Social Engineering
Social engineering is the use of psychological manipulation and human interaction to trick people into revealing confidential information, such as a password, or into granting access to systems. Rather than exploiting technical flaws, it targets human behavior and trust. It is often the first step an attacker uses to compromise information about an organization or its computer systems.
Social engineering refers to non-technical attack methods that exploit human behavior—through social interaction, deception, and psychological manipulation—to induce individuals to reveal sensitive information or provide access to systems and networks. Attackers leverage social skills to obtain or compromise information about an organization or its computing environment, targeting the human element rather than technical vulnerabilities. Because it relies on manipulating people rather than breaching controls directly, awareness and verification practices are intended to help reduce, but do not guarantee elimination of, exposure to such attacks.
Why it matters
Social engineering matters because it targets the human element rather than technical controls, which means even organizations with strong encryption, tokenization, and network segmentation can be compromised when an attacker successfully manipulates a person. In payment security contexts, a single employee tricked into revealing credentials or granting access can expose systems that store or process cardholder data, undermining otherwise sound technical safeguards. Because these attacks exploit trust and normal human behavior, they are often the first step in a broader compromise rather than an end in themselves.
For compliance and fraud teams, social engineering is significant because it does not map neatly to a single technical control. Awareness training, verification procedures, and access management practices are intended to help reduce exposure, but they do not guarantee elimination of the risk, since attackers continually adapt their pretexts and targets. The effectiveness of any given defense depends on implementation, staff behavior, and ongoing reinforcement rather than on a one-time control.
It is worth noting that the specific frequency and financial impact of social engineering attacks vary by source, period, and methodology, so precise figures should be treated cautiously and confirmed against the underlying study or reporting. The qualitative point that stands regardless of numbers is that human-targeted attacks remain a persistent vector because they bypass, rather than break, technical defenses.
Who it's relevant to
Inside Social Engineering
Common questions
Answers to the questions practitioners most commonly ask about Social Engineering.