Cybersecurity

What Is Social Engineering? Examples and Defenses

Learn how social engineering manipulates employees through email, phone, text, and in-person tactics—and how to stop it.

Reviewed October 11, 2026 3 minute read Reviewed by Meta IT Pro
What Is Social Engineering? Examples and Defenses — Cybersecurity illustration from Meta IT Pro
Part of the Cybersecurity Learning Center

Social engineering is manipulation that tricks people into giving away access, information, or money. Instead of breaking technology, attackers exploit trust, urgency, authority, and helpfulness.

Key takeaways

What to know before you act

  • Social engineering targets human decisions, so it can succeed even when systems are well protected.
  • Most attempts rely on a few levers: urgency, authority, fear, curiosity, and the desire to help.
  • Independent verification and easy reporting stop far more attacks than trying to spot every fake.

Why it matters

What business leaders should understand

Many security incidents begin with a person being persuaded to click, share, approve, or pay. Technical controls help, but verification habits and a culture of reporting are what stop most social engineering attempts.

The right response should reflect your environment, data, vendors, risk, and operational priorities. Use this guide as a practical starting point, then validate important decisions with the people responsible for your technology, cybersecurity, legal obligations, and insurance coverage.

Common social engineering tactics

Attackers choose the channel and story most likely to work on their target. The same underlying trick—getting someone to act before they think—appears in many forms.

  • Phishing: deceptive email that leads to fake sign-in pages or malicious attachments.
  • Vishing and smishing: phone calls and text messages that impersonate banks, IT, or executives.
  • Pretexting: a fabricated scenario, such as an auditor or new vendor needing information.
  • Baiting: infected USB drives or 'free' downloads that tempt people to open them.
  • Tailgating: following an employee through a secure door without authorization.
  • Business email compromise: impersonating a trusted contact to redirect payments.

Why it works—and how to build resistance

Social engineers research their targets using company websites, social media, and previous breaches, so their messages can be specific and convincing. They often create time pressure so the victim does not stop to check.

The most effective defense is a set of simple rules employees can follow under pressure: verify sensitive requests through a known channel, never share passwords or MFA codes, and report anything unusual. Leaders should reinforce that slowing down to verify is always acceptable, even when the request appears to come from them.

  • Publish a short list of requests that always require verification.
  • Run realistic awareness exercises across email, phone, and text.
  • Thank people for reporting, including false alarms.
  • Review what staff details are exposed on public websites and social media.

Practical action plan

Steps your business can take

01

Teach employees the common pretexts: urgent executives, IT support calls, vendor changes, and delivery notices.

02

Require independent verification for payments, password resets, and access requests.

03

Make reporting suspicious contacts quick and blame-free.

04

Limit what employee and organizational details are published publicly.

Recommended next steps

Continue from this article.

These pages expand the specific risks and decisions covered in this guide. Use them to move from general understanding to the service, tool, or related topic that best matches your next question.

Warning signs

Do not ignore these indicators

  • Requests that create urgency or ask you to bypass normal procedures
  • Callers who claim to be IT support and ask for codes or remote access
  • Unexpected messages that move the conversation to personal email, text, or chat apps

Frequently asked questions

Common questions, answered.

What is social engineering in cybersecurity?

Manipulating people into revealing information, granting access, or sending money by exploiting trust and urgency.

What are examples of social engineering?

Phishing, vishing, smishing, pretexting, baiting, tailgating, and business email compromise.

How can employees avoid social engineering?

Verify sensitive requests through a known channel, never share passwords or MFA codes, and report anything unusual.

How Meta IT Pro can help

Related services and practical next steps

Explore the services connected to this topic. These links provide more detail about scope, safeguards, support, and how to start a conversation with our team.

Authoritative references

Sources and further reading

These primary sources support the guidance in this article and provide additional technical or consumer information.

Need help with your IT solution?

Get practical guidance from a local IT and cybersecurity team.

Meta IT Pro helps Massachusetts and Rhode Island businesses improve support, security, Microsoft 365, Google Workspace, networks, backup, recovery, and compliance readiness. Tell us what is not working - or what you want to improve - and we will help identify a sensible next step.