# What Is Social Engineering? Cyber Attacks Targeting the Human Factor

**URL:** https://securesys.com.tr/en/learning/end-user-security/what-is-social-engineering

![What Is Social Engineering? Cyber Attacks Targeting the Human Factor](/images/bilgi-merkezi/covers/cover-sonkullanici-03.webp)

When cyber attacks are mentioned, technical methods such as exploits, malware, firewall bypass or zero-day vulnerabilities come to most people's minds. Yet in many successful attacks the attacker's first target is not a server or a security device but directly the human being.

Convincing an employee that an urgent payment needs to be made, asking help desk personnel for a password reset, introducing oneself as a senior executive, physically entering an unauthorized area behind another employee or directing a user to approve an MFA verification can lead to serious security breaches even without using a technical vulnerability.

This attack class is generally defined as:

#### Social Engineering

as it is called.

At the basis of social engineering is the manipulation not of technical systems but of people's decision-making processes. By using psychological elements such as trust, authority, fear, curiosity, the desire to help or time pressure, the attacker aims for the user to carry out an operation they would not normally perform.

For this reason social engineering is not only the subject of security awareness training. At the same time it is a direct part of identity security, help desk processes, privileged access, physical security, financial approval mechanisms and incident response processes.

In modern organizations a strong social engineering defense must be built on this principle:

**Do not just tell people to be careful; design critical operations so that they do not depend on the decision of a single person.**

### What Is Social Engineering?

Social engineering is the attack approach that aims to obtain information, access or an operation by manipulating a person's behaviour.

The attacker's goal is most often not to harm the user directly. It is to persuade the user to perform an operation the attacker wants with their own authority.

This operation can be as open as sharing a password or as embedded in the business process as approving a bank account change the attacker wants.

For this reason the critical question in social engineering attacks is this:

#### Does the user really notice that they are under attack, or do they think they are doing their normal job?

In the most successful social engineering attacks the user most often experiences the second situation.

### Why Is Social Engineering Different From Technical Attacks?

Technical attacks generally target a vulnerability, a misconfiguration or a weak security control. Social engineering, on the other hand, takes advantage of the predictable characteristics of human behaviour.

In the work environment people are used to deciding quickly, to prioritizing requests coming from managers, to helping customers and to solving problems. And the attacker uses exactly these behaviour models.

For example the attacker can call a help desk employee and say "My phone is broken, MFA is not working, I have to join the CEO meeting". The attack here is not an exploit but the pressure created on the process.

If the help desk can perform an MFA reset based only on a few pieces of information the person knows, the attacker can take over the account without technically hacking the system.

For this reason an important part of the social engineering risk is related less to user training than to:

**process design**

it is related to this.

### The Psychological Methods Used in Social Engineering

The greater part of social engineering attacks uses certain psychological mechanisms. Foremost among these are urgency, authority, fear, trust and curiosity.

**Urgency aims to reduce the user's thinking time. Messages such as "If this payment is not made today the contract will be cancelled" or "your account will be closed within 20 minutes" push the user to take quick action.**

**Authority is the imitation of authority figures such as managers, official institutions, bank personnel or the IT team. The user may ask fewer questions of a person they think is authorized.**

**Fear affects the decision mechanism through fears such as the account being closed, money loss, a penalty, a disciplinary process or job loss.**

**Curiosity, on the other hand, tries to make the user interact with content that arouses curiosity such as "the salary list", "a confidential report", "the raise rates" or "a complaint about you".**

Successful social engineering attacks most often use several of these elements at the same time.

### What Is Pretexting?

Pretexting is the attacker trying to gain the target's trust by creating a convincing story or role.

The attacker can introduce themselves as:

an IT support specialist,

a bank employee,

a supplier,

a manager,

a courier,

an auditor

or another authorized person.

Here the strength of the attack depends less on technical knowledge than on how realistic the story is.

For example the attacker can first research the company structure, employee names, departments and managers over LinkedIn. Then they can call the help desk and request a password reset using the name of a real employee.

In this case the real information obtained with OSINT increases the credibility of the attack.

