Skip to content
How‑To Guides

Social Engineering Attacks: How to Spot and Stop Them

Social engineering attacks bypass technical defences by manipulating people. Here is the essential guide to recognising every type and defending against them effectively.

Social Engineering Attacks: How to Spot and Stop Them

The most sophisticated technical defences can be bypassed by a well-crafted phone call, a convincing email, or a plausible pretext that makes a target willingly hand over access or information. Social engineering attacks exploit human psychology rather than technical vulnerabilities — they create false trust, manufactured urgency, or the appearance of legitimate authority to get victims to take actions they would not otherwise take. For a broader walkthrough, our Complete Guide to Online Security and Privacy is a good next read.

Social engineering is the initial access method for the majority of significant security breaches. No technical tool prevents these attacks without the human layer of awareness. Understanding how they work — the research phase that makes them plausible, the pretext that makes them compelling, and the request that makes them profitable — is the core skill that allows you to identify an attack before complying.

The common types — and how they differ

Attack typeChannelKey techniqueRecognition signalDefence
PhishingEmailImpersonation + urgencySender domain mismatch; unexpected action requestCheck sender; verify out of band
Spear-phishingEmailPersonal details + targeted pretextUnusually specific details; unexpected request from “known” personSame as phishing; call to verify
VishingPhoneAuthority + real-time pressureInbound call requesting credentials or actionHang up; call back on official number
SmishingSMSUrgent link; delivery/bank alertsUnexpected SMS with link from unknown numberDon’t click; navigate directly
PretextingAnyFabricated scenario; established trustUnusual request from plausible-sounding sourceVerify identity independently
Quid pro quoPhone/emailOffer of benefit for informationUnsolicited help; too-good-to-be-true offerVerify before accepting any help
BaitingPhysical/digitalCuriosity or desire exploit (USB drop)Found USB drive; free download requiring installNever use unknown USB; verify sources
TailgatingPhysicalSocial pressure to hold doorUnfamiliar person following through secured doorRequire badge; contact security

These attacks work through a limited number of psychological mechanisms regardless of the channel: authority (impersonating a trusted organisation), urgency (creating pressure to act before thinking), fear (threatening negative consequences), curiosity (exploiting desire to know or have something), and reciprocity (offering something to create an obligation). Recognising which lever is being used — and noticing that emotional pressure is rising — is the signal to pause rather than act.

The one-time code attack — the most acute form in 2026

OTP relay attacks deserve specific attention because they’ve become the dominant credential theft technique for high-value account takeovers since 2022 — specifically targeting accounts with 2FA enabled, because the 2FA can be worked around through social engineering if the victim can be manipulated into sharing the code.

The pattern: the attacker has already obtained your password (from a breach database). They call claiming to be from your account provider’s security team, say they noticed suspicious activity, and ask you to “verify” by reading out the authentication code just sent to your phone. That code is your account’s real 2FA code. Reading it out gives the attacker the second factor they need to complete login — in real time while you’re on the phone.

The absolute rule: no legitimate organisation ever needs you to read out a code that was sent to you. Security codes are for you to enter, not to share. An organisation with a genuine need to verify your identity will ask you to take an action through your authenticated app or account — not to read a code to an inbound caller. If someone asks for a code, it’s an attack.

Verification habits — the core defence

The defence against social engineering is not cynicism about every interaction — it’s a specific set of verification habits applied to requests that follow the patterns in the table above. A legitimate bank, government agency, employer, or IT department almost never initiates contact and then immediately requests credentials, payment, or the installation of software.

When any inbound contact — email, phone, or text — includes a request with these characteristics, the correct response is:

  1. Pause. Don’t act while under emotional pressure.
  2. Disengage from the initial channel. End the call, close the email.
  3. Verify through an independently-sourced contact method. Look up the bank’s official number from the back of your card or the organisation’s official website — not from the contact you received.
  4. Make contact through that verified channel and ask whether the alleged situation is real.

