Every social engineering attack is a variation on the same idea: give someone a plausible reason to act quickly, and skip the part where they'd normally stop and check.
What changes is the channel and the pretext. Here are the seven forms that show up most often, and what each one actually looks like in an inbox, a phone call, or a text message.
|
40% higher click rate for voice and text-based social engineering compared to email in 2026 (Verizon 2026 DBIR) |
6% of all incidents in the 2026 DBIR now start with pretexting, tracked for the first time as its own leading category (Verizon 2026 DBIR) |
+138% jump in BEC losses at large Australian businesses in FY2024–25, largely driven by impersonation and pretexting (ASD Annual Cyber Threat Report 2024–25) |
The broadest and still the most common category: an email designed to get a recipient to click a link, download a file, or hand over credentials.
|
What it looks like: a message from what appears to be a known vendor, IT department, or delivery service, with a spoofed sender address or a hyperlink that doesn't quite match its display text. |
The same mechanism as phishing, but personalised. Spear phishing targets a specific individual using details gathered about them; whaling is spear phishing aimed specifically at senior executives, often to authorise a payment or share sensitive data.
|
Why it matters right now: business email compromise, usually a form of whaling, drove a 138% jump in reported losses at large Australian businesses in FY2024–25. |
A phone call from someone posing as IT support, a bank, or a government agency, built to extract information or push a target toward an urgent action. Voice-based social engineering is showing meaningfully higher success rates than email in the latest data, and AI voice cloning is starting to make these calls harder to distinguish from the real thing.
|
What it looks like: an unexpected call referencing a real internal process (“we're verifying a recent transaction”) that pressures the target to act before they can confirm it independently. |
Phishing delivered by text message, often impersonating a delivery notification, a bank alert, or a two-factor authentication prompt. It works partly because people tend to trust texts more than email, and partly because a phone screen makes a spoofed link harder to inspect before tapping it.
An attacker fabricates a scenario, a new vendor, an auditor, a job candidate, to justify a request that would otherwise raise questions. Verizon's 2026 report is the first to break pretexting out as a leading initial access method in its own right, which tells you it's no longer just a supporting tactic inside phishing, it's becoming the primary approach for a meaningful share of attackers.
What it looks like: a follow-up “confirmation” call or email that references a plausible internal detail, designed to make an unusual request feel routine.
|
▶ WATCH · STICKMANCYBER Most Cyber Security Breaches Are Due to Stolen or Compromised Credentials Pretexting rarely stops at the story, it's usually just the setup for getting a login handed over. This breaks down why identity, not infrastructure, ends up being the weak point. |
|
Baiting dangles something the target wants, a free download, a USB drive labelled “Payroll 2026”, a prize, in exchange for an action that compromises them. Quid pro quo is the same idea framed as a trade: “let me fix that issue for you” in exchange for a login or remote access.
The physical-world version of social engineering: following an authorised employee through a secured door, or asking someone to hold it open, to bypass access controls entirely. It's a reminder that social engineering defences can't stop at the inbox.
Knowing the list matters less than recognising the pattern behind it: urgency, authority, and a request that skips your normal checks. For what to actually do about that, see our post on eight ways to prevent social engineering attacks, and for the psychology behind why these tactics work as well as they do, see what social engineering actually is.
StickmanCyber runs social engineering simulations across email, voice, and text so you can see exactly which of these tactics would actually work against your organisation, before an attacker tries them for real.
Sources
Verizon, 2026 Data Breach Investigations Report
Australian Signals Directorate, Annual Cyber Threat Report 2024–25