Social Engineering Attacks: Types, Examples and Prevention

social engineering attacks

In short: Social engineering attacks use a false or misleading identity, story or context to influence a person’s actions. Recognising these tactics can help employees pause and verify unusual requests before acting. Attackers may try to obtain information or money, gain access, persuade someone to install software or bypass a normal process. A practical response is to pause, independently verify the identity and request through a trusted route, follow the approved process and report concerns.

Employees can recognise possible social engineering by checking whether the claimed identity, reason for contact and requested action fit normal workplace processes. Employees and managers can apply the same check across email, text, voice, messaging apps and face-to-face contact.

Phishing is a common form of social engineering in which attackers use fraudulent messages to prompt unsafe actions.

Organisations can reduce social engineering risk by linking employee awareness to trusted verification routes, clear reporting processes and controls around high-impact actions.

How Do Social Engineering Attacks Work

Many social engineering attempts follow a recognisable sequence. An attacker adopts a credible identity or story, makes the contact feel relevant and asks the target to take a particular action.

Pressure, authority, secrecy, curiosity or familiarity may then make a normal check feel unnecessary, awkward or too slow. The request may be direct, but some approaches begin with harmless-looking questions and build trust over time. The NPSA describes both short approaches and longer relationships used to obtain information or access (NPSA, 2015).

The method used to influence someone is separate from the attacker’s objective. One attacker may want a password or account code. Another may seek payment, sensitive information, system access, physical entry or permission to work outside an established process.

Public information about roles, suppliers, projects or colleagues can make the story sound routine. Information from a compromised account can make it sound even more convincing. Plausibility does not establish that the person has authority for the requested action.

Social engineering can exploit normal workplace behaviour. Workplace norms often encourage employees to respond promptly, solve problems and respect legitimate authority. Attackers may exploit those behaviours when employees are under time pressure.

AI can help threat actors carry out existing social engineering tactics more efficiently, but employees should still verify the claimed identity, context and requested action. The identity, context and requested action still need an independent check (NCSC, 2025a).

What Are the Main Types of Social Engineering

Social engineering can be classified by contact route, attacker method or objective, and several types may be combined in the same attempt. In the UK Government’s 2025/26 Cyber Security Breaches Survey, 38% of businesses said they had identified phishing breaches or attacks and 12% reported impersonation breaches or attacks in the previous 12 months. Those figures describe two reported categories, not social engineering as a whole (DSIT and Home Office, 2026).

Type How It Reaches the Target What the Attacker Tries to Achieve
Phishing A deceptive email presents a familiar organisation, colleague or work task. Prompt the target to log in, disclose information, download a file, make a payment or take another action.
Smishing A text message creates a reason to reply, open a link or take another action. Obtain information or account access, or prompt the target to take another action through a mobile channel.
Vishing A voice call uses conversation, authority or rapport to build trust. Persuade the target to share information or codes, grant access or agree to a request before verifying the caller's claim.
Pretexting and Impersonation An attacker uses email, calls, messaging, social contact or an in-person approach to present a plausible false role. Impersonate a colleague, supplier, IT worker, visitor or service provider to gain trust, access or information.
Relationship-Building and Elicitation A professional or social contact asks small questions or favours over time. Collect separate details, build a fuller picture or gradually gain access to more sensitive information.
Business Email Compromise and Payment Diversion A message from a spoofed or compromised business account makes a false executive, supplier or payment request appear credible. Redirect a payment, change account details or obtain sensitive business information.

Social engineering categories overlap. A payment diversion attempt may begin with phishing, continue through a compromised account and rely on impersonation. Pretexting can support a phone call, a visitor request or gradual information gathering. Naming the approach can help employees describe it when reporting, but the immediate response should remain consistent across types. A consistent response is to verify the identity and request independently, follow the approved process and report concerns.

What Does Social Engineering Look Like at Work

Employees should examine the requested action as well as how convincing the contact appears. A polished message, a correct job title or knowledge of an internal detail may support the story, but none proves identity.

An Urgent Request From a Senior Manager

A message that appears to come from a director asks an employee to send a sensitive file before a meeting and says no one else should be involved. Authority, urgency and secrecy can discourage an employee from questioning the request. The request falls outside the director’s usual role or approval route, so the employee verifies it using a known contact method and follows the normal information-sharing process.

Changed Supplier Payment Details

A message from a familiar supplier account asks the finance team to change the bank details before an invoice is paid. The timing aligns with current work and the message looks routine, but the requested change falls outside the normal payment process. Finance checks the instruction with a known supplier contact and follows the approved change process to reduce the risk of payment diversion (Report Fraud, n.d.).

