Social engineering – ITSAP.00.166

Social engineering is now considered one of the most effective ways to compromise systems, often even more successful than advanced technical exploits. These attacks occur when threat actors use manipulation and deception to pressure or trick users into taking actions that compromise personal or organizational security. Threat actors often impersonate trusted individuals or reputable organizations and frequently collect publicly available information, including on social media, to tailor messages and increase credibility.

These attacks can be launched through emails, text messages, phone calls, collaboration tools or social media. They may also include QR codes or counterfeit websites and often involve requests to change passwords or provide information that grants system access. Once access is granted, threat actors can use it to steal business and financial information, compromise user accounts and potentially deploy malware. Anyone, at any level within an organization, can be targeted, making it essential to recognize and guard against these tactics to protect networks, systems and sensitive data.

 

On this page

Social engineering attacks and techniques

Social engineering attacks rely on deception, influence and impersonation to gain information, access or advantages. These techniques reflect how threat actors design and deliver their tactics, often combining multiple approaches. Artificial intelligence (AI) is making social engineering more effective by enabling highly realistic phishing messages, personalized lures and deepfake impersonation of trusted individuals. These tools reduce traditional warning signs and allow attackers to exploit trust at scale, reinforcing social engineering as a leading entry point for breaches.

The following sections outline three common tactics used by threat actors:

  • Impersonating trusted individuals or organizations
  • Manipulating behaviour through fabricated scenarios or emotional pressure
  • Using AI to enhance the realism, personalization or scale of deceptive activity

Impersonation-based attacks

These attacks rely on imitating trusted individuals, organizations and communication methods to appear legitimate, including through compromised internal or partner accounts. Threat actors use familiar names, messages and channels to blend into normal activity and increase the likelihood that their requests will be accepted. The goal is to prompt the user to take an action that benefits the attacker, such as transferring funds, altering payment information, disclosing sensitive information or completing a task that enables unauthorized access or fraud.

Phishing

Phishing is a tactic where threat actors send messages that appear to come from a trusted source. These messages are often distributed broadly and may attempt to trick recipients into sharing sensitive information or taking actions such as changing a password, clicking malicious links, or opening harmful attachments that appear legitimate. For more information, read our publication Don’t take the bait: Recognize and avoid phishing attacks (ITSAP.00.101).

Spear phishing

Spear phishing is a more targeted form of phishing in which attacks are directed at a specific individual or small group. These messages often include personalized details to make them appear more convincing.

Whaling

Whaling refers to phishing attacks aimed at senior leaders in an organization, such as CEOs or executives, with the goal of facilitating fraudulent financial transactions like unauthorized payments or wire transfers.

Smishing

Smishing is a phishing attack sent through short message service (SMS) or text message. Threat actors send fraudulent messages to trick victims into revealing sensitive information, such as login credentials or banking details.

Quishing

Quishing occurs when a phishing attack includes a QR code that directs users to a malicious website when scanned.

Vishing

Vishing involves phishing conducted through voicemail or voice calls on a landline, mobile phone or voice over Internet protocol (VoIP). Threat actors may spoof numbers, disguise their voice or use AI to imitate trusted individuals. For more information, read our publication What is voice phishing? (ITSAP.00.102).

Consent phishing

Consent phishing occurs when a threat actor sends a legitimate-looking, malicious app authorization request. If approved, the request grants the attacker access to the account or data without the need for a password.

Thread hijacking

Thread hijacking is an attack where a threat actor gains access to an email account and inserts themselves into an existing conversation. The attacker replies within the thread to make communication appear legitimate and increase the likelihood that the request will be trusted.

Business email/communication compromise

Business email/communication compromise is an attack where a threat actor impersonates a trusted individual, such as a leader, colleague or business partner. The goal is to prompt the recipient to transfer funds, disclose sensitive information or complete an action that benefits the attacker.

Manipulation-based techniques

The approaches below focus on influencing decisions or behaviours through false promises, emotional pressure or manufactured situations. Threat actors create convincing narratives, incentives or warnings to guide users into taking actions that support their objectives. These techniques work by taking advantage of a person’s trust or creating a sense of urgency. This can cause someone to respond in ways that can reveal information, allow access or create openings for further harm.

