
What Is a Social Engineering Attack? Types & Examples
You can have the most sophisticated firewall money can buy, and a determined attacker might never need to touch it. Instead, they might just call your receptionist, sound like they belong there, and ask for the password everyone writes on sticky notes. That’s the essence of a social engineering attack — and the reason these psychological tricks account for a huge slice of real-world breaches.
Core Tactic: Psychological manipulation · Common Goal: Confidential information access · Key Examples: Phishing, pretexting · Reported Types: Up to 8 per Arctic Wolf · Top Focus: Human trust exploitation
Quick snapshot
- Exploits trust, not software flaws (CrowdStrike)
- Phishing dominates as most common method (Okta)
- Exact count varies by source (8–15+ reported types)
- Precise global financial impact hard to pin down
- Incidents traced back to at least 2013 (Target breach)
- Scale and financial damage escalating year over year
- MFA fatigue and AI-generated phishing on the rise
- Prevention increasingly blends training + technical controls
The key facts table below summarizes definitions, attributes, and their authoritative sources.
| Attribute | Detail | Source |
|---|---|---|
| Definition Source | Manipulating people for credentials or access | Wiz |
| Key Trait | Not technical — psychological (CrowdStrike) | Psychological manipulation |
| Types Count | Up to 8 distinct types reported | Arctic Wolf |
| Goal | Sensitive data access, financial transfer, or system entry | Gatefy |
| Most Common Method | Phishing across email, SMS, voice channels | CrowdStrike |
| December 2021 Phishing Reports | Over 300,000 reported attacks in single month | Okta |
What is a social engineering attack?
A social engineering attack bypasses the technical lock on your system by targeting the human lock instead. Rather than hacking software, attackers manipulate people into handing over passwords, granting access, or transferring money — exploiting trust, urgency, and authority.
Core definition from Cisco
CrowdStrike describes social engineering as any attack that “relies on human interaction” to trick someone into making security mistakes or giving up sensitive information. The attack itself isn’t cyber in the way we usually mean — it’s a con that works because people want to be helpful and avoid appearing suspicious.
Distinction from cyber attacks
Traditional cyber attacks exploit software vulnerabilities — a flaw in code that lets an intruder slip through. Social engineering sidesteps the code entirely. Wiz notes that attackers using these methods “persuade users to give up confidential information” through conversation and deception, not zero-day exploits.
Psychological basis per IBM
IBM’s security team frames it as manipulation of human nature. People follow mental shortcuts — deferring to authority, responding to urgency, reciprocating favors. A skilled attacker knows which shortcuts to press and when. SentinelOne adds that these attacks often succeed even against users who know better, because the manipulation targets emotion, not logic.
The implication: technical defenses alone cannot stop an attacker who convinces an employee to hand over the keys willingly.
What is an example of social engineering attacks?
Real cases show how these attacks play out at scale. From vendor phishing to CEO impersonation, the methods are varied but the pattern is consistent: someone gets duped, and the organization pays.
Real life examples
In 2013, attackers sent a phishing email to an HVAC vendor working with Target. One employee clicked, and the attackers walked into Target’s network, ultimately exposing 40 million credit and debit card numbers (Computer Security Blog). The hack that made headlines started with a social engineering email, not a zero-day exploit.
Google and Facebook lost $100 million between 2013 and 2015 when Evaldas Rimasauskas posed as Quanta Computer, a legitimate supplier, and submitted forged invoices. Both tech giants paid without question. The Computer Security Blog notes the attackers used “no malware, no exploits, just forged invoices and letterheads that looked legitimate.”
Top 5 attacks
- Target breach — 40 million cards via vendor phishing (2013)
- Google/Facebook BEC — $100 million via forged invoices (2013–2015)
- Twitter phone spear phishing — high-profile account hijacks, $100,000+ Bitcoin (July 2020)
- MGM Resorts help desk call — $100 million ransomware via social engineering (September 2023)
- Barbara Corcoran phishing — $400,000 lost to invoice fraud (2020)
The pattern: each incident succeeded not through technical brilliance but through human manipulation, proving that the path of least resistance often runs through a person.
