Social engineering: how attackers manipulate people

What is social engineering?
Social engineering is the art of manipulating people into giving away confidential information, granting access, or taking actions that compromise security. Unlike attacks that target software vulnerabilities, social engineering targets human vulnerabilities: our tendency to trust, to help, to obey authority, and to act quickly under pressure. An attacker using these techniques does not need to break a firewall or crack a password. They simply need to convince a person to open the door for them.
The reason social engineering remains so effective is that human behaviour is far harder to patch than a piece of software. You can update your antivirus overnight, but you cannot reprogram instinct. A well-crafted message that appears to come from a trusted colleague or a familiar service can bypass expensive technical defences in seconds. For professionals in France, this matters across every sector, from finance and healthcare to public administration and small businesses, because attackers rarely discriminate by industry.
Understanding social engineering is the first line of defence. It is not about becoming paranoid or distrusting everyone. It is about recognising that manipulation follows predictable patterns, and that once you know those patterns, you become far harder to fool. Awareness turns an ordinary employee into a resilient part of the organisation's security.
The psychological principles attackers exploit
Social engineering works because it targets deeply ingrained mental shortcuts. Attackers study these principles carefully and combine them for maximum effect. Understanding them helps you notice when someone is pulling your strings.
Authority is one of the most powerful. When a message appears to come from a manager, an IT administrator, or a government body, we are inclined to comply without questioning. An email signed by the fictitious head of finance asking for an urgent transfer exploits this instinct.
Urgency and scarcity push us to act before we think. Phrases like 'your account will be suspended in 24 hours' or 'only two seats left' short-circuit careful reasoning. When you feel rushed, you are more likely to skip the verification steps you would normally take.
Reciprocity plays on our desire to return favours. An attacker who offers a small piece of help or a gift may later request something in return, and refusing feels awkward. Social proof convinces us that if others are doing something, it must be safe, which is why fake reviews and forged group emails are effective.
Finally, attackers exploit liking and familiarity. We trust people who seem similar to us or who reference shared details. A caller who mentions a real project or a colleague's name feels legitimate, even when the information was scraped from public sources. Recognising these levers is the foundation of resistance.
Common social engineering tactics and techniques
Social engineering takes many forms, and attackers often blend several techniques in a single campaign. Phishing is the most widespread: fraudulent emails that imitate banks, delivery services, or internal systems, designed to steal credentials or deliver malware. Spear phishing narrows the focus to a specific individual, using personal details to make the message convincing. Whaling targets senior executives, whose access and authority make them especially valuable.
Beyond email, attackers use the telephone in a technique known as vishing, or voice phishing. A caller may pose as technical support, a supplier, or a bank agent to extract information or persuade the victim to install remote-access software. Smishing does the same through SMS messages, often containing a link to a fake login page.
Pretexting involves inventing a plausible scenario, or pretext, to justify a request. An attacker might claim to be conducting a security audit or updating personnel records. Baiting relies on curiosity or greed, such as leaving an infected USB stick labelled 'salaries' in a car park, hoping someone plugs it in.
Tailgating and piggybacking are physical techniques where an attacker follows an authorised person through a secured door, perhaps carrying boxes to invite a helpful colleague to hold it open. Business email compromise combines several methods, taking over or spoofing a real account to redirect payments. Knowing the vocabulary helps you name what you see and respond appropriately.
How to recognise the warning signs of manipulation
Most social engineering attempts share telltale signs, and training yourself to spot them dramatically reduces your risk. The most reliable red flag is a sense of pressure. If a message insists that you act immediately, threatens consequences for delay, or discourages you from checking with anyone else, treat it with suspicion. Legitimate organisations rarely demand instant, secret action.
Unexpected requests are another warning. Be cautious when someone asks for credentials, payment details, or access that falls outside normal procedures, even if they seem to have authority. Requests that bypass established processes, such as a supposed executive asking you to buy gift cards or change bank details for a supplier, deserve extra scrutiny.
Inconsistencies in the details often reveal a fraud. Look at the sender's actual email address rather than the display name, hover over links to see where they truly lead, and note awkward phrasing or generic greetings. A message that mixes a familiar logo with an unusual tone or a slightly wrong domain name is a strong signal.
Emotional manipulation is a further clue. Attackers deliberately provoke fear, excitement, curiosity, or sympathy to cloud judgement. If a communication makes you feel unusually anxious or eager, pause. That emotional spike is exactly what the attacker wants. When something feels off, trust that instinct and verify through an independent channel.
Practical steps to defend yourself and your colleagues
Defence begins with a simple habit: verify before you act. If you receive an unexpected request, confirm it through a separate, trusted channel. Call the person back on a known number rather than the one provided in the message. Never rely on the contact details supplied within a suspicious communication itself.
Slow down when you feel rushed. Attackers depend on speed, so deliberately taking a moment to think is one of your strongest tools. Ask yourself whether the request makes sense, whether it follows normal procedure, and what the consequences would be if it turned out to be fake.