Pretexting

Pretexting is a technique where a threat actor uses a fabricated scenario or narrative as a pretext for contacting the target. This false justification is designed to make the interaction seem reasonable and believable, build trust over time and encourage the target to share sensitive information or provide access.

Baiting

Baiting is an attack in which a threat actor convinces users to take an action, such as clicking a malicious link, by offering something enticing like a reward or prize.

Quid pro quo

Quid pro quo is where a threat actor persuades users to provide sensitive information or perform a task in exchange for a promised service or benefit.

Honey traps

Honey traps involve a threat actor building a fake romantic relationship to obtain money or sensitive information.

Scareware

Scareware is an attack that attempts to scare users into believing their device or network is at risk, encouraging them to take harmful actions such as clicking a malicious link.

Multi-factor authentication (MFA) fatigue

Multi-factor authentication (MFA) fatigue is an attack in which a threat actor sends repeated MFA prompts in an attempt to wear down the target. The goal is to increase the chance that the target will eventually approve the request.

Watering hole

Watering hole is an attack that involves compromising a trusted website that a specific target group frequently visits, allowing attackers to install malware on visitors’ devices.

Artificial intelligence-driven attacks

The attacks listed below use AI to create convincing messages, identities or media that support deception. AI tools can imitate natural communication patterns, generate realistic synthetic content or replicate human voices with a high level of accuracy. By increasing the speed, scale and believability of malicious activity, these techniques enhance traditional social engineering methods and make them more difficult to detect.

AI-generated phishing at scale

This attack uses AI tools to rapidly create large volumes of personalized phishing messages. These messages often mimic natural writing styles, organizational language or known communication patterns to increase the likelihood of being trusted. As a result, even well-crafted messages should be treated with caution and verified through trusted channels.

Synthetic identity deception

In this type of attack, AI is used to create or enhance false identities that appear legitimate and trustworthy. These identities may combine real and fabricated details to allow threat actors to gain access to systems, services or information. This highlights the importance of verifying identities using established processes rather than relying on appearance or familiarity alone.

Deepfakes

This method relies on AI-generated audio, video or images that accurately imitate one or more real individuals. These fabricated media pieces are used to manipulate conversations, impersonate trusted individuals or add credibility to fraudulent requests. Audio or video alone should not be considered proof of identity, especially for sensitive or unusual requests.

Voice cloning

This technique uses AI models to replicate a person’s voice using small audio samples. Cloned voices can be used in calls or voice messages to impersonate trusted individuals, bypass voice-based authentication and support fraudulent or unauthorized requests. Any requests involving sensitive actions should be confirmed by using a second, independent form of communication.

Autonomous agentic AI attacks

This emerging class of threat uses autonomous AI agents to carry out entire attack lifecycles with little to no human involvement. These agents can perform reconnaissance, select targets, create believable personas and attempt exploitation in a continuous process. By monitoring victim behaviour in real time, agent-driven attacks can automatically adjust their approach, shifting between email, text, voice or other channels when an attempt is unsuccessful. This adaptability makes these attacks more difficult to detect and disrupt.

 

Social engineering lifecycle

Threat actors typically follow a consistent pattern when executing social engineering attacks. Understanding how these steps unfold can help support awareness activities and strengthen organizational defences.

The common phases of a social engineering attack are outlined in the following section. Each phase provides an example of the actions a threat actor may take.

The bait

Threat actors research their targets at various levels to gather information and craft convincing messages. This targeting can range from broad approaches such as sending messages through social media platforms to more focused efforts aimed at a specific organization, team or individual. This early phase of collecting and analyzing information enables threat actors to build a pretext that appears credible, authentic and trustworthy.

The hook

Threat actors attempt to draw their targets into the scheme by using familiarity, sympathy, urgency, threats, authority cues or a casual tone. These psychological triggers are designed to lower defences and make the communication feel genuine. As a result, users may be more likely to believe that the request or scenario is legitimate.

