securitymanipulationpsychologyinfluencecritical-thinking

Social Engineering: Why Smart People Fall for It

By Persuasion Lab2026-09-127 min read

After a successful phishing attack, the first question people ask is usually some version of "how could anyone fall for that?" It is the wrong question, and it makes organizations less safe. Social engineering, the practice of getting people to hand over access, money, or information by manipulating them rather than by breaking software, does not work because its targets are foolish. It works because its targets are cooperative, busy, and reasonably trusting, which is to say, because they are behaving the way functional colleagues and customers are supposed to behave.

Kevin Mitnick, who spent years talking his way into telephone and computer companies before becoming a security consultant, made the point bluntly in The Art of Deception: an attacker who can simply ask for a password has little need to crack it. Two decades later the FBI Internet Crime Complaint Center still reports phishing and its variants as the most frequently reported crime type, and business email compromise as one of the costliest, with reported losses of roughly $2.9 billion in its 2023 report. These are not exotic technical intrusions. They are conversations.

The attack is a story, not a trick

Christopher Hadnagy, whose book Social Engineering: The Science of Human Hacking is the closest thing the field has to a textbook, describes attacks as built around a pretext: an invented identity and situation that makes the request feel routine. The caller is from the IT help desk and needs to verify your account before a migration. The email is from the chief executive, who is boarding a plane and needs a wire sent before the close of business. The visitor in the high-visibility vest is here about the fire extinguishers. None of these scenarios asks the target to do something that feels strange. That is the design goal. A good pretext places the request inside a script the target has run a hundred times before.

The preparation is usually done in the open. Staff directories, professional networking profiles, press releases, and out-of-office replies tell an attacker who reports to whom, who is travelling, which vendors the company uses, and what internal jargon sounds like. A message that names your actual manager and your actual invoicing system is not evidence that the sender is legitimate. It is evidence that the sender can read.

Which levers are being pulled

Robert Cialdini's principles of influence were derived from watching compliance professionals such as salespeople and fundraisers, but they map closely onto the social engineer's toolkit. Three do most of the work.

  • Authority. People defer to legitimate authority for good reasons, and organizations depend on that deference. Attackers borrow it by impersonating executives, auditors, police, tax agencies, or the bank fraud department. The signal being faked is often trivially cheap: a title, a display name, a confident tone, a uniform.
  • Urgency and scarcity. Deadlines narrow attention. Research on the mere-urgency effect shows that people tend to prioritize tasks that are merely time-limited over tasks that matter more. A request that must be completed in the next twenty minutes crowds out the thought "I should check this."
  • Reciprocity and liking. The attacker who first helps you, by "fixing" a problem they created, or who is simply pleasant and apologetic about bothering you, has made refusal feel rude. Hadnagy notes that most successful pretexts are friendly, not threatening.

Fraud-prevention practitioners often summarize the consumer-scam version as a triad: urgency, authority, and secrecy. Secrecy is the tell that deserves the most attention. "Do not discuss this with anyone, the acquisition is confidential." "Stay on the line and do not tell the bank teller what the withdrawal is for." A legitimate process almost never requires that you avoid talking to the people around you. The instruction exists to cut you off from the one thing that reliably breaks the spell, which is a second person saying "that sounds odd."

Why intelligence and training are weak protection

Studies of phishing susceptibility point to attention and habit more than to intellect. Vishwanath and colleagues found that people who fell for a simulated phish tended to process the message through a few surface cues, such as the sender name, the subject line, and the urgency, and that heavy habitual email use made this shallow processing more likely. That is not a character flaw. Nobody can give forensic attention to two hundred messages a day. Attackers simply need one message to arrive at a moment when you are clearing a backlog on your phone between meetings.

Expertise can make things worse in a specific way: experienced staff have well-worn routines, and a request that fits the routine is approved on autopilot. Seniority also matters. Executives are heavily targeted by spear phishing because they hold authority to approve payments and are often exempted, formally or informally, from the controls that apply to everyone else. And confidence is its own exposure. The person who is sure they would never fall for a scam has less reason to follow a verification step that feels insulting to their judgment.

