What Is Social Engineering?

Social engineering is a method used by criminals to trick people into revealing information or performing actions that help the attacker.

Introduction

Many cyber attacks do not begin with sophisticated hacking tools. Instead, they begin with a simple conversation, email, text message, or phone call.

Social engineering relies on manipulating people rather than attacking computers directly.

Attackers attempt to gain trust and persuade victims to reveal information such as:

  • Passwords
  • Personal information
  • Banking details
  • Security codes
  • Company information

How Does Social Engineering Work?

A typical social engineering attack follows this process:

Attacker Gains Trust > Victim Believes Story > Sensitive Information Shared > Attacker Uses that Information

The attacker often pretends to be someone trustworthy, such as:

  • A bank employee
  • An IT support technician
  • A delivery company
  • A colleague
  • A government organisation

Common Examples

Phishing Emails

An email claims:

Your account has been locked. Click here to verify your details.

The goal is to trick the recipient into revealing login credentials.

Phone Scams

A caller claims to be from:

Microsoft Technical Support

and asks for remote access to your computer.

Text Message Scams

You receive a message saying:

Your parcel is waiting. Please pay £1.99 to arrange delivery.

The link leads to a fraudulent website.

Why Is Social Engineering Effective?

Social engineering exploits natural human behaviour, such as:

✅ Trust

✅ Curiosity

✅ Fear

✅ Urgency

✅ Desire to help

Attackers often create a sense of pressure so that victims act quickly without stopping to think.

How to Protect Yourself

✅ Be cautious of unexpected emails, texts, and phone calls

✅ Verify requests before providing information

✅ Never share passwords

✅ Enable Multi-Factor Authentication (MFA)

✅ Check website addresses carefully

✅ Think before clicking links or opening attachments

Key Takeaway

Social engineering is the practice of manipulating people into revealing information or taking actions that benefit an attacker. While technology plays a role, the primary target is often human trust rather than computer systems. Taking a moment to verify unexpected requests can significantly reduce the risk of becoming a victim.

Scroll to Top