Social engineering is the manipulation of a person, rather than a system, to obtain information or provoke an action that serves the attacker. This coverage defines social engineering and walks through the methods of contact, the tactics, and the forms of false information a threat agent uses.
Social Engineering Techniques
No one really wants to be controlled or manipulated, but there are some threat agents out there that become masters at it. We call that social engineering. They're able to social engineer, or trick, people into getting what they want.
We'll start out by defining what social engineering is, then we're going to get into some methods of contact that a threat agent will use, to include phishing, in person, and no contact. Then we're going to get into some tactics that they'll use, and then we'll wrap things up by talking about false information.
Your brain is really quite amazing. Have you noticed there's some activities that you can do without ever thinking about it, that you've done them enough that your brain has logged it as a routine and you don't have to consciously focus on it? A sort of autopilot that your brain has. Well, that resides as a function of your brain so you don't have to think about every single activity you do, and some of those functions you're actually born with and your brain just naturally does. But the problem is that there are some people out there that know how to leverage these functions for their own gain.
That's what social engineering is. Social engineering is when somebody manipulates or controls somebody else using these built-in functions, or using some form of manipulation, for their own purpose, for getting some sort of information from them, or other fraudulent purposes.
A threat agent is going to start out by making a connection with somebody. Perhaps it's through messaging like email, maybe it's that they've given them a phone call, perhaps it's in person, or there are even methods where they don't even have to reach out to the person and they can actually leverage the person for their own gains.
One of the ways that a threat agent will do this is through the use of phishing. Phishing is when a threat agent sends an email or other type of message with the intention of getting some sort of information out of you. Perhaps it's maybe like user credentials or some other sensitive piece of information.
Phishing can actually go by many different names depending on who's being targeted, how they're being targeted, and what kind of information is trying to be extracted. An example of this is spear phishing. Spear phishing is a targeted attack against an individual or an organization. Whaling is a type of spear phishing when it targets somebody big in the company, like a CEO, somebody that's higher up in the ranks.
If phishing is happening through email we call that phishing; if it's happening through text messages we call it smishing; if it's happening over a phone call we call it vishing; or there's also instant messaging, so there is a threat through instant messaging as well. And a term you might see out there is message-based, which just means it's happening through text, whether it's phishing, smishing, or instant messaging.
If a threat agent is sending a phishing email to somebody at a company pretending to be somebody else at the company, we call that a business email compromise, or BEC. As already mentioned, if there's phishing happening through text messages we call that smishing, and I wanted to point out the reason why there's an S at the beginning: because texting uses a protocol called short message service, so SMS. That's why smishing.
Phishing is not the only social engineering technique out there, though. For instance, you've got several in-person tactics that they'll use as well. A couple of examples of in-person would be tailgating and shoulder surfing.
Shoulder surfing is when somebody's looking over your shoulder to gather information. Perhaps it's when you're typing in your credentials and they see what your password is. So that's an example of shoulder surfing.
Tailgating is when somebody walks in behind you, like into a building or a closed-off area. A good example of this: I worked on the second floor of a building one time, and there was somebody, one of the employees, who was in the elevator with somebody else. When the employee got off, they turned the corner, and as the doors were shutting the other person stuck their hand out, the doors opened back up, and now he had access to the second floor and stole some equipment. So that's an example of tailgating.
There are no-contact methods of social engineering as well. Baiting is an example of that. Baiting happens when you entice somebody to take some sort of bait. A good example of this is, let's say I want to trick people into installing a virus on their computer. I could put a virus on a thumb drive, put it around the office, and somebody would come along and say, oh, I wonder what that's for, or who that's for, what am I going to do with this? Well, I'll plug it into my machine to see what's on it, to see if I can give it to the proper person or throw it away. They plug it into their machine and then the virus gets installed on that machine.
Another example is dumpster diving. There are a lot of threat agents that will go through trash, go through the dumpster, go through the recycle bin to see if they can find sensitive information. It's a great source to get the initial information to leverage a network and get into a network.
There's also the watering hole. If I wanted to target a specific business, what I could do is see where that business went and browsed on the web, what pages they would go to, what sites they would go to, and then whatever site they would go to I would go and infect that site, hoping that somebody from that company would then go to that site, get the virus, and then I would have access to inside that network.
There are other tactics that threat agents will use as well. One of them is impersonation. You automatically trust certain people, certain people that you've already interacted with. Maybe it's a person of authority, maybe it's some sort of department that you trust like the IT department, and so you already have this trust built up. Well, somebody might impersonate one of those people to leverage that position to get you to do something. That's impersonation.
Quid pro quo is something for something. The idea is, I'll give you this if you give me that. I'll give you some money if you give me some information.
Then there's blackmail. That's, I have a piece of information that's against you, I'm going to release it unless you tell me some sort of information that I'm trying to gather. So that would be blackmail.
And then a lot of what they try to do is evoke some sort of emotion, like maybe it's curiosity, or maybe they're trying to create some sort of fear, or create some sort of urgency for you to do something quickly. So they'll try to evoke some sort of emotion to get you to react and fall for their social engineering tactics.
There are several different types of impersonation. We already mentioned the business email compromise. There's brand impersonation. That's where they pretend to be somebody from a name brand or a brand that you know, so they're just imitating some sort of brand that's out there.
There's also this thing called typo squatting. Typo squatting is the idea that they see some big website out there and they go and buy a domain that's very similar but just maybe has something that would be a common typo in it, and then you would type in that URL and be taken to the wrong site. I know somebody close to me that actually fell for one of those sites. They thought they were going to a Microsoft site but ended up going to a different site. So that would be an example of typo squatting.
Pretexting is when a threat agent will use some sort of fabricated story to extract information or get what they want out of you. The idea behind pretexting is they're probably going to try to evoke some sort of emotion out of you, or something that's compelling from their story, to get you to act and do what they want you to do.
Then there's a lot of false information out there on the internet. Some of it's just misinformation, which means that it's wrong information but whoever created the information didn't intend it to be wrong, they were just inaccurate in the way they reported things.
Then there's disinformation. Disinformation is where somebody has actively put out false information on purpose.
And then deep fake is when there is some sort of voice or video alteration so it looks like one person, maybe a famous person, is saying something that they never said. They're using some voice modulation and some software to be able to trick other people into thinking that this person said stuff or did stuff that they didn't really do.
Social engineering is a huge problem out there, and there are companies out there that have mastered this. That's right, companies. There are businesses that are conducting cyber crime that are scamming people out of their life savings. There are millions of people that get hit every single year with this. It's a huge problem, but we're overcoming it because we're educating people, and so that's really what we want to do: educate our users on what are the tactics that a threat agent would use out there to scam them out of money or to take something away from the business.
So we talked about methods of contact, whether it's phishing, in person, or those no-contact methods; we talked about some of the tactics that they would use; and then what false information is out there.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →