There's an old line in security, usually attributed to famous ex-hackers: why spend weeks breaking encryption when a five-minute phone call gets the password? Social engineering is that idea taken seriously — attacking the humans who operate a system instead of the system itself. Phishing (earlier on this trail) is its most industrialised form, but the family is wider, older, and works face-to-face just as well as by email.
The core exploit: helpfulness
Here's the uncomfortable insight the whole field rests on: the qualities organisations hire for — helpfulness, politeness, deference to authority, desire to avoid friction — are precisely the attack surface. Nobody wants to be the person who made the visiting "engineer" wait in the rain, challenged someone senior-sounding, or refused the stressed caller begging for a password reset before a deadline. Social engineers don't defeat your defences; they recruit your virtues.
The recurring plays
- Pretexting — the foundation of everything: a researched, plausible false identity and scenario. "Hi, it's Dave from the Manchester office IT team — Sarah said you could help me…" The named colleagues are real (LinkedIn is free), the situation is mundane, and the request comes wrapped in enough true detail that the false part slides through.
- Tailgating — following an employee through a secured door, usually by carrying a box (people hold doors for full hands), wearing a hi-vis vest, or just walking with confidence. Physical access is catastrophic access: an unattended meeting room with a network port is an attacker's dream.
- Baiting — leaving something curiosity-poisoned where victims will find it. The classic USB stick labelled "Redundancies 2026" in the car park still works, which is why corporate machines increasingly block unknown USB devices outright.
- Quid pro quo — offering something to create obligation: "helpful IT support" calling to fix a problem you didn't know you had, needing only your credentials to complete the fix.
The defence pattern is the same one from the phishing post, generalised: verify through a channel the requester doesn't control. Call back on the known number. Check with the named colleague directly. Ask the visitor's escort to confirm. Attackers script the channel they chose — a second channel breaks the script. Good organisations make this normal by policy, so no individual has to feel rude enforcing it.
That last point is the real lesson for your career: social engineering is beaten by process, not vigilance. Payment changes that require callbacks. Visitor policies that require escorts. Helpdesks that verify identity the same way for the CEO as for anyone (executives are targeted more, not less). When you see those rules and they feel like friction — they are. They're friction aimed at exactly the attacks that politeness lets through.