A Caller or Visitor Claiming to Be IT Support

A caller asks for a verification code, or a visitor requests access to equipment for an urgent update. Technical language and a plausible manager’s name make the request sound informed. The employee does not share the code or admit the visitor. They contact the approved IT service through the internal directory or use the established visitor route.

A Familiar Contact Sharing an Unexpected Link

A message from a colleague’s profile contains an unexpected link or QR code and asks the employee to verify or recover an account. The familiar profile may lower suspicion, but the request does not fit the colleague’s normal work. NCSC guidance warns that attackers may impersonate known contacts and request account codes through messaging apps (NCSC, 2026). The employee verifies the contact independently and reports the attempt.

A New Professional Contact Asking Small Questions

A person met at an industry event asks about team names, systems and access arrangements across several conversations. Each question appears minor and no urgent request is made. A sequence of small questions matters because separate details can be combined. The employee follows the organisation’s information-sharing rules and checks with the designated internal contact before sharing work information.

Anatomy of a Social Engineering Request

Employees can examine seven elements of a request to decide whether it needs further verification, regardless of the channel.

Element What to Examine Practical Check
Channel Email, text, call, messaging, social contact or an in-person approach. The same social engineering tactic can use more than one channel.
Claimed Identity A colleague, manager, supplier, IT worker, service provider or trusted organisation. Familiarity is not proof of identity.
Pretext The reason given for the contact and why it appears relevant now. Was this contact expected and does the story fit the work?
Pressure Urgency, authority, secrecy, emotion, reciprocity, curiosity or a deadline. Pressure is a reason to slow down, not proof of an attack.
Requested Action Information, credentials, a code, money, access, software, a link, a file or a process exception. What exactly will change if I comply?
Process Deviation A changed detail, unusual channel, skipped approval or request outside normal authority. Does the request fit our established process?
Safe Response Stop, verify independently, follow the normal process and report the attempt or any action already taken. Use a trusted route that does not depend on the request.

What Warning Signs Should Employees Recognise

A warning sign is a reason to pause and check, not proof that the contact is malicious. Modern scams may be polished and can mislead experienced people, so spelling, branding, caller ID, a display name or a familiar voice should not be treated as proof that the contact is genuine (NCSC, 2022).

  • The contact, request or change in context is unexpected.
  • The person creates pressure to act quickly, secretly or without consulting someone else.
  • The person uses authority, familiarity or insider knowledge to discourage questions or checks.
  • The request involves credentials, verification codes, sensitive information, money, system access, remote access or physical entry.
  • The person asks to bypass an approval, callback, visitor, account-reset, payment or information-sharing process.
  • The contact moves to an unusual or personal channel, or the request does not fit the person’s normal role or authority.
  • Newly supplied contact details, altered payment details or a duplicate profile can make an identity check appear independent when it is not.
  • A sequence of small questions or favours may gradually reveal more information or lead to greater access.

Several signs may appear together, but one high-impact request can justify a check even without obvious pressure. An attacker may sound patient, informed and helpful. A genuine contact may also make an unusual request for legitimate reasons. Independent verification can confirm whether the request is genuine without accusing the contact of wrongdoing. Employees should rely on the organisation’s verification procedures rather than the contact’s appearance or manner. The key question is whether the claimed identity, reason for contact and requested action match the organisation’s established procedures. Employees should not have to diagnose the attacker or prove malicious intent before asking for support.

How Should Employees Respond to Social Engineering Attempts

A consistent response helps employees act when a request is unusual or difficult to verify. Employees can use three questions.

  1. What am I being asked to do or disclose?
  2. Does the request fit the person’s authority and our normal process?
  3. Can I verify it through a trusted route that does not depend on the request itself?

Stop before completing an unusual, sensitive or high-impact action. Break contact where appropriate and use an internal directory, a known telephone number or address, an official website, an existing supplier record, an approved visitor route or an established approval process. Contact details, links or instructions supplied in the approach are not an independent check. Official UK guidance similarly advises people to stop and contact an organisation through details they know are correct (Stop! Think Fraud, n.d.).

Follow normal payment, access, account-reset and information-sharing procedures even when the request claims urgency, seniority or confidentiality. Never disclose passwords or verification codes. Before sharing other sensitive information, verify the request and recipient through the approved route.

