Elicitation
What it is
Steering an ordinary-seeming conversation so that a target reveals sensitive information without ever being directly asked for it, and usually without realizing anything was extracted.
How it works
Real-world examples
- •At a conference bar, a friendly stranger complains that "nobody really uses multi-factor anyway," prompting an engineer to proudly explain exactly which systems his company protects and how.
- •A caller feigns confusion about a company's org chart, and a helpful employee corrects the "mistakes," confirming names, roles, and reporting lines useful for a later impersonation.
- •Intelligence tradecraft has long used the deliberate wrong statement, because a specialist will often reveal classified nuance simply to correct an error.
- •A recruiter-style chat that praises a candidate's current project draws out architecture and security details the candidate would never have volunteered to a stranger who asked directly.
Ethical guidelines
- ●Extracting information a person would withhold if they understood the purpose is deceptive, even when no question is ever asked outright.
- ●Journalists, researchers, and investigators should disclose their role when soliciting information that a source would guard if they knew who was listening.
- ●Authorized elicitation in security assessments must stay within a signed scope and must not target individuals' private lives to build leverage.
How to defend against it
- ►Notice interest that is out of proportion to the relationship: a new acquaintance steering repeatedly toward your work internals is a tell, not a compliment.
- ►Decide in advance what you will not discuss with people outside a need-to-know, so the choice is made before flattery or rapport can move it.
- ►When a statement invites you to correct it with sensitive detail, you can simply not take the bait: "I couldn't say" is a complete answer.
- ►Be wary when praise arrives bundled with questions; the ego lift is doing the work of the interrogation.
- ►For organizations, teach staff the common conversational moves by name, since recognizing the pattern (Persuasion Knowledge) is what breaks its power.
From the Defense Playbook
Every playbook entry states how strong its evidence is and when not to use it. Browse the full playbook.
References
- Hadnagy, C. (2018). Social Engineering: The Science of Human Hacking (2nd ed.). WileyCatalog of conversational elicitation moves (deliberate false statement, feigned ignorance, flattery) and their recognition signals.
- Mitnick, K. D., & Simon, W. L. (2002). The Art of Deception: Controlling the Human Element of Security. WileyCase studies of piecing together sensitive information from individually harmless disclosures across friendly conversations.
- Stajano, F., & Wilson, P. (2011). Understanding scam victims: seven principles for systems security. Communications of the ACM, 54(3), 70-75 · linkGeneral principles (herd, kindness, need-and-greed) that explain why targets volunteer information to a plausible stranger.
Related Articles
Social Engineering: Why Smart People Fall for It
Social engineering does not target stupidity. It targets helpfulness, deference, and time pressure, which are the same habits that make people good at their jobs. Here is how the attacks are built and which procedures actually stop them.
The Disinformation Playbook: How Campaigns Are Built and Where They Break
Disinformation campaigns follow a recognizable sequence: seed, launder, amplify, and let real people carry it the rest of the way. A field guide to the stages, drawn from the research, with the defences that work at each one.