Social engineering relies on hacking people instead of software, and it has become quite the art. Rather than breaking through a firewall, attackers manipulate people — by impersonating someone trustworthy, creating urgency, and exploiting fear and curiosity. This commonly leads to handing over passwords, money, or access. And it works disturbingly well: Verizon's 2025 Data Breach Investigations Report found the human element present in a staggering 60% of all breaches, and phishing was once again the single most reported crime category in the FBI's 2025 Internet Crime Report, with nearly 200,000 complaints out of more than a million filed.
Every social engineering attack starts the same way: with information about you. The attacker who calls pretending to be your bank already knows your name, your city, maybe your carrier and your relatives' names, and it's usually because that information is sitting in public on data broker and people-search sites. That's the part you can actually control, and we'll come back to it.
How social engineering attacks work
Almost every attack, from a mass phishing email to a months-long romance scam, follows the same four-stage arc:
- Research. The attacker gathers what's publicly available about the target: social media profiles, employer pages, and data broker listings that bundle your address, phone number, employer, and family members into one convenient dossier.
- The approach. The attacker contacts their victim under a pretext: a delivery notification, a fraud alert from "your bank," a recruiter with an offer, a match on a dating app.
- The exploit. Using trust built in the approach, plus urgency, fear, or authority, they extract the payload: credentials, a wire transfer, remote access to your device, or gift card codes.
- The exit. The attacker disappears, covers their tracks, and often sells what they learned so the next crew can run a follow-up scam on a now-proven victim.
Understanding the individual tactics matters because each one has a different tell.
The 12 most common types of social engineering attacks
1. Phishing
The workhorse of social engineering: fraudulent emails impersonating a company or person you trust, designed to harvest logins or deliver malware. Modern phishing emails clone real branding, use lookalike domains (eg. "arnazon.com"), and increasingly are written by AI, so the old advice about spotting typos unfortunately no longer holds. The FTC's guidance is blunt: legitimate companies do not email you asking for your Social Security number, password, or payment details.
2. Spear phishing
Phishing aimed at one specific person, built from research about them. Where mass phishing says "Dear Customer," spear phishing says "Hi Sarah — following up on the Henderson invoice." The personal details that make these messages convincing — your job title, coworkers, home address, phone number — are frequently pulled straight from LinkedIn and people-search sites.
3. Whaling
Spear phishing aimed at executives, or attacks that impersonate an executive to pressure employees ("It's the CEO. I need those wire details in the next hour — I'm boarding a flight"). The authority of the sender substitutes for evidence.
4. Smishing and vishing
Phishing by SMS (smishing) and by voice call (vishing). Smishing texts pose as toll authorities, delivery services, or your bank's fraud department. Vishing got dramatically more dangerous with AI voice cloning: a few seconds of audio from a social video is enough to fake a family member's voice in a "grandparent emergency" call. The FBI's 2025 report added a dedicated section on AI-enabled fraud — over 22,000 complaints costing nearly $893 million.
5. Pretexting
The attacker invents a scenario — a pretext — that makes their request seem routine: an IT contractor who needs your login to "migrate your mailbox," a survey researcher, a building inspector. Good pretexts are built from real facts about you or your employer, which is why exposed personal data makes them so much more effective.
6. Business Email Compromise (BEC)
The most financially damaging variant. Attackers compromise or spoof a business email account, then redirect invoice payments or payroll to accounts they control. BEC consistently ranks among the top loss categories in IC3 data year after year, with losses measured in billions of dollars annually.
7. Baiting
An irresistible freebie with a hook in it: a "free" movie download that's malware, a USB drive dropped in a parking lot labeled "Q4 layoffs," a giveaway that requires you to "verify" your account. Curiosity does the attacker's work for them.
8. Quid pro quo (tech support scams)
The attacker offers a service in exchange for access — most commonly fake tech support. A pop-up or cold call claims your computer is infected, then the "technician" asks for remote access and payment. Real security warnings never include a phone number to call.
9. Honeytraps and romance scams
A fabricated romantic relationship, built over weeks or months, that ends in requests for money — often laundered through a fake crypto investment ("pig butchering"). These scams increasingly begin with a "wrong number" text that turns friendly.
10. Scareware
Fake alarms designed to panic you into acting: browser pop-ups claiming infection, emails claiming a hacker has your webcam footage. A common variant quotes your real password or home address — pulled from an old breach or a people-search site — as fake "proof" that you've been hacked.
11. Tailgating and piggybacking
The physical-world version: following an authorized employee through a secure door, borrowing a badge, or posing as a delivery driver. Low-tech, but still effective.
12. Watering hole attacks
Instead of coming to you, the attacker compromises a website your community already visits, such as an industry forum or a local news site, and plants malware there. You get infected doing something you do every week.
How to recognize a social engineering attack
The tactics differ, but there are certain tells:
- Manufactured urgency. "Act in the next 30 minutes." These deadlines are created entirely to stop you from thinking or verifying.
- Requests to move channels. "Don't call the office, use this number." Attackers isolate you from any channel where the impersonation would collapse.
- Unusual payment rails. Gift cards, wire transfers, crypto, payment apps. Remember, no legitimate institution takes gift cards.
- Secrecy. "Don't tell anyone about this transaction." Real processes survive scrutiny.
- Too much familiarity. A stranger who already knows your address, employer, and mother's name isn't proving legitimacy — they're proving they bought your data profile.
When in doubt, break contact and verify independently: hang up and call the organization on the number printed on your card or its official website — never a number the message gave you.
How to protect yourself
- Enable two-factor authentication everywhere, preferring an authenticator app or passkey over SMS codes.
- Use unique passwords via a password manager, so one phished login can't cascade.
- Verify out-of-band. Any request involving money, credentials, or sensitive data gets confirmed on a channel you initiated.
- Agree on a family or business code word to defeat voice-cloning emergency calls.
- Report attacks at reportfraud.ftc.gov and ic3.gov, and follow CISA's phishing guidance for reporting workplace attempts.
- Shrink the research phase. This is the underrated one. Every attack in this list gets easier when the attacker can pull your phone number, address, relatives, and employment history from data broker sites for a few dollars. Removing your listings from people-search and data broker sites cuts off the raw material spear phishing, pretexting, and scareware are built from. Our guide to removing your personal information from the internet walks through exactly how.
The bottom line
Social engineering succeeds because it targets the one system that can't be patched: human judgment under pressure. You don't need to memorize all twelve tactics. You need three habits — slow down when anything is urgent, verify on a channel you chose, and keep your personal information off the open market so attackers start with an empty file instead of a dossier.