This is the argument against treating victims as careless. An organization that shames the employee who clicked teaches everyone else to hide their clicks, and delayed reporting is what turns a contained incident into a breach.

Defenses that work are procedures, not vigilance

"Be more careful" is not a control. The defenses that hold up are the ones that do not depend on anyone spotting the lie in the moment.

  • Verify out of band. When a request involves money, credentials, or sensitive data, confirm it through a channel you chose, not one supplied in the message. Call the vendor on the number in your own records. Call the bank on the number printed on your card. Walk to the executive's office or use the internal chat. This single habit defeats most business email compromise and most phone-based fraud.
  • Treat any change of payment details as a red flag by policy. New bank account for an existing supplier means a callback and a second approver, every time, with no exception for urgency or seniority. Attackers rely on the exception.
  • Make "no" and "let me check" socially safe. Staff should be able to tell a caller claiming to be a vice president "I will call you back through the switchboard" without fearing a reprimand. Mitnick argued that policies are only effective when employees know that following them will be backed even if the caller turns out to be genuine and annoyed.
  • Use technical backstops. Phishing-resistant multi-factor authentication such as hardware security keys or passkeys means a stolen password is not enough. Never read a one-time code to someone who called you; legitimate services do not ask for it.
  • Agree on a family protocol. For the "relative in trouble" call, which voice cloning has made more convincing, agree in advance on a question or phrase that only the family knows, and hang up and call the person directly before sending anything.
  • Reward fast reporting. The measure of a healthy program is not how few people click a simulated phish. It is how quickly a real one gets reported, including by the person who clicked.

A thirty-second check

When a message or call leaves you feeling that you must act now, ask three questions. Did I initiate this contact, or did it come to me? Is the channel for verifying it one that I picked? Is anyone discouraging me from pausing or consulting someone else? If the answers are "it came to me," "no," and "yes," stop. A real deadline survives a five-minute callback. A fraudulent one does not, and that asymmetry is the most useful fact in this entire field.

For more on the individual tactics, see the encyclopedia entries on phishing, elicitation, and tailgating, and the practical playbooks under Defenses. If you want to test a suspicious message against known manipulation patterns, try pasting it into the detector.

References

  1. Hadnagy, C. (2018). Social Engineering: The Science of Human Hacking (2nd ed.). Wiley
    Framework of pretexting, information gathering from open sources, and the observation that effective pretexts are usually friendly and routine rather than threatening.
  2. Mitnick, K. D., & Simon, W. L. (2002). The Art of Deception: Controlling the Human Element of Security. Wiley
    The claim that asking for access is often easier than technical intrusion, and the recommendation that verification policies must be backed by management to be effective.
  3. Cialdini, R. B. (2021). Influence, New and Expanded: The Psychology of Persuasion. Harper Business
    The principles of authority, scarcity, reciprocity, and liking that the post maps onto social-engineering tactics.
  4. Federal Bureau of Investigation, Internet Crime Complaint Center (IC3) (2024). Internet Crime Report 2023. FBI IC3
    Phishing as the most frequently reported crime type and business email compromise losses of roughly $2.9 billion reported for 2023. Figures reflect complaints filed with IC3 and understate total losses.
  5. Vishwanath, A., Herath, T., Chen, R., Wang, J., & Rao, H. R. (2011). Why do people get phished? Testing individual differences in phishing vulnerability within an integrated, information processing model. Decision Support Systems, 51(3), 576–586
    Finding that phishing victims tend to rely on surface cues such as sender, subject line, and urgency, and that habitual media use increases shallow processing.
  6. Zhu, M., Yang, Y., & Hsee, C. K. (2018). The mere urgency effect. Journal of Consumer Research, 45(3), 673–690
    Experimental evidence that people prioritize time-limited tasks over more important ones, which underlies the urgency lever.
Last reviewed
Suggest a correction

Share this article

Related Persuasion Techniques

Want to practice these techniques?

Persuasion Lab lets you roleplay scenarios, analyze messaging, and defend against manipulation with AI.

Try Persuasion Lab Free