### The Relationship Between OSINT and Social Engineering

OSINT, that is Open Source Intelligence, is the collection of information from open sources.

The corporate website, LinkedIn, social media, press statements, job advertisements and organization announcements can be important information sources for the attacker.

Too much information being shared about the technology a company uses, employee names, the roles of managers or ongoing projects can make it easier for the attacker to create a pretext.

For this reason social engineering defense is not only an e-mail filter or awareness training. Which information the organization publishes to the outside is also part of the attack surface.

### What Is Baiting?

Baiting is the social engineering method that tries to obtain interaction by offering the user content or an opportunity that looks attractive.

This content can be free software, a gift, a discount, a special file or a document that arouses curiosity.

One of the most classical examples in the physical world is USB baiting. The attacker can leave a USB device with an eye-catching expression such as "Salary List" or "Board of Directors" on it around the organization.

The aim is for a curious user to plug the device into their computer.

In modern organizations a removable media policy and endpoint device control are important for reducing risks of this kind.

### What Is Impersonation?

Impersonation is the attacker assuming the identity of another person or role.

This person can be the CEO, the CFO, an IT employee, a bank official or a real supplier of the company.

In impersonation attacks the attacker does not necessarily have to take over the real account. Even the e-mail display name, a telephone call or a fake social media account can be enough.

For this reason users need to look not only at the visible name but at the source of the communication and the nature of the request.

Particularly in financial transactions:

**as much as who it came from, what is being asked for must also be verified.**

### Authority Abuse and CEO Fraud

Authority abuse is a person creating pressure on the user by behaving like a senior authority.

CEO Fraud is one of the best known examples of this in corporate environments.

The attacker can ask the finance team for a quick payment by showing themselves as a company executive. If the request contains expressions such as "confidential", "urgent" or "do not share with anyone" in particular, the risk increases.

These attacks are not carried out only over e-mail. The telephone, messaging applications and even voice imitation methods can be used.

For this reason the finance processes need to be based not only on identity verification but on:

**business process verification**

on these mechanisms.

### What Is the Four-Eyes Principle?

The Four-Eyes Principle is the principle of a critical operation being checked by at least two authorized people.

Particularly in a payment, a bank account change, privileged access or important configuration changes, a single person deciding is risky.

In social engineering attacks the attacker can most often succeed in deceiving one user. However, having the same operation verified by a second independent person seriously reduces the probability of the attack succeeding.

For this reason social engineering defense is not only user awareness.

In some processes the strongest control:

**dual approval**

can be this.

### What Is Out-of-Band Verification?

Out-of-band verification is a request being verified over another trusted channel different from the communication channel it came from.

For example if a vendor notifies a bank account change by e-mail, instead of calling the telephone number inside the e-mail the vendor contact number previously registered in the organization must be used.

This method is particularly important in operations such as:

payment change,

password reset,

privileged access

and critical data sharing

it is quite important in operations such as these.

### What Is Help Desk Social Engineering?

Help desk teams are high-value targets in social engineering attacks.

Because the help desk:

password reset,

MFA reset,

account unlock,

device enrollment

can carry out critical operations such as these.

The attacker's aim can be to persuade the help desk employee rather than to deceive the user directly.

For this reason performing identity verification in help desk processes with only easily findable information such as the name, date of birth, employee number or the manager's name is not a strong method.

Identity verification processes must as far as possible contain:

strong identity verification,

an approved workflow,

an audit trail

and, where necessary, manager confirmation

they must contain these.

### The MFA Reset Social Engineering Risk

Using MFA is a very strong control in terms of account security. However, if the MFA enrollment or reset processes are weak the attacker can indirectly cross the strong authentication mechanism.

For example the attacker can call the help desk, say that their phone has been lost and try to register a new MFA device.

If the help desk performs the MFA reset without sufficient identity verification the attacker can bind their own device to the user account.

For this reason in the modern identity security approach it is not only MFA being active but also:

#### MFA lifecycle security

that is important.

