In cyberspace, not every danger looks the way we imagine. It is not always a piece of malware lurking without you noticing, nor a hacker breaking through our defenses from the other side of the world. There is another family of attacks that does not exploit a flaw in software or configuration: it exploits the human nature of its victims.
It attacks your naivety, your kindness, your inability to say no to someone who asks for help. It attacks your desire to show off your knowledge when someone asks about something you happen to know. These are noble qualities in everyday life, and precisely for that reason they are a treasure in the hands of an attacker.
The ancient art of deception
Social engineering is not a digital-age invention. Deception and psychological manipulation are centuries old, and they are not always used to cause harm. Everyone has pulled a small ruse to find out what a family member likes, in order to surprise them on their birthday. Nobody would call that an attack.
In a cyber context, the objective is always the same: that a third party, under pressure or of their own free will, helps the attacker achieve a malicious goal. Most of these attacks are after two kinds of loot: getting the victim to hand over their login credentials —to a bank, to a corporate network, to their social media accounts— or to reveal valuable personal information.
The main channel is the phone and the screen: emails, phone calls or text messages. But there are also techniques carried out in person, less common because of the risk they pose to whoever executes them, and no less dangerous.
The effectiveness of these deceptions depends on two things: the attacker’s skill in planning and running the strategy, and how easily each victim can be manipulated. That is why raising awareness matters so much. Many disasters we read about as news could have been avoided with a little training and plenty of common sense.
Within social engineering there are several types of attacks. As with so much else in this field, most are known by their English names. Let’s look at the four that matter most to understand and prevent.
Tailgating: when politeness opens the door
Tailgating —also called piggybacking— is not carried out through electronic means. It happens at the door: an attacker tries to get into a building or a restricted area, usually protected by unattended electronic equipment, a card reader or a turnstile.
It relies on the trust of people who do have legitimate access. The script is classic: the attacker waits for the right moment outside the building, hands full of bags or boxes that are impossible to handle. The moment a legitimate employee approaches their card to come in, they ask with all the naturalness of the world.
—Excuse me, would you mind holding the door? I can’t let go of these boxes.
And so they get in with no valid credentials at all, thanks to the other person’s kindness. That person, in all good faith, would not suspect their real intentions.
The defense is simple. Before holding the door for a stranger, ask yourself: do I know them? Was I expecting them? Can they show me an ID? And if anything feels off, warn security or your manager. Two seconds of doubt are enough.
Baiting: the lure that feeds on curiosity
Baiting attacks one of our least protected aspects: greed and curiosity. It consists of leaving devices infected with malware strategically abandoned in specific places, where the bait must attract attention and look authentic.
The most famous case: infected USB drives dropped in visible, high-traffic areas —bathrooms, elevators, parking lots. To complete the scene, the attacker sticks on an irresistible label: «Payroll», «Layoffs», «Confidential offer». Someone is going to want to see what is inside. Finding out what your colleagues earn, or whether you are on the next round of redundancies, is a temptation that is only too human.
The moment the victim plugs the USB drive into a computer —at the office or at home— a piece of malware quietly installs in the background to carry the attack through. To avoid raising suspicion, the document or folder promised by the label may well exist, simulating a normality that does not exist.
Baiting is not confined to the physical world. Online, the pages with irresistible ads that lead to malicious sites —or encourage you to download infected applications— are the same technique with a different set.
There is also a slower, more profitable variant for the attacker: suspiciously cheap second-hand devices. A cybercriminal buys an old iPod or any device that must be connected to transfer information, plants malware inside it to carry out the attack, and resells it on classifieds platforms such as Wallapop or Facebook Marketplace. The moment you connect it to your everyday computer or tablet, the attacker gains full access to your device.
And not to be missed is the classic of events: free USB drives handed out at concerts, fairs or conferences, USB fans, keyboard lights, USB-C to Lightning cables. Beyond what they advertise, they can carry embedded malware —or, in the case of malicious cables, record everything you type —including passwords— and transmit it wirelessly to an attacker who is not far away.
There are documented cases in large organizations where simply inserting a USB drive found in a parking lot was enough to open a serious security breach. It is not fiction.
Pretexting: the well-rehearsed lie
Pretexting is the construction of a pretext —an elaborately crafted lie— whose objective is to win the victim’s trust in order to extract information or induce a specific action.
The attacker presents themselves as someone with apparent authority and every right to ask whatever they want: a coworker, a police officer, a bank employee, a tax inspector. They first establish a relationship of trust.
And here is the most subtle trick. To avoid raising suspicion, the deception usually starts with questions that appear to confirm the victim’s identity. The attacker provides certain data they already know —your name, your city, something visible— and in exchange asks the victim to confirm other data. It is supposedly a verification of identity. And from that point on, the requested data becomes gradually more sensitive.
Let’s take the classic phone call. A voice on the other end introduces themselves from your bank’s security department. They inform you of «suspicious activity» on your account and offer, with reasonable urgency, to block it. But for that they need your account number, your password and, as a finishing touch, the verification code that just arrived by SMS.
The victim believes they are helping their bank, since from the very beginning they were addressed by their first and last names. In reality, they have just handed over every piece of information the attacker needed.
With this method, almost anything can be collected: national identification numbers, home addresses, phone numbers, call records, staff vacation dates, banking details, and even information about a company’s physical security.
Phishing, vishing and smishing: the classic trio
As we covered in detail in a previous post, Is your email a leak? Protect yourself from spam, phishing, tracking, there are three closely linked modalities: phishing, vishing and smishing. It’s worth distinguishing them so you don’t confuse them when they appear.
Phishing is the email attack: a message pretending to come from a trusted entity —a bank, a provider, IT administration— that tries to get you to click a fake link, download an infected attachment, or hand your credentials over on a fraudulent page.
Vishing uses the same logic over the phone. In practice, it is the favorite channel for many pretexting attacks: the voice, the accent, and the feeling of urgency do the rest.
Smishing arrives by SMS text message: «Your package could not be delivered, click here», «Your account expires today, confirm your details». Short, direct, and hard not to read.
All five share a common fingerprint worth recognizing: they always appeal to urgency, they always avoid a simple way to verify, and they always end the same way —with a request for a click, a download, or confirmation of data— leaving no room to doubt.
The cheapest shield that exists
Found a USB drive: don’t plug it in «just to take a look». Ask around whether anyone lost it; if nobody claims it, destroy it. Inserting it into a device to see its contents is exactly what the attacker is counting on you to do.
Second-hand purchases: distrust any electronic device that is suspiciously cheap, especially if it needs to be connected to «sync». And before selling your own —phone, tablet, computer—, first encrypt it if possible, restore it to its factory settings, and only then hand it over, with a backup of your data already taken beforehand. Free forensic tools exist that can extract photos, videos and confidential information from a device that looked clean. The same advice applies when taking it in for repair: hand it over factory-restored, with your backup already taken.
Events and fairs: be extra careful with any USB drive or cable given away for free. If it is not essential, don’t plug it in at all.
Any call from your bank, the police or the tax office: remember that a legitimate institution will never ask for your password or a verification code. Hang up, look up the official number yourself on your card or on the website, and call. If it was an attack, the attacker hangs up; if it was real, they will answer without any fuss.
And a final rule that sums up everything: whenever anyone makes an urgent request for information, pause. Attackers win when you act without thinking. Common sense, well-trained, is the cheapest firewall in existence.