Pretexting
What it is
Inventing a plausible scenario and identity (the pretext) that gives an attacker a legitimate-seeming reason to ask for information or access, so that the target's cooperation feels like ordinary helpfulness rather than a security decision.
How it works
Real-world examples
- •In 2006 investigators hired by Hewlett-Packard obtained board members' and journalists' phone records by calling carriers while posing as the account holders; the scandal led to the U.S. Telephone Records and Privacy Protection Act of 2006.
- •The Gramm-Leach-Bliley Act of 1999 specifically outlaws obtaining customer financial information by false pretenses, a response to "information brokers" who phoned banks impersonating customers.
- •A caller posing as a new IT contractor asks reception for the name of the VPN vendor and the badge format "so my paperwork matches"; each answer becomes a prop for the next call.
- •Attackers phone a company's support line pretending to be the customer, armed with a date of birth and the last four digits of a card from a data breach, and ask to "update the email on file", which quietly hands them control of the account.
Ethical guidelines
- ●Lying about who you are to obtain information someone would not give you knowingly is deception by definition; in finance and telecommunications it is also a specific federal offense.
- ●Authorized social-engineering assessments must have written scope, must avoid impersonating law enforcement or emergency services, and must debrief the people who were tested.
- ●Journalists and investigators face the same line: the public interest does not license impersonation, and most press codes prohibit it except in narrow, documented circumstances.
How to defend against it
- ►Adopt one rule: identity is verified by something the caller cannot supply. Call them back at a number from the directory, or ask for a ticket number and look it up yourself.
- ►Be alert to callers who volunteer credibility details unprompted (a manager's name, an employee ID, insider jargon); real colleagues rarely narrate their own legitimacy.
- ►Notice pressure disguised as courtesy: "I know you are busy, this will only take a second" is designed to keep you from pausing to check.
- ►It is acceptable to say "I cannot give that out over the phone, but I can send it to the address we have on file." Legitimate callers accept that; pretexters push.
- ►Organizations should publish which information staff may never share by phone (passwords, MFA codes, network details, personal data) so employees do not have to judge each case alone.
From the Defense Playbook
Confirm any request that arrives through one channel (email, text, chat, a phone call) by reaching the supposed sender through a different channel you already trusted before the request existed.
When anyone contacts you claiming to be your bank, a government agency, a utility, or a company you deal with, hang up and call back on the number printed on your card, statement, or the organization's official website, never the number they gave you.
No bank, agency, or company will ever ask you to move, withdraw, convert, or hand over your money to keep it safe, so any such request identifies the person making it as the threat.
Separate the symbols of authority (a title, a uniform, a badge, a confident tone, an official-looking letterhead) from the fact of authority, and check the fact through a source the claimant does not control before you comply.
Turn on a second factor for every account that matters and prefer phishing-resistant forms (passkeys or hardware security keys), so that a password typed into a fake page or talked out of you on the phone is not enough to take the account.
Answer an intrusive, oddly specific, or out-of-place question with a friendly question of your own about its purpose, which buys time, reveals intent, and breaks the reflex to answer simply because you were asked.
Every playbook entry states how strong its evidence is and when not to use it. Browse the full playbook.
References
- Mitnick, K. D., & Simon, W. L. (2002). The Art of Deception: Controlling the Human Element of Security. WileyFirst-person account of pretext-based intrusions and the principle that requests framed as routine escape scrutiny.
- Workman, M. (2008). Wisecrackers: A theory-grounded investigation of phishing and pretext social engineering threats to information security. Journal of the American Society for Information Science and Technology, 59(4), 662-674 · linkField study finding that trust, normative pressure, and commitment predict compliance with pretext social engineering.
- Hadnagy, C. (2018). Social Engineering: The Science of Human Hacking (2nd ed.). WileyPractitioner treatment of pretext construction and the role of rapport and small truths in gaining compliance.
Related Articles
Social Engineering: Why Smart People Fall for It
Social engineering does not target stupidity. It targets helpfulness, deference, and time pressure, which are the same habits that make people good at their jobs. Here is how the attacks are built and which procedures actually stop them.
The Disinformation Playbook: How Campaigns Are Built and Where They Break
Disinformation campaigns follow a recognizable sequence: seed, launder, amplify, and let real people carry it the rest of the way. A field guide to the stages, drawn from the research, with the defences that work at each one.