### MFA Fatigue and Push Manipulation

In MFA fatigue attacks the attacker makes login attempts again and again with the username/password they have captured and sends a large number of push notifications to the user.

The aim is for the user finally to approve by mistake or in order to get rid of the notifications.

This attack is a psychological pressure method rather than a technical authentication bypass.

Users need to reject unexpected MFA requests and report them to the security team.

Methods such as number matching and phishing-resistant MFA also help to reduce this risk.

### Why Is Identity Verification Critical?

In social engineering attacks the fundamental problem is most often that the identity is verified incorrectly.

A person introducing themselves as the CEO does not mean that they really are the CEO.

The telephone number appearing correctly on the screen is not enough either.

The e-mail display name can be the same.

The attacker may even know some real personal information.

For this reason identity verification:

**instead of depending on a single piece of information, multiple verification**

must be built on this.

### Deepfake Voice and AI-Assisted Social Engineering

With the development of artificial intelligence technologies social engineering attacks can become more convincing.

Voice cloning technologies can be used to produce voice recordings that resemble the voice of a real person. Similarly video or image manipulation techniques can also strengthen impersonation attacks.

This situation is important particularly in terms of executive impersonation and payment fraud.

For this reason:

"I recognized their voice, so it really is them."

this approach is no longer a strong verification method on its own.

For critical operations predefined business processes and approval mechanisms must be used.

### What Is the Strongest Approach in Deepfake Defense?

Deepfake detection technology can be useful but on its own it is not sufficient.

The strongest approach is most often:

**to apply the same verification process regardless of who requested the operation.**

Even if the CEO asks for a payment the system must use the same approval chain.

In this case even if the attacker successfully imitates the CEO's voice or image the business process control can stop the attack.

### What Is Tailgating?

Tailgating is an unauthorized person entering a secure area behind an authorized employee.

For example when the employee opens the door with an access card the attacker can enter behind them carrying boxes in their hands.

People's reluctance to close the door in someone's face can be used by the attacker.

For this reason physical security awareness is also a part of end user security.

### The Difference Between Piggybacking and Tailgating

Even though these terms are sometimes used interchangeably, piggybacking mostly expresses the situation in which the authorized person consciously allows the other person to pass.

Tailgating, on the other hand, can express passing behind the authorized person without them being aware.

In both cases the aim is to cross the physical access control.

### Physical Social Engineering

Social engineering does not take place only in the digital environment.

The attacker:

a courier,

a technician,

a cleaning worker,

a visitor

or vendor personnel, by behaving like these, can try to obtain physical access.

For this reason visitor management, badge control and a secure area policy are important.

### Why Is Badge Sharing Risky?

Access card or badge sharing weakens the authentication and accountability mechanism.

Who entered which area and when cannot be tracked correctly.

For this reason personnel must not share their own access card with another user.

### Why Are Clean Desk and Clear Screen Related to Social Engineering?

In the event that the attacker obtains physical access inside the organization, open screens, written passwords, customer lists or sensitive documents can be an additional information source.

Clean Desk and Clear Screen policies are not only a matter of tidiness.

They reduce the information exposure risk.

### What Is Shoulder Surfing?

Shoulder surfing is the user's screen, keyboard or document information being observed physically.

It is risky particularly for users working in public areas.

A privacy screen, auto-lock and physical awareness can reduce this risk.

### What Is Dumpster Diving?

Dumpster diving is sensitive information being sought from documents or devices thrown into the rubbish.

Printed documents not being disposed of securely;

an employee list,

an invoice,

a network diagram,

customer information

can cause data such as this to be exposed.

For this reason secure document disposal processes are also within the scope of information security.

### What Is Business Process Fraud?

Social engineering is not only credential theft.

The attacker's aim can be to persuade the employee to perform a wrong operation inside the existing business process.

For example:

changing the payment account,

having the wrong invoice approved,

having a sensitive document sent,

having a new vendor added

operations such as these can be targeted.

For this reason when organizations design security controls they must look not only at IT security but also at:

**business process security**

at this subject.