Report the concern through the organisation’s established route. Employees should know that route before they need it. State what happened, the channel used, the requested action and whether anything was shared or completed. If action has already been taken, report it quickly and factually. The team assigned to handle the report can then direct the next steps. Certainty is not a condition of reporting.

How Can Organisations Reduce Social Engineering Risk

Organisations cannot rely on every employee identifying every attempt. For phishing, NCSC guidance recommends layered defences that combine technology, processes and people, with user education as one part of the approach (NCSC, 2024). Although the NCSC guidance focuses on phishing, its layered approach can also inform controls for other social engineering risks. The aim is to make secure action practical during normal work and limit the effect of a mistaken response.

  • Set a shared awareness standard that explains how attackers create pressure or trust across different channels, uses role-relevant scenarios and defines how employees should verify and report requests.
  • Protect high-impact processes by requiring independent checks for payments, supplier-detail changes, account resets, privileged access, sensitive information and physical entry.
  • Separate approvals and limit privileges so urgency, confidentiality or seniority cannot override essential checks.
  • Use layered controls across email, web access, devices, permissions and authentication. Require strong, unique passwords and multi-factor authentication so one mistaken response does not automatically expose additional systems or information.
  • Make reporting quick and safe by providing an accessible route, thanking reporters and giving feedback. Investigate incidents to learn and improve, not to blame someone for an innocent mistake (NCSC, 2025b).
  • Review publicly available information that could strengthen an impersonation story, including information published by the organisation, staff, suppliers and contractors.
  • Assign clear ownership so reports reach IT, security, finance or management quickly and trigger a defined response.

Check whether employees can find and follow the verification and reporting routes during routine work and under time pressure. A control may fail under pressure if trusted contact details are difficult to find or employees lack support to question a senior person’s request. Review reports, near misses and genuine requests that were hard to verify, then improve the process. UK employers should use cyber security awareness training to explain how employees must handle high-impact requests and which organisational process supports that response. Training should reinforce the controls people are expected to use, not compensate for unclear verification, difficult reporting or a process that allows an informal bypass.

How Can Human Focus Support Cyber Security Awareness

Social engineering may use different contact routes, but attackers often try to make a request seem normal, familiar or urgent so that the target acts before checking it. A shared awareness standard tells employees to pause, verify and report suspicious requests across email, text, voice calls, messaging apps and face-to-face contact.

Human Focus Cyber Security Awareness Training is a CPD-certified, fully online course that takes 35 minutes or more to complete. It covers how cyber criminals exploit human behaviour through tactics such as social engineering, phishing and vishing, and explains employees’ responsibilities for following company policy and reporting attacks. Training should sit alongside the organisation’s technical, process and cultural controls.

About the author(s)

Human Focus Editorial Staff comprises a dedicated collective of workplace safety specialists and content contributors. The team shares practical guidance on human factors, risk, and compliance to support safer, more effective workplaces.

Share with others
You might also like

Popular Courses

GDPR Awareness Training Course
GDPR Training
View Course Details
LOTOTO online training course
Safe Isolation – Lock Out, Tag Out, Try Out (LOTOTO) Training
View Course Details
IOSH Managing Safely
IOSH Approved Managing Safely e-Learning
View Course Details
spill kit training
Spill Kit Hazardous Substances Training
View Course Details
Legionella-Risk-Assessment-Training
Legionella Risk Management Principles for Responsible Persons
View Course Details

Recent Articles

what is phishing
What Is Phishing? Phishing Training for Employees: What Should Staff Know?
fire safety competence framework industry standards
Fire Safety Competence Expectations in England and Wales: Can Your Organisation Evidence the Right Capability?
LOLER lift plan requirements
What Must a LOLER Lift Plan Include? A Guide for Duty Holders
harness inspection requirements
Harness Inspection Requirements: Does PUWER Apply?
dse assessment how often review frequency
How Often Should Display Screen Equipment (DSE) Assessments Be Reviewed?

Current Offers

BSA course
Building Safety Act Training

Original price was: £35.00.Current price is: £28.00. +VAT

carbon literacy course
Carbon Footprint Reduction

Original price was: £95.00.Current price is: £76.00. +VAT

near miss reporting for effective learning
Managing Near Miss Reporting for Effective Learning

Original price was: £895.00.Current price is: £595.00. +VAT

Sustainability and Environmental Management Training
Sustainability & Environmental Management Training

Original price was: £895.00.Current price is: £595.00. +VAT

colour blind test
Colour Blind Test

Original price was: £25.00.Current price is: £15.00. +VAT