In simple terms — Social engineering means deceiving a person so that they reveal information, grant access, transfer value, or perform another unsafe action. The attacker works on trust and decision-making instead of relying only on a technical flaw.
It is a broad attack category, not the name of one final scam. Phishing can deliver a social-engineering attempt by email, text, call, QR code, or fake page. A romance scam can use the same principle through a much longer relationship. The channel and the intended harm must therefore be described separately.
From a believable pretext to the requested action
An attacker invents a reason for contact and adopts an identity that makes the request plausible: support agent, colleague, authority, broker, friend, or partner. Urgency, fear, scarcity, helpfulness, or familiarity can reduce the time available for checking. The immediate request may concern a password, authentication code, remote-access tool, bank transfer, wallet connection, or digital signature.
The first action may only prepare a later attack. A shared code can enable account takeover; a remote session can expose further systems; a signature can authorise an on-chain operation. This is why recognising the requested action and its consequence is more useful than trying to judge whether the message “looks professional.”
Social engineering and phishing: the difference
Pause without arguing with the sender. Reach the organisation or person through a bookmark, registered number, existing conversation, or other contact found independently. State the exact action requested and ask whether it is necessary. Examine what a link, permission, signature, or transfer would actually authorise before approving it.
Urgency, persuasion, or an unexpected message alone does not prove social engineering. The defining element is deceptive use of trust to obtain information, access, value, or an illegitimate action. Legitimate support may request normal verification, but it should not require passwords, recovery phrases, or authentication codes intended to remain secret.
If an action was completed, use the genuine service to change exposed credentials, close sessions, review permissions, and notify the affected provider. Preserve the message, sender details, domain, requested destination, and transaction records. Technical controls reduce exposure, but a second independent verification path is what directly tests the attacker's pretext.
Sources
- NIST — Social engineering glossary — Defines deception used to obtain sensitive information, unauthorised access, or fraud by gaining confidence and trust.
- ENISA — Threat Landscape: Social Engineering — Defines manipulation of human behaviour and places phishing, pretexting, and baiting among its attack vectors.
- INCIBE — Ingeniería social — Explains trust manipulation used to induce malware execution, disclosure of secrets, or purchases on fraudulent websites.
Related entries
Anti-scam · Phishing · Romance scam · Clone website · Red flags