If there’s a genuine fraud alert on your account, you’ll learn that through the verified channel. If there isn’t, you’ve confirmed the social engineering attack and protected yourself. This out-of-band verification approach applies across every channel and every claimed source — it’s always the correct response to any unexpected request for sensitive information or action.

Recognising specific techniques

Vishing (voice calls): the caller claims authority (bank fraud department, IRS, Microsoft support), creates urgency (“your account is being drained right now”), and requests immediate action (verify your PIN, pay via gift card, download remote support software). Phone callers are harder to verify than email senders, and people are less suspicious during real-time conversation. The correct response to any inbound call requesting credentials or payment: hang up and call back on the official number. No legitimate authority requires you to stay on the line to validate an urgent action.

Pretexting: a fabricated scenario provides context that makes the manipulation feel like routine business interaction. A “new employee” who needs help accessing a system, a “vendor” calling about an invoice discrepancy, a “partner” requesting a change to payment details — all are pretexting attacks. They’re the technique most commonly used in business email compromise (BEC) that costs organisations billions annually. The defence is independent verification of the scenario before taking any action, through a channel you established — not one the caller or email provides.

Baiting: found USB drives in car parks or conference venues, free software downloads requiring administrator installation, prize claims requiring a credential. The psychological lever is curiosity or desire. The rule: never plug in an unknown USB drive on a connected machine (use an isolated, non-networked machine if you genuinely need to check the contents, or don’t check at all). Free downloads from unofficial sources that require escalated permissions should be treated as malware delivery attempts.

Social engineering at work — the organisational dimension

Organisations face these attacks at scale and with higher potential consequences. BEC fraud — fraudulent emails impersonating executives or finance departments to authorise wire transfers or change payment details — requires no malware and succeeds entirely through deception of legitimate employees.

Procedural controls are more reliable than employee recognition for BEC defence:

  • Phone verification requirement for all wire transfers above a threshold — using an existing established contact number, not one provided in the requesting email
  • Payment detail changes require confirmation through an established contact — any email requesting change to supplier bank details should be verified by calling the supplier on a number from your existing records
  • “No action on CEO/executive request without verification” policy for finance teams — the finance team shouldn’t need to recognise sophisticated impersonation; the process should require verification regardless of who appears to be asking

Security awareness training with simulated attacks (phishing simulations, pretexting exercises, vishing tests) is more effective than classroom descriptions of what attacks look like. Employees who receive immediate feedback after nearly falling for a simulation retain recognition skills significantly longer than those who only read about the attacks. Our guide on avoiding phishing scams covers the specific email-channel social engineering attacks in detail. For APWG statistics on current phishing volumes and OTP relay attack prevalence, the Anti-Phishing Working Group’s quarterly reports provide current data.

AI-generated deepfakes — the emerging frontier

Deepfake audio and video — synthetic media that realistically replicates a person’s voice or appearance — are being used in attacks that previously required a convincing human impersonator. A video call where the “CEO” requests an emergency wire transfer, a voice message that sounds exactly like a family member describing an emergency, or an audio clip used to clone someone’s voice for vishing calls are all emerging social engineering attacks enabled by AI generation tools that are increasingly accessible and inexpensive.

The human recognition capacity that is reliable against traditional social engineering — recognising a voice, identifying a face — becomes unreliable against deepfake attacks. This makes procedural verification habits more important, not less. The fact that a voice sounds familiar or a face looks real does not substitute for verified contact through an independently-sourced channel.

The defence: establish a family safe word — a private code known only within the family that confirms identity in emergency communication scenarios. The “grandparent scam” (attacker calls claiming to be a grandchild in emergency need of money) exploits family trust and urgency. A pre-established code word that the genuine grandchild would know allows immediate verification without requiring a judgment call under emotional pressure. The same principle applies in professional contexts: a pre-established verification protocol that doesn’t rely on voice or face recognition is the defence that works regardless of how convincing the synthetic media is.

Long-term resilience — the principle that works against all variants

Social engineering attack techniques evolve rapidly — new pretexts, new channels, new AI tools making impersonation more convincing. The specific techniques in the table above will be supplemented by new variants that don’t exist yet.