Protect your credentials rigorously. Use strong, unique passwords for each account and enable multi-factor authentication wherever possible, so that a stolen password alone is not enough. Be careful about how much personal and professional information you share publicly, since attackers harvest these details to make their approaches credible.
For physical security, do not hold secure doors open for people you do not recognise, and challenge unfamiliar visitors politely. Never plug in unknown USB devices. When handling payments or sensitive changes, insist on a second layer of verification, such as a callback or dual approval. These practices cost little effort but block the vast majority of attacks, and they protect not only you but everyone who depends on the same systems.
Building a security-aware culture in your team
Individual vigilance matters, but a resilient organisation depends on a shared culture where security is everyone's responsibility. This begins with regular, practical training that goes beyond a once-a-year presentation. Short, frequent sessions that use real examples keep awareness fresh and help people recognise evolving tactics.
Simulated phishing exercises can be valuable when handled well. The goal is education, not punishment. If employees who click on a test message are blamed or shamed, they will hide future mistakes, which is exactly the opposite of what you want. Instead, treat every reported attempt, real or simulated, as a positive contribution and a learning opportunity.
Clear procedures reduce ambiguity. When staff know the correct way to verify a payment request, handle a visitor, or report a suspicious email, they are far less likely to be manipulated into improvising. Make reporting easy and quick, and ensure people know exactly who to contact.
Leadership sets the tone. When managers openly follow security procedures, admit their own near-misses, and thank colleagues for raising concerns, they signal that caution is respected rather than mocked. Over time, this builds an environment where questioning an unusual request is normal and expected. A team that talks openly about threats is far harder for an attacker to divide and deceive.
What to do if you suspect you've been targeted
If you think you have fallen for a social engineering attack, or even that you have narrowly avoided one, act quickly and calmly. Speed limits the damage, and reporting promptly is far more valuable than trying to hide a mistake. Contact your IT or security team immediately and describe exactly what happened, including any links you clicked or information you shared.
If you entered credentials on a suspicious page, change those passwords without delay, and change them anywhere else you may have reused them. Enable multi-factor authentication if it was not already active. If you shared payment details or authorised a transfer, contact your bank at once, as swift action can sometimes halt or reverse a fraudulent transaction.
Preserve the evidence. Do not delete the suspicious email or message, as it can help investigators understand the attack and warn others. Take note of times, phone numbers, and any names used. If the incident involves personal data, your organisation may have legal reporting obligations, and in France serious cyber incidents can be reported to the relevant national authorities.
Finally, share the lesson without embarrassment. Attackers succeed partly because victims stay silent. By speaking up, you protect your colleagues from the same trap and strengthen the whole team's defences. Being targeted does not mean you failed; how you respond is what truly matters.
Example
Common social engineering techniques and how to respond
| Technique | How it works | How to respond |
|---|---|---|
| Phishing | Fraudulent email imitating a trusted source to steal data or deliver malware | Check the sender address, hover over links, verify through a known channel |
| Vishing | Phone call posing as support, bank, or supplier to extract information | Hang up and call back using an official number you trust |
| Pretexting | Invented scenario to justify a request for access or data | Confirm the person's identity and authority before complying |
| Baiting | Infected device or tempting offer left for a curious victim | Never plug in unknown USB devices; report found items |
| Tailgating | Following an authorised person through a secure door | Do not hold doors for strangers; challenge unknown visitors politely |
| Business email compromise | Spoofed or hijacked account redirecting payments | Use dual approval and callback verification for financial changes |
FAQ
Is social engineering only a problem for large companies? No. Attackers target organisations of every size, and small businesses are often seen as easier because they may have fewer formal procedures. Individuals are targeted too, through fake bank messages and delivery scams. Awareness benefits everyone, regardless of the size of the organisation.
How is social engineering different from hacking? Traditional hacking exploits weaknesses in software or systems, while social engineering exploits human psychology. Rather than breaking through technical defences, the attacker persuades a person to grant access or share information. The two are often combined, but social engineering focuses on manipulating people rather than machines.
Can technology alone protect me from social engineering? Technology such as spam filters and multi-factor authentication reduces risk, but it cannot stop every attempt. Because these attacks target human decisions, the person receiving the message is the final line of defence. A combination of good tools and informed, alert people offers the strongest protection.
What should I do if I clicked a suspicious link but entered no information? Report it to your IT or security team promptly so they can check for any hidden risk, such as malware. Avoid entering any details, disconnect if instructed, and keep the message as evidence. Reporting even a minor incident helps protect your colleagues from the same attack.
How can I encourage colleagues to take security seriously without seeming alarmist? Focus on practical, relatable examples rather than fear. Share recent scams, make reporting easy and blame-free, and celebrate people who raise concerns. When security feels like a shared, everyday habit rather than a threat, colleagues are far more willing to stay vigilant and speak up.
Read next
Get structured security awareness guidance for you and your team.