stuff right away, it just takes one or two successes for these hackers to continue to try to leverage and go after this. This can be really problematic in companies.

Texting

I've also seen similar attempts using text messages to get information or get somebody to do something. Smishing is similar to phishing with email, but through text messages, where they're trying to gather information through texting an individual.

Pretexting is where they're trying to get an individual to do something, to take some sort of order. Maybe they're portraying themselves as a police officer, or maybe they're portraying themselves as the CEO of the company, and they say, "Hey, you know what I really would like you to do is get some Google Play cards and send them to me right away. I've got this urgent need." I've seen people get tricked with this before and then send off Google Play cards to somebody that's tricking them, and then the money is lost. So texting is another way that hackers will use to trick individuals.

In person

It doesn't always need to be virtual. It could be in person also. One example of this would be tailgating. Tailgating is where one person who is unauthorized follows an authorized person into a building or into an area, and therefore they're getting access to this area even though they're not supposed to have access to it.

A good story behind this is that I worked at a company that had badges, where you would have to badge into the elevator in order to get onto the floor. What happened is one employee badged into the area, and somebody else came into the elevator right after him. They went up to the second floor. The person that was authorized exited, and then the second person waited until the doors were almost closed and then pushed the open button and followed them into that area, and then actually stole some stuff. So this is an example of tailgating that can happen.

Piggybacking is something similar, except that in the example of piggybacking the authorized person knows the person is not authorized to go into the area but allows them into the area anyway. So the difference here is that with tailgating the authorized person is unaware that somebody is tailgating them, versus piggybacking, where they are aware that the person is not supposed to be in that location but for some reason is letting them into that location.

Then there's also shoulder surfing. This could be as simple as somebody looking over your shoulder when you're typing in a password, or when you have sensitive information up on your screen and somebody is there and looks over your shoulder and gathers that information. So these are some in-person things to watch out for.

Other tactics

One is quid pro quo. This is something for something: I'll give you something if you give me something back.

There's also impersonating that will happen, whether they impersonate the IT person, or a police officer, or one of the execs. They'll impersonate somebody to leverage a position in order to get something out of somebody.

There's also baiting. Baiting is where there's some sort of false premise. They're creating some sort of false scenario and tricking the person into divulging some sort of information or doing something that they normally wouldn't do.

And then we've talked about dumpster diving: going through the garbage, jumping into the dumpster, looking for sensitive information. Sometimes people will collect paperwork in a box before it goes to get shredded, and that is going to be sensitive information. So they're gaining sensitive information by going through the trash.

There are a lot of techniques that hackers can use to social engineer. They know how people work, how they operate, and they can leverage that. They can leverage these different mechanisms to actually facilitate their own needs. We would like to think that we could rise above this, and we can, through education, but the hackers do this on a daily basis, so they've gotten really good and really convincing at what they do. Some of it just seems really obvious to us. Some of it comes in through our email and seems really obvious and we get rid of it right away. But other stuff can be very tricky, and it's getting more sophisticated. Hackers are getting better and better at what they're doing.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →