Skip to content

Fundamentals

Social engineering exploits the person, not the machine. In most real intrusions the first access comes through a human who clicks, answers the phone, or lets someone in. This card covers the psychological principles, the attack cycle, and the ethical/legal framework required to do it in an authorized engagement.

Authority "I'm from IT / management / the tax office" -> obedience without verifying
Urgency "your account locks in 1h" -> bypasses reflective thinking
Scarcity "only X left / limited offer" -> quick decision
Social proof "all your colleagues already did it" -> conformity
Liking empathy, rapport, shared interests -> lowered guard
Reciprocity a small favor -> the victim wants to reciprocate
Commitment a small "yes" chains into a bigger one (foot-in-the-door)

These are Cialdini’s principles: the attacker combines several so the victim acts before thinking.

- authority bias and trust in known brands/logos
- fear (of losing access, a fine, getting in trouble) as a driver
- curiosity ("look at this photo", "attached invoice", "you were mentioned")
- workload/distraction: busy people verify less
1. RECON/OSINT gather target info (see se-pretexting): org chart, emails,
vendors, internal jargon, social media
2. PRETEXT build the credible story and the channel (email, phone, in person)
3. HOOK contact: the message/call that triggers the action
4. EXPLOITATION the victim acts: click, credentials, transfer, physical access
5. EXIT achieve persistence/objective and withdraw without raising alarms
Phishing mass or targeted email (spear/whaling) -> see se-phishing
Vishing by voice/phone; Smishing by SMS -> see se-vishing
Pretexting elaborate story, often in person or by phone -> see se-pretexting
Physical tailgating, USB drop, in-person impersonation -> see se-physical
- WRITTEN authorization with explicit scope BEFORE any testing
- define what's allowed: phone pretext? physical access? who NOT to touch?
- mind the human factor: don't humiliate; the goal is to IMPROVE, not punish
- data protection: OSINT and captured credentials are personal data (GDPR)
- reporting aimed at training and controls, not at naming specific people

Without authorization these techniques are crimes (fraud, impersonation, trespass). The value of social red teaming is measuring and improving human resilience with consent.

  • Ongoing awareness and simulations (see Phishing campaigns) measured by click/report rate.
  • Out-of-band verification procedures for sensitive requests (payments, account changes).
  • Phishing-resistant MFA (FIDO2/passkeys), and technical controls that reduce the impact of a click.
  • A “report without fear” culture: make the report button easy and don’t punish those who fall for it.
  • Twitter (2020): vishing of employees → access to internal tools and hijacking of verified accounts.
  • RSA SecurID (2011): spear-phishing with a malicious Excel → compromise of token seeds.
  • MGM / Caesars (2023): Scattered Spider used help-desk vishing to reset MFA.
  • Phishing/social engineering leads the initial-breach vector in DBIR reports year after year.
  • Written authorization and scope (channels, targets, exclusions) confirmed
  • Target OSINT completed (see Pretexting & target OSINT)
  • Pretext credible and consistent with the gathered info
  • Influence principles chosen (authority/urgency/…)
  • Channel and pretext aligned (email/voice/physical)
  • Evidence captured without over-exposing personal data
  • Report aimed at training and controls, not at people