### Invoice Fraud and Vendor Manipulation

In invoice fraud attacks the attacker can change the payment information by imitating the identity of a real vendor or manager.

In some cases the attacker may have compromised the real vendor mailbox. In this case the e-mail really comes from the correct account.

Therefore checking the sender address is not enough on its own.

Critical changes such as a new bank account request must be verified over a different channel.

### The Relationship Between BEC and Social Engineering

Business Email Compromise is one of the examples of social engineering with the highest financial impact.

In BEC attacks malware or an exploit may not be used.

The attacker:

business context,

the trust relationship,

timing

and authority

manipulates the user through these.

For this reason in BEC defense finance process controls are as critical as mail filtering.

### The Relationship Between Insider Risk and Social Engineering

The social engineering attacker does not always have to be outside the organization.

Someone from inside can obtain information or access they do not normally have by manipulating other employees.

In addition the attacker can send requests that look more trustworthy to other employees over an internal account they have compromised.

For this reason internal communication must not automatically be accepted as trusted.

### What Is Lateral Social Engineering?

It is a compromised internal identity being used to perform social engineering on other employees.

For example the attacker can send a payment request to the finance team from a real employee's mailbox.

In this case the message is not external and the classic external sender warning may not appear.

For this reason identity monitoring and anomalous mailbox behaviour detection are important.

### How Should Security Awareness Be in Social Engineering?

One of the biggest mistakes of security awareness programs is to tell the user only:

"Do not click suspicious e-mails."

to say this.

Social engineering awareness must be far broader.

Users must be able to recognize unexpected:

credential requests,

MFA requests,

payment instructions,

password resets,

physical access requests

situations such as these.

### The Use of Scenarios in Awareness Training

Realistic scenarios can be more effective than only explaining theory.

For example a BEC scenario can be explained to the finance team, MFA reset manipulation to the help desk, and whaling and impersonation risks to the executive team.

This approach is called:

#### Role-Based Security Awareness

as it is known.

### Why Is Role-Based Security Awareness More Effective?

Every user's attack surface is not the same.

Finance personnel on payment fraud,

the IT help desk on identity verification,

executive users on whaling,

and HR on personal data manipulation

can carry a higher risk.

For this reason a role-based approach is more meaningful than giving the same training content to everyone.

### What Is Human Risk Management?

Human Risk Management is user-related cyber risks being managed not only with training but together with measurement and technical controls.

In this approach the user's:

role,

privilege,

phishing behaviour,

device risk,

incident history

factors such as these can be evaluated.

The aim is not to blame the user but to apply stronger controls to high-risk areas.

### What Is a User Risk Score?

A User Risk Score is the security risk associated with the user being evaluated with a relative score.

For example a privileged administrator or a finance manager can carry a higher impact because of their role.

In addition repeated phishing simulation failures or risky login events can raise the risk score.

This information can be used for targeted training or stronger authentication controls.

### The Balance Between User Monitoring and Privacy

When user behaviour is analyzed in human risk programs the subject of privacy must be taken into account.

The scope of the monitoring;

the security requirement,

organizational policy,

legal obligation

and proportionality

must be evaluated within this framework.

A User Risk Score must not mean that a person is "untrustworthy".

This must only provide security risk context.

### Technical Controls in Social Engineering Defense

Even though social engineering is a human-centric attack, strong technical controls can seriously reduce the effect of the attack.

For example the use of MFA can make account takeover after password theft more difficult. EDR can detect the behaviour when a malicious attachment is run. DLP can prevent sensitive data from being sent to an unauthorized destination. The SIEM can correlate identity, e-mail and endpoint events.

For this reason:

**"Because it is a human attack technology cannot solve it."**

this approach is not correct.

The correct approach is to design the human and technology layers together.

### Identity Security

An important part of social engineering attacks results in identity compromise.

For this reason:

MFA,

phishing-resistant authentication,

conditional access,

session monitoring,

privileged access control

are critical defense layers.

The password reset and MFA reset processes in particular need to contain strong verification.

### Endpoint Security

If the social engineering attack persuades the user to run a malicious file, endpoint security comes into play.