2025 predictions
Security firms anticipate increased use of AI-generated phishing messages that read naturally and bypass traditional detection. MFA fatigue attacks — flooding victims with push notifications until they approve one out of frustration — also saw notable growth after the Uber breach in 2022.
Over 300,000 phishing attacks were reported in December 2021 alone, according to Okta, and the financial toll of high-profile cases ranges from hundreds of thousands to over $100 million per incident. The pattern is clear: social engineering pays.
Organizations with strong technical defenses still fall victim because the attack targets employees, not infrastructure. A sophisticated firewall won’t stop a convincing email from your “CEO” asking for an urgent wire transfer.
What are types of social engineering?
CrowdStrike catalogs at least eight distinct types, with some sources listing more. The common thread: each method exploits a different human instinct or social norm.
Four main types
- Phishing — Spoofed emails or messages to elicit sensitive information. Includes sub-types: spear phishing (targeted individuals), whaling (executives), and smishing (SMS-based).
- Vishing — Voice-based attacks where attackers call pretending to be authority figures, tech support, or trusted vendors.
- Pretexting — Fabricating a scenario (often involving a made-up identity or story) to extract privileged information.
- Baiting — Leaving infected USB drives or downloads in places where targets will use them, exploiting curiosity.
Three common types
- BEC (Business Email Compromise) — Poses as executives to request wire transfers or sensitive data. Google’s $100 million loss exemplifies the stakes.
- Smishing — SMS phishing using text messages with malicious links or urgent requests.
- Quid pro quo — Offers something desirable (a software upgrade, gift card) in exchange for login credentials or access.
Eight types overview
- Tailgating — Following authorized personnel into restricted physical areas.
- Honeytrap — Creating fake romantic or social personas to extract money or information from targets.
- Scareware — Frightening users into downloading malicious software with fake warnings or alerts.
- Watering hole attacks — Compromising websites frequented by a target group, waiting for victims to visit.
- Diversion theft — Redirecting deliveries or information through social manipulation.
- Spoofing — Disguising attacker identity in emails, SMS, or websites to appear legitimate (Arctic Wolf).
- Consent phishing — Tricking users into granting permissions to malicious cloud applications (Wiz).
- MFA fatigue — Bombarding victims with push notifications until they approve access out of frustration (Computer Security Blog).
What this means: no matter which variant, the attacker’s success depends on finding someone willing to bend the rules — not on finding a software flaw.
What are the most common signs of social engineering attack?
Detecting an attack in progress comes down to recognizing behavioral and communication patterns. CrowdStrike and SentinelOne both emphasize training employees to spot the red flags before any damage occurs.
Behavioral red flags
- Unsolicited requests for passwords, access codes, or financial information
- Pressure to bypass normal verification procedures
- Requests made outside of normal business channels or hierarchies
- Anyone asking for information they should already have
Communication cues
- Email addresses, domains, or phone numbers that look slightly off (typosquatting, lookalike domains)
- Generic greetings (“Dear Customer”) instead of your actual name
- Unexpected attachments or links, especially from unknown senders
- Urgent language demanding immediate action
Urgency pressure
Copado notes that attackers frequently create artificial urgency — a looming deadline, a threatened account suspension, an “emergency” requiring immediate wire transfer. The goal is to prevent the target from taking time to verify through proper channels. SentinelOne recommends that any unusual request involving urgency should trigger a verification step through an independent channel.
The implication: urgency is the attacker’s shortcut around your verification process — recognizing it as a red flag, not a reason to act faster, is what stops the attack.
How to prevent social engineering attacks?
Prevention requires both human awareness and technical controls working together. CrowdStrike, Wiz, and SentinelOne all emphasize that neither layer alone is sufficient.
