Social Engineering & Fraud

Social Engineering & Fraud Persuasion Techniques

Phishing, pretexting, impersonation, romance and investment scams, and the pressure patterns behind them. These entries are written for recognition and defense: what the target experiences, the tells, and what to do — never an operator's playbook.

36 techniques in this category

Phishing

Mass-distributed fraudulent messages, usually email, that impersonate a trusted organization to trick recipients into clicking a malicious link, opening an attachment, or entering credentials on a counterfeit site.

Spear-Phishing

A targeted phishing message crafted for a specific person or small group using details harvested from public sources, prior breaches, or the target's own social media, so that the request arrives looking like ordinary business.

Whaling

Spear-phishing aimed at senior executives, board members, or the staff who act on their behalf, exploiting the fact that a request made in the chief executive's name is rarely questioned.

Business Email Compromise (BEC)

A fraud in which an attacker uses a compromised or spoofed business email account to redirect legitimate payments, typically by changing the bank details on a real invoice or requesting a plausible transfer.

Vishing (Voice Phishing)

A phone call, often with a spoofed caller ID, in which the caller impersonates a bank, government agency, help desk, or vendor to extract information, credentials, or payments in real time.

Smishing (SMS Phishing)

Short text messages that impersonate a bank, delivery service, toll authority, or employer and push the recipient to tap a link or reply with information.

Pretexting

Inventing a plausible scenario and identity (the pretext) that gives an attacker a legitimate-seeming reason to ask for information or access, so that the target's cooperation feels like ordinary helpfulness rather than a security decision.

Baiting

Leaving or offering something the target wants (a found USB drive, free software, a media download, a plausible "lost" document) that carries a hidden payload, so that curiosity or self-interest does the attacker's work.

Quid Pro Quo Social Engineering

An attacker offers a service or benefit (help with a computer problem, a survey reward, a gift, a "free" upgrade) in exchange for information or actions that grant access, relying on the norm that a favor deserves a return.

Tailgating / Piggybacking

Gaining entry to a restricted physical space by following an authorized person through a controlled door, relying on ordinary courtesy and the reluctance to challenge a stranger who looks like they belong.

Elicitation

Steering an ordinary-seeming conversation so that a target reveals sensitive information without ever being directly asked for it, and usually without realizing anything was extracted.

Reverse Social Engineering

The attacker arranges for the target to come to them for help, so that the request originates with the victim and any information handed over feels freely given rather than extracted.

Authority Impersonation Scam

A fraud in which the contact claims to be a government agency, law-enforcement body, bank, or well-known company and uses the borrowed weight of that institution to demand payment or personal information.

Tech Support Scam

A fraud in which the target is convinced their device is infected or compromised and that a fake "support" agent must be given remote access or payment to fix it.

Romance Scam

A fraud in which the criminal builds a fake romantic relationship over weeks or months, then leverages the emotional bond to extract money, gifts, or laundering assistance.

Pig-Butchering Scam

A hybrid romance-and-investment fraud in which the criminal cultivates a relationship, introduces a fake cryptocurrency or trading platform showing false gains, and drains the victim of ever-larger deposits.

Grandparent Scam

A fraud in which a caller poses as a grandchild (or an authority acting for them) in sudden trouble, using panic and secrecy to rush an older person into sending cash, gift cards, or a courier payment.

Advance-Fee Fraud

A scam that promises a large future payout (an inheritance, lottery win, business commission, or trapped fortune) but requires the victim to pay a series of upfront fees that never unlock the promised money.

Affinity Fraud

An investment or Ponzi scam that targets members of a tight community (a religious congregation, ethnic group, profession, or social club) by exploiting the shared identity and internal trust of the group.

Pump-and-Dump Hype

A market-manipulation scheme in which promoters inflate the price of a thinly traded stock or token through coordinated hype, then sell their holdings into the buying frenzy, collapsing the price on everyone else.

MLM Recruitment Pitch

The persuasion script used to recruit multi-level-marketing distributors, which reframes a low-odds income proposition as entrepreneurship, community, and personal growth while obscuring that most participants lose money.

Invoice Fraud

A scam that inserts a fake or altered invoice into an organization's or individual's normal payment flow, so that a routine-looking bill diverts money to the fraudster.

Voice-Cloning Scam

A fraud that uses AI-synthesized audio of a real person's voice, built from a short sample, to impersonate a relative, executive, or official and trigger urgent payments or disclosures.

Credential Harvesting

The collection of usernames, passwords, and authentication codes at scale, typically through counterfeit login pages, so that stolen credentials can be used or resold for account takeover.

Sextortion

Extortion in which the offender threatens to publish sexual images of the victim, real or fabricated, unless the victim pays money or provides more images; financial sextortion targeting teenagers has become widespread and has been linked to suicides.

Job and Task Scam

A fraud built around fake employment: bogus job offers that harvest data or fees, and "task" or gig scams that pay tiny rewards to build trust before requiring the victim to deposit their own money.

Disaster and Charity Scam

A fraud that exploits compassion after disasters, illnesses, or for popular causes, soliciting donations for fake charities or diverting nearly all funds to the operators rather than the cause.

Fake Verification Badge

Exploiting trust markers, such as a platform "verified" checkmark, security padlock, seller rating, or app-store badge, to make a fraudulent account or site appear authoritative when the marker is bought, faked, or misunderstood.

Ponzi Dynamics

The self-sustaining illusion of a profitable investment created by paying existing investors with new investors' money, so that apparent returns and word-of-mouth mask a fund that produces nothing and must eventually collapse.

Overpayment Scam

A fraud in which the scammer "pays" a victim more than an agreed amount with a fake or reversible instrument, then asks for the difference back before the payment is discovered to be worthless.

Account Suspension Lure

A phishing pretext claiming that an account will be suspended, locked, or deleted unless the recipient acts immediately, driving them to a counterfeit login or payment page.

Package Delivery Lure

A phishing message posing as a postal or courier service claiming a delivery problem (a held package, an address issue, a small fee due) to harvest payment details or credentials.

Long-Con Trust-Building

An extended fraud that invests weeks, months, or years in building genuine-feeling trust and rapport before any request for money, so that when the ask comes it is granted almost automatically.

Scam Triad: Urgency, Authority, Secrecy

The recurring three-part pattern beneath most scams: manufactured urgency to prevent thought, borrowed authority to compel compliance, and enforced secrecy to block the outside check that would break the spell.

SIM-Swap Fraud

Social engineering of a mobile carrier (or a bribed insider) to transfer a victim's phone number to the attacker's SIM, intercepting calls and texts, including the one-time codes that guard bank and crypto accounts.

MFA Fatigue Attack

An account takeover in which an attacker who already has a password floods the victim with repeated multi-factor push notifications, wearing them down or confusing them into approving one.