The attack

Users may be persuaded to provide sensitive information or take harmful actions such as clicking a malicious link, opening an attachment or changing passwords that provide account or system access. These actions allow the threat actor to obtain credentials, financial details or other information that may be used to access networks, steal data or deploy malware.

The escape

Once a threat actor has obtained the information or completed their objective, they disengage. Some threat actors may attempt to silence the target through intimidation or warning messages, while others simply disappear to avoid detection.

The aftermath

In the post-incident phase, threat actors may continue to benefit from the stolen information. This can include reusing compromised credentials to access other accounts or selling sensitive information to other criminals. It may also involve using the information or accounts to target others. These activities can extend the impact beyond the original incident and create ongoing risk if left unaddressed.

How to spot social engineering threats

There are certain warning signs that often appear in social engineering attempts. Recognizing these signs can help prevent harmful actions before they occur.

Watch out for unsolicited communications with:

  • attachments
  • hidden links
  • spoofed websites
  • malicious QR codes
  • login pages
  • mismatched or suspicious sender details
  • threatening or urgent language prompts for personal or sensitive information

Be aware that while financial institutions and government agencies may contact you by phone, text or email, they will never request sensitive information or provide links for account access. Exercise caution when handling any unsolicited communications, particularly those requesting engagement or action.

How to respond to suspected social engineering attacks

A quick and coordinated response is essential when an incident involves deceptive tactics that are designed to manipulate individuals or compromise systems. Take immediate action by following the steps below to limit potential damage, contain the incident and reduce the risk of further compromise:

  • Do not reply to the sender
  • Save the suspicious message for review and investigation
  • Notify your IT or security team immediately
  • Change passwords on all impacted accounts that may be compromised
  • Enable or reset MFA
  • Contact your bank or financial institution if you shared any payment or banking information
  • Run an antivirus scan if you clicked a link, downloaded a file, or installed software
  • Monitor all accounts closely for unusual logins, messages or transactions
  • Review and reduce personal information shared online to limit further targeting
 

Tips to stay safe from social engineering

Social engineering attacks can present significant risks to an organization and may disrupt operations if the IT environment becomes compromised. Threat actors often exploit common workplace conditions such as time pressure, remote work and role-based responsibilities. Taking the following protective measures can help strengthening overall security and safeguarding your organization by taking the following protective measures.

Administrative controls

  • Avoid logging into websites using any links sent to you by unsolicited emails, texts or messages
  • Provide regular training to employees to ensure they understand how to recognize and respond to suspected social engineering attempts, and apply the principle of least privilege to limit access and reduce potential impact
  • Contact the sender through securely verified and out-of-band (alternate) channels to confirm the legitimacy of business email communications or to address the situation
  • Inspect links carefully before selecting them by hovering over the Uniform Resource Locator (URL) to confirm the domain is correct and free of misspellings, extra characters or unusual subdomains
  • Limit the amount of personal and professional information shared on social media platforms

Technical safeguards

  • Use phishing-resistant MFA on all systems and accounts, prioritizing the most sensitive or critical systems to reduce the risk of account compromise
  • Enable spam filtering and disable embedded macros in email attachments
  • Implement network-based security tools such as protective Domain Name System (DNS), URL filtering, content inspection, and Transport Layer Security or Secure Sockets Layer inspection to detect and block malicious activity
  • Install security tools such as antivirus, anti-malware, anti-phishing tools and firewalls from trusted vendors
  • Enable automatic updates and patches for security tools and operating systems on devices
  • Design networks with segmented zones and restricted access to minimize the impact of cyber security incidents

Monitoring and response

  • Develop and implement an incident response plan that covers cyber incidents, including social engineering attacks
  • Monitor for unusual access and activity across identity, financial, cloud and collaboration systems
  • Back up information offline to ensure the backup remains isolated from organizational systems and networks

By reporting suspicious online activity and scam messages through our trusted national resources, individuals and organizations can help reduce cyber threats and protect others. You can report a cyber incident on the Cyber Centre’s website or via text message to 7726.

Learn more

Date modified: