Skip to content

Social Engineering

Social engineering bypasses encryption, MFA, and most technical controls by targeting the human. It is still the most effective initial-access technique used by both nation-state and criminal actors — including against communities that otherwise practice strong digital hygiene.

“Phishing remains one of the most unsophisticated, yet effective means of cyber compromise, often rendering other protections irrelevant including end-to-end encryption.”FBI/CISA PSA I-032026, March 2026

Across vectors, social engineering attacks share a recognizable shape:

  1. Pretext — actor establishes a context (impersonates a contact, a “support” account, a service, a deadline)
  2. Urgency — manufactured time pressure (“suspicious activity detected,” “your account will be locked”)
  3. Authority — claim to represent something official (Signal Security, IT department, FBI, a known executive)
  4. Action — request the victim do something they wouldn’t normally do (type a code, click a link, scan a QR, install an app, transfer money, run a script)
  5. Quiet — instruct the victim not to verify out-of-band (“don’t tell anyone, including Signal employees”)

If a message hits 3 or more of these in a row, treat it as phishing until proven otherwise.

The general Phishing — Defender’s Guide covers all of the below at a working level. Dedicated sub-vector pages will be split out as content depth justifies it. Contributions welcome.

  • Smishing — SMS phishing, common lures, carrier reporting channels (covered in the general phishing guide)
  • Vishing — voice phishing, AI-cloned voice, callback scams (covered in the general phishing guide)
  • QR code phishing (quishing) — physical and digital QR-based lures (covered in the general phishing guide)
  • Verification code theft — the “read me the code your bank just sent” pattern (see also the Signal/RIS page)
  • Impersonation — fake executive / fake contact / fake support
  • Business email compromise — wire-fraud and invoice-redirect schemes