Training steps
- Conduct regular phishing simulation exercises to test employee responses
- Teach recognition of spoofed emails, urgent requests, and authority impersonation
- Establish clear escalation procedures when suspicious contact occurs
- Make reporting easy and reward employees who flag attempts
Technical measures
- Deploy multi-factor authentication (MFA), preferably phishing-resistant FIDO2 hardware keys or passkeys
- Install spam filters, pop-up blockers, and endpoint detection and response (EDR) tools
- Use SIEM tools to monitor for unusual network activity patterns
- Implement email authentication protocols (SPF, DKIM, DMARC) to reduce spoofing
Verification protocols
- Verify identities through alternate, independent channels before sharing sensitive information
- Require multi-person approval for wire transfers above certain thresholds
- Establish out-of-band verification for executive requests (call back on known numbers)
- Cross-check supplier requests against known contact records before processing changes
Prevention fails when organizations treat it as a training problem or a technical problem alone. SentinelOne notes that effective programs combine human awareness training with automated technical controls — the human firewall and the software firewall working in tandem.
AI-generated phishing messages are becoming harder to distinguish from legitimate communications. Organizations should prepare by deploying phishing-resistant MFA now, before these attacks become the norm.
The pattern: organizations that treat prevention as purely a technical problem still get breached through employees, while those that rely only on training still lack the automated guardrails that stop determined attackers.
Confirmed vs Uncertain
Confirmed facts
- Social engineering exploits human psychology, not software
- Phishing is the most common attack method
- Incidents like Target (2013), Uber (2022), MGM (2023) are documented and verified
- MFA fatigue exploits push notification frustration
- Training combined with technical controls outperforms either alone
What remains unclear
- Total global financial impact — figures vary by source
- Exact type taxonomy — sources list 8 to 15+ variants
- Quantitative success rates of specific prevention measures
- Prevalence of AI-generated phishing in 2024–2025
Expert perspectives
“This technique — called MFA fatigue — exploits the frustration people feel when their phone won’t stop buzzing.”
— Computer Security Blog (analysis of the Uber 2022 breach)
“Social engineering doesn’t always target your employees directly — sometimes it targets the people who have access to your systems.”
— Computer Security Blog (supply chain attack analysis)
The pattern across a decade of incidents is straightforward: attackers find the path of least resistance, and for most organizations, that path runs through a human being. Technical defenses matter, but they don’t answer the phone when a convincing caller asks for a password reset. For security teams, the implication is clear: invest in the human layer with the same rigor applied to software patches, or accept that a determined attacker will find someone who’ll say yes.
Related reading: How to Trade Safely in Roblox · RBC WestJet Mastercard Login Guide
livingsecurity.com, terranovasecurity.com, masterconcept.ai, sentinelone.com
Among the most common social engineering tactics, phishing relies on deceptive phishing links hidden in emails that mimic trusted sources to steal sensitive data.
Frequently asked questions
What best describes a social engineering attack?
A social engineering attack is a method of gaining access to systems or information by manipulating human psychology rather than exploiting technical vulnerabilities. Attackers rely on trust, authority, urgency, or reciprocity to convince targets to hand over credentials, grant access, or transfer funds.
Which of the following is a social engineering attack method?
Phishing, pretexting, baiting, vishing, smishing, BEC, tailgating, MFA fatigue, and honeytrap are all recognized social engineering attack methods. Each exploits a different human instinct or social norm to achieve unauthorized access or information disclosure.
What is a real life example of social engineering?
The Target breach in 2013 began with a phishing email to an HVAC vendor, exposing 40 million payment cards. Google and Facebook lost $100 million to BEC when Evaldas Rimasauskas posed as their supplier. MGM Resorts paid $100 million in ransomware after attackers used a help desk call to gain entry.
How are social engineering attacks carried out?
Attackers research their targets to build convincing pretexts, then initiate contact via email, phone, SMS, or in person. They exploit psychological triggers like urgency and authority to persuade the target to bypass normal procedures. The attack succeeds when the target acts without independent verification.
What is the social engineering attack cycle?
The cycle typically includes: (1) information gathering via reconnaissance, (2) rapport building or pretext creation, (3) the exploit attempt — making the request for access or information, and (4) disconnection and execution. The target may not realize what happened until damage is already done.