top of page

Social Engineering

May 1
3 min read

Updated: May 3

AttacksHacking humans instead of systems


Article Written By: Iyithihya Prakasan

Article Designed by: Iyithihya Prakasan and Natasha Gumpula


What is Social Engineering?


Social engineering (IBM) attacks work their way to orchestrate individuals to part with information that they are not supposed to share, install software that they are not supposed to install, open web pages that they are not supposed to visit, send money to criminals, or commit other errors that jeopardize their personal or organizational safety.


Psychological premise of Social Engineering

Understanding how humans are exploited on the basis of their emotions.


Image by (63 SATS)


Some of the commonly used forms in social engineering are phishing, pretexting, baiting and tailgating. With the insight into such techniques, individuals and organizations can defend themselves against them with greater success.


Phishing:  Fraudulent emails or messages are sent by attackers, and they are created in such a way that they make the recipients expose sensitive information or even download malware.

 

Variants: Spear Phishing - Targeted at specific individuals or organizations.

               Whaling - Targets High-level executives.

               Smishing - Conducted via SMS.

               Vishing - Conducted via phone calls.


Pretexting: A hacker creates a fictional situation in order to win the trust of the victim and elicit personal or sensitive information.

Example - Contacting a person by impersonating themselves from tech support and requesting confirmation codes from unknown sources.


Baiting:  Scamming victims with an agreement of something enticing, like free software, or a prize, to install malware into their systems, or steal data.


Taligaiting: Hacking into restricted zones through trailing an authorized individual, mostly through courtesy. 

Example -  An intruder who is not carrying an ID badge can access a secure component by trailing a staff member.


There are various other forms in Social Engineering such as Quid Pro Quo, Impersonation, Watering Hole Attacks, Shoulder Surfing, Dumpster Diving, Honey Traps, Rogue Software, DNS Spoofing, Scareware.


Human Hacking vs System Hacking 

Pretexting and manipulation strategies.


Image by (Cybernx)


The pretext development and research.


Attackers collect information that is publicly available on the websites of corporations, LinkedIn, or even social media in order to understand how to create a convincing identity or scenario.


Psychological triggering


Messages are packaged to elicit certain responses like feeling of urgency (such as, your account will be terminated), fear ( such as, security alert detected); or command ( such as, imminent approval required by management).


The participation and exploitation


The target that receives then clicks an evil link in the email/ message, opens up an attachment, or shares credentials, and naively provides the attackers access.


Escalation and breach


Beyond using ransomware or stealing data, cybercriminals are able to implement unauthorized intrusions to infiltrate the network infrastructure and cause additional harm to it.


Real World Scenarios and Historical examples.


Industrial Espionage Methods (link-  There are widespread reports of former Soviet Bloc intelligence operatives acting as freelancers to the highest bidders, as well as foreign intelligence agencies refocusing their efforts on U.S. companies as opposed to the U.S. Government. These intelligence organizations bring their tried and true methods with them. Unfortunately, most corporate security managers are not aware of the threats and the methods they employ. Intelligence gathering methods are more effective on companies than they are on governments, because companies do not have the appropriate countermeasures in place.


Image by (Vigilfy)


Academic Research on Social Engineering


The human, organisational and adversarial characteristics of cyber threats are identified by systematising the knowledge on the Social Engineering Attacks (SEAs). It discusses the escalated security threats presented by SEAs that are very much applicable in the realm of physical cyber places such as traveller in airports and citizenry in smart cities, and generalizes the discoveries of peer reviewed studies, industry and government publications to guide its viable counterinterventions that can be integrated into the future smart cities.



References


Thomson, Scott, et al. "Social Engineering Attacks: A Systemisation of Knowledge on People Against Humans." (Cornell).


Pramono, Patricia A. “What Is Social Engineering?” Cisometric, Patricia A Pramono, 18 November 2025,(Cisometric). Accessed 18 January 2026.


uhayat. “Social Engineering – Exploiting Human Psychology.” Mind Classic, uhayat, 22 November 2024, (Mind Classic). Accessed 18 January 2026.


Siddiqi, Murtaza Ahmed, et al. “A Study on the Psychology of Social Engineering-Based Cyberattacks and Existing Countermeasures.” MDPI, 14 June 2022, (MDPI). Accessed 18 January 2026.



