Social Engineering & FraudMANIPULATIVE

Pretexting

What it is

Inventing a plausible scenario and identity (the pretext) that gives an attacker a legitimate-seeming reason to ask for information or access, so that the target's cooperation feels like ordinary helpfulness rather than a security decision.

How it works

A pretext works because it supplies the answer to the question the target would otherwise ask: why is this person asking me this? A caller who says "this is Dana from the audit team, we are reconciling vendor records before the quarter closes" has framed the interaction as routine, borrowed authority from a real process, and made refusal feel obstructive. Good pretexts are built from small, checkable truths (real names from the website, real project jargon, a real recent event) so that the one false element rides in on the credibility of the rest. Kevin Mitnick, whose intrusions in the 1980s and 1990s relied more on pretext calls than on code, described the method as making the request so ordinary that the target never notices a decision was made. Workman's 2008 field study found that the same factors that predict successful marketing (trust, normative pressure, commitment) predicted who complied with pretext requests, which is why the effective defense is a rule rather than a feeling.

Real-world examples

  • In 2006 investigators hired by Hewlett-Packard obtained board members' and journalists' phone records by calling carriers while posing as the account holders; the scandal led to the U.S. Telephone Records and Privacy Protection Act of 2006.
  • The Gramm-Leach-Bliley Act of 1999 specifically outlaws obtaining customer financial information by false pretenses, a response to "information brokers" who phoned banks impersonating customers.
  • A caller posing as a new IT contractor asks reception for the name of the VPN vendor and the badge format "so my paperwork matches"; each answer becomes a prop for the next call.
  • Attackers phone a company's support line pretending to be the customer, armed with a date of birth and the last four digits of a card from a data breach, and ask to "update the email on file", which quietly hands them control of the account.

Ethical guidelines

  • Lying about who you are to obtain information someone would not give you knowingly is deception by definition; in finance and telecommunications it is also a specific federal offense.
  • Authorized social-engineering assessments must have written scope, must avoid impersonating law enforcement or emergency services, and must debrief the people who were tested.
  • Journalists and investigators face the same line: the public interest does not license impersonation, and most press codes prohibit it except in narrow, documented circumstances.

How to defend against it

  • Adopt one rule: identity is verified by something the caller cannot supply. Call them back at a number from the directory, or ask for a ticket number and look it up yourself.
  • Be alert to callers who volunteer credibility details unprompted (a manager's name, an employee ID, insider jargon); real colleagues rarely narrate their own legitimacy.
  • Notice pressure disguised as courtesy: "I know you are busy, this will only take a second" is designed to keep you from pausing to check.
  • It is acceptable to say "I cannot give that out over the phone, but I can send it to the address we have on file." Legitimate callers accept that; pretexters push.
  • Organizations should publish which information staff may never share by phone (passwords, MFA codes, network details, personal data) so employees do not have to judge each case alone.

From the Defense Playbook

Out-of-Band Verificationminutes

Confirm any request that arrives through one channel (email, text, chat, a phone call) by reaching the supposed sender through a different channel you already trusted before the request existed.

The Callback Ruleminutes

When anyone contacts you claiming to be your bank, a government agency, a utility, or a company you deal with, hang up and call back on the number printed on your card, statement, or the organization's official website, never the number they gave you.

Never Pay (or Move Money) to Protect Moneyseconds

No bank, agency, or company will ever ask you to move, withdraw, convert, or hand over your money to keep it safe, so any such request identifies the person making it as the threat.

Verify, Then Trust (for Authority Claims)minutes

Separate the symbols of authority (a title, a uniform, a badge, a confident tone, an official-looking letterhead) from the fact of authority, and check the fact through a source the claimant does not control before you comply.

Multi-Factor Authentication and Passkeysminutes

Turn on a second factor for every account that matters and prefer phishing-resistant forms (passkeys or hardware security keys), so that a password typed into a fake page or talked out of you on the phone is not enough to take the account.

"Why Do You Ask?"seconds

Answer an intrusive, oddly specific, or out-of-place question with a friendly question of your own about its purpose, which buys time, reveals intent, and breaks the reflex to answer simply because you were asked.

Every playbook entry states how strong its evidence is and when not to use it. Browse the full playbook.

References

  1. Mitnick, K. D., & Simon, W. L. (2002). The Art of Deception: Controlling the Human Element of Security. Wiley
    First-person account of pretext-based intrusions and the principle that requests framed as routine escape scrutiny.
  2. Workman, M. (2008). Wisecrackers: A theory-grounded investigation of phishing and pretext social engineering threats to information security. Journal of the American Society for Information Science and Technology, 59(4), 662-674 · link
    Field study finding that trust, normative pressure, and commitment predict compliance with pretext social engineering.
  3. Hadnagy, C. (2018). Social Engineering: The Science of Human Hacking (2nd ed.). Wiley
    Practitioner treatment of pretext construction and the role of rapport and small truths in gaining compliance.
Last reviewed
Suggest a correction

Detect Pretexting in any text

Paste any message, email, or article into our free Manipulation Detector to see if Pretexting or other techniques are being used on you.

Related Articles