EDR;

process execution,

network connections,

suspicious script activity

can detect the attack through behaviours such as these.

For this reason even if the user makes the wrong decision the endpoint provides another defense layer.

### DLP and Data Sharing

In a social engineering attack the attacker can ask the user to send a sensitive document.

DLP can in this case control the data transfer using classification and content inspection.

For example when restricted data is being sent to an external e-mail recipient additional approval or blocking can be applied.

This too can prevent human error from turning into a data breach.

### SIEM and SOC

When a compromise occurs after social engineering different security signals can emerge.

For example:

an unexpected MFA,

a new device login,

a mailbox forwarding rule,

an endpoint alert,

an unusual file download

these can be associated with the same user.

While the SIEM correlates these events the SOC can investigate whether the event is a real incident.

### How Should Social Engineering Incident Response Be?

When a user reports a suspicious social engineering interaction, first of all which information was shared and which operations were performed must be determined.

There may only have been a telephone call.

Credentials may have been shared.

MFA may have been approved.

A file may have been opened.

A bank account change may have been made.

In each case the response is different.

The basic process:

**Detect → Validate → Contain → Investigate → Recover → Learn**

can progress in this way.

### If the User Shared Credentials

A password reset alone is not always sufficient.

Active sessions and tokens must be revoked, authentication logs must be examined and whether mailbox access occurred must be checked.

If there is suspicious activity on the endpoint an EDR investigation must be carried out.

### If MFA Was Approved

If an unexpected MFA request has been approved the possibility of account compromise must be evaluated.

Identity logs, the login source, session activity and account changes must be examined.

### If a Financial Transaction Took Place

Alongside the cyber security team, finance, legal and the relevant business stakeholders must be brought in quickly.

Banking processes and fraud response procedures must be included in the organization's incident playbook.

### If Physical Access Was Obtained

Badge logs, CCTV records, visitor records and the relevant area access activity must be examined.

Which physical systems or documents the suspicious person may have reached must be determined.

### What Is a Social Engineering Simulation?

Organizations can test the user and process resistance level with authorized simulation exercises.

Phishing simulation is the most widespread example but it is not limited to e-mail only.

In an authorized and controlled way, help desk verification, physical access procedures or voice social engineering scenarios can also be evaluated.

The aim of these exercises is not to "catch" the employee but:

**to find process weaknesses.**

### What Should Be Looked At in the Simulation Results?

Looking only at whether the user made a mistake is not correct.

For example the following questions are more valuable:

Did the user report the suspicious request?

Did the help desk apply the procedure?

Did finance ask for a second approval?

Did the SOC receive a notification?

How quickly did the security team respond?

In this way the test moves beyond user performance and becomes enterprise security control validation.

### Why Is Security Culture Important?

If the user thinks they will be punished when they make a mistake they can hide the incident.

This situation lengthens the security team's response time.

A good security culture must give the user the message:

"If you have seen something suspicious report it immediately."

it must give this message.

The faster the user reports, the faster attack containment can be performed.

### Mean Time to Report

Mean Time to Report is the period between the user seeing suspicious activity and reporting it to the security team.

This metric is quite valuable for human security programs.

Because a successful security culture is created not only by the user who does not fall for the attack but by:

**the user who reports the attack quickly**

this user creates it.

### The Most Frequently Made Mistakes in Social Engineering

One of the important mistakes organizations make is handling social engineering only as phishing training.

Yet the risk extends from the help desk to the finance processes, from physical access to identity reset processes.

Among the other important mistakes:

- leaving critical operations to a single person,
- using weak verification for password/MFA reset,
- accepting a telephone call as trustworthy identity verification,
- seeing internal e-mail as automatically trusted,
- not verifying vendor bank account changes independently,
- processing executive requests outside the process,
- not applying physical visitor procedures,
- making the user reporting process difficult,
- not performing social engineering simulations,
- not customizing awareness training according to role

these can be counted.