-Iyithihya Prakash

Contributing Author


 
 
 

103 Comments


Guest
2 hours ago

Nói về vụ “link chính thức 2026” nghe cũng hơi dễ gây nghi ngờ, kiểu không biết có bị làm quá lên không. https://ae888.nagoya/ mình ghé thử cho biết thôi, lướt vài phút là thấy trang làm khá gọn, không kiểu nhét chữ kín màn hình nên đọc đỡ mệt; cái tông đỏ – trắng nhìn tưởng chói mà hóa ra lại ổn, ngồi lâu cũng không khó chịu. Mình dùng điện thoại là chủ yếu nên để ý nhất khoản thao tác, bấm chuyển qua lại mấy mục cơ bản khá mượt, ít phải zoom qua zoom lại. Không cần mò nhiều vẫn biết mình đang ở phần nào vì các khối nội dung trên trang chủ tách ra…

Like

Guest
18 hours ago

https://pg66.us.com/ Có dễ nhìn không nhỉ? Mình vào thử cho biết thì thấy giao diện khá “thẳng thắn”, kiểu vừa mở ra là nhận ra ngay đâu là phần cần bấm tiếp, không bị rối mắt bởi quá nhiều thứ chen chúc. Lướt một chút là quen tay vì cái menu đặt ở vị trí dễ thấy, chuyển qua lại giữa các mục khá mượt nên đỡ phải quay lại tìm hoài, nhất là lúc chỉ muốn xem nhanh thông tin chứ không đọc kỹ. Với lại mình thích mấy chỗ hiển thị số liệu vì trình bày theo cột nhìn gọn, liếc qua là nắm được ý chính chứ không bị dính thành một đống chữ. Nói chung mình…

Like

Guest
4 days ago

keonhacai mình thấy bạn bè nhắc hoài nên cũng bấm vào coi thử cho biết thôi. Không phải kiểu ngồi đọc kỹ từng thứ đâu, mình chỉ lướt xem giao diện có dễ nhìn không. Vào cái là thấy trang làm khá gọn, khoảng trắng vừa đủ nên nhìn không bị bí hay rối mắt. Mình thích nhất là họ chia nội dung thành từng khối rõ ràng, kéo xuống tới đâu biết tới đó chứ không bị tràn lan một mớ. Với lại phần thông tin họ để dạng bảng cột nên liếc nhanh vẫn nắm được ý, chữ cũng không nhỏ quá. Menu đặt ngay chỗ dễ thấy, bấm qua lại vài lần thấy phản hồi nhanh, không…

Like

Guest
Sep 03

8xbet.com so với mấy trang mình từng lướt trước đó thì nhìn “thẳng thớm” hơn chút, dù lúc đầu mình vẫn hơi nghi ngờ là vào sẽ rối mắt. Mở lên một cái là thấy họ chia nội dung thành từng khối rõ ràng, kéo xuống đến đâu thì các mục hiện ra theo kiểu ô danh sách nên mắt bắt nhịp khá nhanh (mình chỉ xem qua chứ chưa bấm sâu). Mình thích nhất là mấy bảng dạng cột được canh gọn, chữ với số tách nhau rõ nên lướt ngang vẫn hiểu đang nói gì, không phải căng mắt dò từng dòng. Thanh menu cũng đặt ở vị trí dễ thấy nên đổi qua lại giữa các phần…

Like

Owen Kim
Aug 27

Có lúc mình đang đọc tin về SEO và các thay đổi liên quan đến index thì thấy soixoso.net xuất hiện trong danh sách mình đang xem. Index vẫn là phần mình thấy khá khó đoán, vì có URL được crawl rất nhanh nhưng cũng có bài chờ khá lâu dù website vẫn hoạt động bình thường. Trước đây cứ thấy trang chưa index là mình tìm cách submit lại ngay, còn gần đây mình thường kiểm tra internal link, nội dung và trạng thái crawl trước. Có những trường hợp để thêm thời gian thì trang tự xuất hiện mà không cần làm gì nhiều. Vì thế mình đang cố phân biệt vấn đề kỹ thuật thực sự với những…

Like
bottom of page