Skip to main content
FixMyTech

What Is Social Engineering and How to Spot It

By

Published

8 min read

Share

Short answer

Social engineering is manipulating a person into giving up access, rather than breaking into a system. Nearly every version uses the same levers: authority, urgency, fear and helpfulness. The defence is procedural rather than clever — verify any unexpected request through a channel you chose yourself, and never read out a code someone sent you.

On this page

Social engineering is the practice of getting a person to do something they should not, instead of getting a computer to. No encryption is broken. No software flaw is exploited. Someone is simply persuaded to open the door, and then the attacker walks through it with valid credentials.

It is worth understanding as a separate category because the usual defences do not apply. Antivirus cannot catch a phone call. A password manager cannot stop you reading your password aloud. The decision point is a human one, which means the defence has to be a habit rather than a product.

The four levers, and why they are always the same

Pretexts vary endlessly — the bank, the courier, the IT desk, the recruiter, the HMRC letter, the new chief executive emailing from a personal address. The psychological machinery underneath barely changes at all.

Authority. The request comes from someone whose instructions you do not normally question. Your bank, your employer, the police, a senior manager. The instinct to comply with authority is socially useful and that is precisely why it is targeted.

Urgency. A deadline removes the time in which you would have checked. Your account will be suspended in twenty-four hours. The payment must go today. The courier is waiting.

Fear. A consequence you want to avoid. An unauthorised transaction, a legal problem, a tax penalty, data loss. Fear narrows attention to the threat and away from the mechanics of the request.

Helpfulness. The most underrated one, because it feels good. Someone is struggling, locked out, new to the job, standing at a door with their arms full. Most people want to help, and most workplaces reward it.

A message or call that combines two or more of these and ends with a single specific action is the pattern. The branding is irrelevant.

The forms it actually takes

Form Delivery What they want
Phishing Email or message Credentials, card details
Vishing Phone call Codes, remote access, transfers
Pretexting Any channel Information to build a better attack
Baiting A free or urgent offer An install, or a payment
Tailgating In person Physical access to a building

Vishing — a phone call — is the one that catches people who are careful about email. A call seems more real than a message, caller ID is easy to falsify, and the attacker can improvise around your objections in real time. The bank fraud call is the classic: someone claims your account is compromised, builds alarm, and either asks for codes or talks you into moving money “to a safe account”. No bank has ever needed you to move money to a safe account. That phrase alone is enough to end the call.

Pretexting is the quiet one. A short call asking which payroll system you use, or who handles invoices, or when the office is closed. No request for anything secret, so nothing triggers suspicion. The information feeds the real attempt two weeks later, which arrives knowing exactly the right names and the right process.

Baiting includes the fake virus warning on a web page, the prize notification, the unexpected refund. All of them trade a reward or a scare for an install or a payment. The pop-up version is covered in how the fake virus warning scam works, which is worth reading because the telephone follow-up is where the real damage happens.

The tells that survive a good pretext

Sophisticated attempts will pass most surface checks. These hold up better.

The channel is unusual for the request. A bank that normally messages you in its app suddenly calling your mobile. A manager who always uses the work system sending a personal-looking email. The switch of channel is often the only irregularity, because the attacker cannot access the normal one.

You are discouraged from hanging up or checking. “Stay on the line while I transfer you.” “Do not discuss this with anyone, it is a confidential investigation.” “There is no time to call back.” A legitimate organisation is entirely comfortable with you ringing them back on a published number. An attacker cannot be, because the pretext dies the moment you do.

A code or password is requested. This is the clearest rule available. No bank, no help desk, no platform support team ever needs a one-time code or your password. If you remember one line from any of this, make it that one.

Remote access is requested. “Let me connect to your computer to show you the problem.” Occasionally legitimate when you initiated the contact with a company you chose. Never legitimate when they called you.

The payment method is unusual. Gift cards, cryptocurrency, bank transfer to a new account, a payment app to a person rather than a business. These are chosen because they are irreversible. No government department, utility or retailer asks for gift cards, under any circumstances.

The one rule that works

Everything above compresses into a single habit: for any unexpected request involving money, credentials or access, verify through a channel you chose yourself.

Hang up and ring the number printed on your bank card, not the one you were given. Open the app you already have rather than the link you were sent. Walk to the colleague’s desk, or ring their internal number from the directory. Message the supplier on the thread that existed before today.

The reason this works where pattern-spotting fails is that it does not require you to be right about whether the approach was genuine. A real request survives verification without difficulty. A fake one does not survive it at all. You stop having to judge, which is the point, because judgement is exactly what the urgency was designed to degrade.

One operational detail: when you hang up on a suspicious call, use a different phone or wait a couple of minutes before dialling. Call-retention tricks on landlines are much rarer than they once were, but it costs nothing to avoid.

Reducing what they have to work with

Social engineering is more convincing when the attacker already knows things about you. Some of that is unavoidable, some is not.

  • Check whether your details are already circulating. Finding out whether your email was in a data breach tells you what a stranger can trivially look up about you.
  • Be careful with security questions. Mother’s maiden name, first school and first pet are often discoverable from social media. Answering them with invented strings stored in a password manager removes the problem entirely.
  • Think about what your public profiles reveal. Employer, job title, manager, travel dates. None of it is secret, and all of it makes a pretext stronger.
  • Use two-factor authentication, understanding that it narrows the attack rather than ending it. A code sent to you is only dangerous if you give it away, which is why the request for a code is now the centrepiece of so many calls. Passkeys sidestep this because there is no code to repeat.

Realistic expectations

You will not spot every attempt, and anyone who tells you otherwise is selling training. Attempts aimed at a specific person, using real details, delivered at a moment when you are distracted, are convincing by design.

What you can do is make the verification habit automatic for the narrow set of requests that matter: money, credentials, codes, access. That is perhaps a dozen situations a year for most people, and a ninety-second check in each one. It is a small, dull discipline, and it removes nearly all of the risk that recognition alone never could.

Frequently asked questions

Is social engineering the same as phishing?
Phishing is one form of social engineering, delivered by message. The broader category includes phone calls, in-person approaches and impersonating colleagues, all using the same psychological levers.
Why do intelligent people fall for this?
Because it does not target intelligence. It targets attention, time pressure and the social instinct to be helpful, all of which work against you hardest when you are busy. Being told you are too clever for it is itself a risk factor.
Can social engineering work over the phone if my number is private?
Yes. Phone numbers are widely available from data breaches and marketing lists, and caller ID is simple to falsify, so a call that appears to come from your bank's published number proves nothing about who is calling.
What information is safe to confirm to a caller?
Nothing that identifies you to them, because a genuine organisation already knows it and an impostor is trying to collect it. Confirming your date of birth or address to someone who called you is how a thin profile becomes a convincing one.
How do attackers know so much about me already?
Breached databases, social media, company websites, and public records combine easily. Knowing your employer, your manager's name and your recent holiday is not evidence of legitimacy — it is a few minutes of research.

All Security guides