Social Engineering & FraudMANIPULATIVE
Reverse Social Engineering
What it is
The attacker arranges for the target to come to them for help, so that the request originates with the victim and any information handed over feels freely given rather than extracted.
How it works
Real-world examples
- •An attacker quietly disrupts a user's network access, then makes sure the user finds the attacker's "help desk" number, so the victim phones in and volunteers credentials to get working again.
- •In Irani and colleagues' 2011 experiments, decoy profiles designed to surface in social-network recommendations received unsolicited friend requests and personal messages from strangers.
- •A fake technician leaves business cards around an office after a staged printer failure; when the printers "break," staff call the card and grant remote access.
- •Online marketplaces see sellers post an attractive item, then let eager buyers drive the interaction, lowering the buyers' guard against a fake-payment or overpayment twist.
Ethical guidelines
- ●Manufacturing a problem so that victims seek you out for the "solution" is fraud with an extra layer of misdirection; it has no honest form.
- ●Positioning yourself as help you are not qualified or authorized to give is deceptive even when the victim is grateful.
- ●Authorized testing that uses reverse techniques must be scoped and must not degrade real services that others depend on.
How to defend against it
- ►Verify help sources independently: use only the IT number in your official directory, not one you found on a sticker, a card, or a search result.
- ►Remember that initiating contact does not make the other party legitimate; a request you started can still be answered by an impostor who set the trap.
- ►Be suspicious when a problem and its convenient fix appear together, especially if the fix requires credentials, payment, or remote access.
- ►On social platforms, treat "mutual connections" and recommendation placement as weak signals, since both can be engineered.
- ►Organizations should publish the single authoritative channel for support so a planted alternative stands out as anomalous.
From the Defense Playbook
Every playbook entry states how strong its evidence is and when not to use it. Browse the full playbook.
References
- Irani, D., Balduzzi, M., Balzarotti, D., Kirda, E., & Pu, C. (2011). Reverse Social Engineering Attacks in Online Social Networks. Detection of Intrusions and Malware, and Vulnerability Assessment (DIMVA 2011), Lecture Notes in Computer Science 6739, Springer, 55-74 · linkExperiments showing that accounts engineered to appear in recommendations attract unsolicited contact and disclosure.
- Mitnick, K. D., & Simon, W. L. (2002). The Art of Deception: Controlling the Human Element of Security. WileyThe three-stage sabotage-advertise-assist pattern in which the victim is led to request the attacker's help.
Last reviewed
Suggest a correctionRelated Articles
Social Engineering: Why Smart People Fall for It
Social engineering does not target stupidity. It targets helpfulness, deference, and time pressure, which are the same habits that make people good at their jobs. Here is how the attacks are built and which procedures actually stop them.
7 min read
The Disinformation Playbook: How Campaigns Are Built and Where They Break
Disinformation campaigns follow a recognizable sequence: seed, launder, amplify, and let real people carry it the rest of the way. A field guide to the stages, drawn from the research, with the defences that work at each one.
8 min read