But the underlying structure doesn’t change: an attacker tries to create false trust and pressure to extract an action or information from a target. The consistent defence addresses the mechanism rather than the specific presentation:

Requests that create pressure to act quickly, from sources you cannot independently verify, asking for sensitive information or unusual actions, should be treated as potential social engineering until proven otherwise through out-of-band verification.

This single discipline protects against every variant — present and future — because it targets the attack mechanism rather than the specific delivery method. Reducing publicly available personal information (limiting what attackers can use to build credible pretexts) is the complementary long-term measure. The data minimisation practices in our guide on reducing your digital footprint directly reduce the material available for attackers to build convincing personalised pretexts.

Self-assessment — how vulnerable are you right now?

A few questions that reveal current exposure to social engineering attacks:

  • If your bank called right now and said your account was being drained, what would you do? If the answer includes anything other than “hang up and call the number on my card,” that’s the vulnerability the vishing attack exploits.
  • If a vendor emailed requesting a change to their payment bank details, what’s your process? If the answer is “approve based on the email,” that’s the BEC vulnerability. The correct process: call the vendor on a number from your existing records, not from the email.
  • Is there a family code word for emergency contact verification? If not: the grandparent scam and its variants have a clear path to work.
  • Would you share a one-time code with a caller from “your bank’s security team”? If there’s any uncertainty: the OTP relay attack is viable. The answer is always no.

These questions identify specific verification habits that need to be built — not through training that describes the attacks abstractly, but through deliberate practice of the correct response before the attack arrives. Deciding in advance what you will do in each scenario removes the decision from the pressure of the moment, where the social engineering attack is most effective.

Physical social engineering — often overlooked

Most security awareness focuses on digital channels. Physical social engineering is less discussed but equally effective:

  • Tailgating through secured doors: following an authorised person through a badge-access door by being close behind them, exploiting the social awkwardness of stopping someone or letting a door close in their face. The defence: politely ask unfamiliar people for their badge, or direct them to reception. The social discomfort of asking is smaller than the security consequence of not asking.
  • Shoulder surfing: observing someone’s screen, PIN entry, or keyboard in public. Most effective in crowded transit, airports, and open-plan offices. Shield the screen when entering PINs or passwords in public spaces; use privacy screen filters on laptops used in public.
  • Impersonation of maintenance or delivery personnel: an attacker in a plausible uniform claiming to need access to a server room, network closet, or private office. The defence: require photo ID and call the requesting department through your internal directory to verify the visit was expected.
  • Dumpster diving: retrieving discarded documents containing personal information, account numbers, or organisational details. Shred all documents containing names, addresses, account numbers, or any identifying information before disposal.

Physical social engineering is less glamorised in security discussions than cyber attacks, but it provides the same access outcomes with often less detection risk. The same awareness that protects against digital manipulation applies here: unusual requests that create pressure, unfamiliar people claiming authority, situations that don’t quite match expected procedures — all warrant the same pause-and-verify response that protects against digital social engineering.

Social engineering attacks are ultimately about the gap between the effort of critical thinking in the moment and the effort of exploitation by an attacker who has prepared. Building the habits that make verification automatic — pausing, disengaging, verifying independently — closes that gap regardless of how technically sophisticated or personally targeted the attack becomes. If this sounds familiar, Protect Your Online Identity is worth a look.

Nikolas Lamprou

Nikolas Lamprou (MSc; GCFR, SC-200, Security+) has been working with computers professionally since 2009 — starting with web development and e-commerce, and moving into cybersecurity over the years. Based in Greece, he brings over 15 years of real-world IT experience to SolveTechToday, where he writes about Windows fixes, software reviews, security tools, and AI applications. His goal is straightforward: cut through the noise and give readers clear, honest guidance on the tech decisions that matter.

Stay Ahead

Fix your next problem before it starts

Get the week's best Windows fixes, software picks, and security guides delivered straight to your inbox. No noise, just solutions.

Press ESC to close · Try "Windows 11" or "Chrome"