What Is Social Engineering and How Hackers Use It Online
Patrick Bushe
September 23, 2024 · 5 min read
Social engineering means manipulating people into giving away information or access, instead of breaking through technical defenses. It works because it targets trust, helpfulness, fear and urgency, which software can't patch.
Common techniques
- Phishing: emails that look like they're from a bank, delivery company or colleague, with a link to a fake sign-in page.
- Smishing and vishing: the same trick by text message or phone call.
- Pretexting: inventing a believable story, such as "I'm from IT and need to verify your account."
- MFA fatigue: flooding someone with sign-in approval prompts until they tap "approve" to make it stop.
- Baiting: leaving infected USB drives or offering free downloads.
- Fake fixes: pages showing a fake error or check that tell you to copy and run a command on your computer.
Real examples
- Uber, 2022: an attacker with a contractor's password sent repeated sign-in prompts, then messaged the contractor pretending to be Uber IT and asked them to approve one.
- MGM Resorts, 2023: attackers reportedly called the company's IT help desk pretending to be an employee and got access reset, leading to a costly outage.
Warning signs
- Urgency or threats: "your account will be closed today."
- Requests to bypass normal process.
- Requests for passwords, codes or remote access.
- Sign-in prompts you didn't start.
- Instructions to paste something into a Run box, terminal or console.
Habits that stop it
- Verify through a separate channel: call back on a number you already know, not one in the message.
- Never share sign-in codes. Real companies don't ask for them.
- Deny prompts you didn't start, and report them.
- Use phishing-resistant sign-in such as passkeys or security keys. See two-factor authentication.
- Never run commands a website tells you to paste.
- Slow down: pressure is the attacker's main tool.
For businesses
- Help desks should verify identity carefully before resetting passwords or sign-in methods.
- Make reporting easy and blame-free.
- Run regular, realistic training.
The clipboard
Some scam pages try to read what you've copied, such as passwords or codes. Clipboard Guard blocks websites from reading your clipboard. It doesn't stop a page from putting text on your clipboard, so the "never paste commands" rule still matters. See spotting fake websites and clipboard hijacking.