### Social Engineering Security Checklist

Organizations can regularly evaluate the following questions:

- Is the help desk identity verification process strong?
- Do MFA reset operations require approval?
- Are password resets being audited?
- Does finance use dual approval for a payment change?
- Are vendor bank account changes verified out-of-band?
- Can executive requests be carried out outside the standard process?
- Is phishing-resistant MFA being used?
- Is the user reporting channel easy?
- Is visitor management being applied?
- Is badge sharing forbidden and monitored?
- Is security awareness role-based?
- Are there special scenarios for finance, HR and IT?
- Are social engineering simulations being applied?
- Are identity logs being sent to the SIEM?
- Are suspicious MFA and mailbox events being monitored?
- Does the incident response playbook cover social engineering?

### The Social Engineering Maturity Model

#### Level 1 - Basic Awareness

Annual security awareness training is given to users but the process controls are limited.

#### Level 2 - Controlled Business Processes

Verification mechanisms are created in critical processes such as payment approval, password reset and visitor access.

#### Level 3 - Role-Based Human Security

Special awareness programs are applied for high-risk roles such as finance, executive, HR and IT.

#### Level 4 - Integrated Human Risk Management

Identity, endpoint, e-mail, DLP and SIEM data are evaluated together with the user risk context.

#### Level 5 - Adaptive Human Risk Security

Controls are strengthened dynamically according to the user, device, identity and behaviour risk and the processes are continuously tested.

### Frequently Asked Questions

#### What is social engineering?

Social engineering is the attack method that aims to obtain information, access or an operation by manipulating human psychology and business processes.

#### Are Social Engineering and phishing the same thing?

No. Phishing is one of the social engineering methods. Social engineering covers many methods such as the telephone, physical access, impersonation, pretexting, baiting and business process manipulation.

#### What is pretexting?

It is the attacker creating a convincing story or identity in order to gain trust.

#### What is baiting?

It is trying to make the user perform a particular action by offering them attractive content or content that arouses curiosity.

#### What is tailgating?

It is an unauthorized person entering a controlled physical area by following an authorized employee.

#### What is Help Desk Social Engineering?

It is the help desk employee being manipulated into performing operations such as a password reset, an MFA reset or an account unlock.

#### Does MFA prevent social engineering attacks?

It can reduce the risk significantly but in situations such as MFA fatigue or weak MFA reset processes it is not sufficient on its own.

#### Can deepfake be used in social engineering?

Yes. Voice or video imitation can make impersonation attacks more convincing.

#### What is Out-of-Band Verification?

It is the request being checked over another previously verified channel different from the communication channel it came from.

#### Can a social engineering attack succeed without a technical weakness?

Yes. By manipulating the user or the process, access or an operation can be obtained without using any software vulnerability.

#### What is the strongest protection against social engineering?

There is no single control. Security awareness, strong identity verification, process verification, least privilege, technical monitoring and incident response must be used together.

### Conclusion: In Social Engineering the Real Target Is Not the Person but the Decision Mechanism

When social engineering is mentioned most organizations look for the solution in telling the user:

**"Be careful."**

in saying this.

However, this is not sufficient on its own.

Because the attacker takes advantage of the natural characteristics of human behaviour.

People:

want to help,

trust their managers,

act quickly in urgent situations,

may not question the requests of people they know.

It is not possible to eliminate all of these behaviours.

For this reason the goal of a strong social engineering defense model is:

**not to change the human being but to support critical decisions with secure processes.**

The user can be deceived.

But the payment process can ask for a second approval.

Help desk personnel can make a mistake.

But an MFA reset can require strong identity verification.

The user can open a malicious file.

But EDR can stop the execution.

The user can try to send a sensitive document.

But DLP can block the transfer.

The attacker can obtain a credential.

But phishing-resistant MFA can make account takeover more difficult.

For this reason the fundamental equation of modern social engineering defense:

**Awareness + Identity Verification + Process Control + Technical Protection + Detection + Response**

is in this form.

And the most critical principle is this:

**Do not make human error the single failure point in the security architecture.**

Because a real security culture is not expecting flawless behaviour from the user but ensuring that the organization continues to be protected even when the user makes the wrong decision.
