7 Types of Social Engineering Attacks to Watch For in 2026

Ajay Unni
Ajay Unni CEO,StickmanCyber
August 14, 2026 3 min read

Every social engineering attack is a variation on the same idea: give someone a plausible reason to act quickly, and skip the part where they'd normally stop and check.

What changes is the channel and the pretext. Here are the seven forms that show up most often, and what each one actually looks like in an inbox, a phone call, or a text message.

 

40%

higher click rate for voice and text-based social engineering compared to email in 2026 (Verizon 2026 DBIR)

6%

of all incidents in the 2026 DBIR now start with pretexting, tracked for the first time as its own leading category (Verizon 2026 DBIR)

+138%

jump in BEC losses at large Australian businesses in FY2024–25, largely driven by impersonation and pretexting (ASD Annual Cyber Threat Report 2024–25)

 

Phishing

The broadest and still the most common category: an email designed to get a recipient to click a link, download a file, or hand over credentials.

What it looks like: a message from what appears to be a known vendor, IT department, or delivery service, with a spoofed sender address or a hyperlink that doesn't quite match its display text.

Spear phishing and whaling

The same mechanism as phishing, but personalised. Spear phishing targets a specific individual using details gathered about them; whaling is spear phishing aimed specifically at senior executives, often to authorise a payment or share sensitive data.

Why it matters right now: business email compromise, usually a form of whaling, drove a 138% jump in reported losses at large Australian businesses in FY2024–25.

Vishing (voice phishing)

A phone call from someone posing as IT support, a bank, or a government agency, built to extract information or push a target toward an urgent action. Voice-based social engineering is showing meaningfully higher success rates than email in the latest data, and AI voice cloning is starting to make these calls harder to distinguish from the real thing.

What it looks like: an unexpected call referencing a real internal process (“we're verifying a recent transaction”) that pressures the target to act before they can confirm it independently.

Smishing (SMS phishing)

Phishing delivered by text message, often impersonating a delivery notification, a bank alert, or a two-factor authentication prompt. It works partly because people tend to trust texts more than email, and partly because a phone screen makes a spoofed link harder to inspect before tapping it.

Pretexting

An attacker fabricates a scenario, a new vendor, an auditor, a job candidate, to justify a request that would otherwise raise questions. Verizon's 2026 report is the first to break pretexting out as a leading initial access method in its own right, which tells you it's no longer just a supporting tactic inside phishing, it's becoming the primary approach for a meaningful share of attackers.

 What it looks like: a follow-up “confirmation” call or email that references a plausible internal detail, designed to make an unusual request feel routine. 

▶ WATCH · STICKMANCYBER

Most Cyber Security Breaches Are Due to Stolen or Compromised Credentials

Pretexting rarely stops at the story, it's usually just the setup for getting a login handed over. This breaks down why identity, not infrastructure, ends up being the weak point.

   

Baiting and quid pro quo

Baiting dangles something the target wants, a free download, a USB drive labelled “Payroll 2026”, a prize, in exchange for an action that compromises them. Quid pro quo is the same idea framed as a trade: “let me fix that issue for you” in exchange for a login or remote access.

Tailgating and piggybacking

The physical-world version of social engineering: following an authorised employee through a secured door, or asking someone to hold it open, to bypass access controls entirely. It's a reminder that social engineering defences can't stop at the inbox.

Knowing the list matters less than recognising the pattern behind it: urgency, authority, and a request that skips your normal checks. For what to actually do about that, see our post on eight ways to prevent social engineering attacks, and for the psychology behind why these tactics work as well as they do, see what social engineering actually is.

StickmanCyber runs social engineering simulations across email, voice, and text so you can see exactly which of these tactics would actually work against your organisation, before an attacker tries them for real.

Sources

Verizon, 2026 Data Breach Investigations Report

Australian Signals Directorate, Annual Cyber Threat Report 2024–25

Ajay Unni

Ajay Unni

CEO,StickmanCyber Ajay Unni is CEO of StickmanCyber, leading the team in delivering cybersecurity, risk, and compliance solutions. He holds a Master of IT and a Bachelor of Computer Science, is a PCI Qualified Security Assessor and Certified Information Systems Auditor, and has served as CREST Vice Chairman and a member of the NSW Government Cyber Security Taskforce. With over 25 years in the industry, Ajay is a sought-after voice on the Australian cyber threat landscape.

Master of IT B. Computer Science PCI Qualified Security Assessor Certified Information Systems Auditor (CISA) CREST Vice Chairman NSW Gov Cyber Security Taskforce

Cybersecurity As A Service for Australian Organisations

StickmanCyber helps mid-market businesses across Australia and New Zealand reduce cyber risk, strengthen compliance, and build security maturity without the cost and complexity of managing it all internally.

Combining experienced cybersecurity specialists with AI-powered delivery, StickmanCyber provides practical, Cyber Done support across risk assessments, compliance, remediation, and ongoing protection — acting as a trusted partner from strategy through to certification and beyond.

CREST Accredited PCI-DSS ISO 27001 Essential Eight Since 2006
Book a free consultation
Risk Assessment & Essential EightUnderstand your current maturity and gaps
Compliance & CertificationISO 27001, PCI DSS, SOC 2 and more
Penetration & VAPTFind gaps, strengthen controls, build resilience
24/7 Monitoring via StickSecureContinuous visibility across your environment

Recent Posts