Better Safe Than Sorry

Scams, recalls, safety. Sorted.

Digital hygiene

Recognising Social Engineering Tactics

Launch library · evergreen read

Photo: Umbrella Street Camden Town by Celsoazevedo (CC BY 4.0), via Openverse

Social engineering relies on manipulating people rather than exploiting technical weaknesses, using trust, urgency or authority to convince someone to reveal information or take an action they would not normally consider under ordinary circumstances at all. The technology involved matters far less than the psychology being used.

A caller pretending to be from an organisation's IT department, asking for a password to "verify" an account, is a classic example, relying on the assumed authority of the role rather than any genuine technical need for that specific information. This particular script recurs constantly across many completely unrelated scams.

Recognising that legitimate organisations rarely need to ask for a password directly, since proper systems verify identity without requiring it to be spoken aloud or typed into an unfamiliar form, helps identify this particular pattern. Knowing this in advance makes the request feel obviously wrong immediately.

Slowing down and verifying independently, through a separate, trusted channel, before providing any sensitive information in response to an unexpected request, defeats most social engineering attempts regardless of how genuinely convincing they seem. This single habit alone stops the vast majority of these attempts cold.

Back to the library

Share

Sharing opens the network in a new tab. No tracking scripts are loaded on this page.

Printed from Better Safe Than Sorry. Sources for this article are listed at the end of the page.