What Is Social Engineering?

Prashant
Prashant
August 14, 2026 4 min read

Social engineering is the practice of manipulating people, not systems, into handing over access, information, or money they wouldn't otherwise give up.

No exploit code, no zero-day, no brute-forcing a password. Instead of finding a flaw in your firewall, an attacker finds a flaw in a moment: someone in a hurry, someone eager to help, someone reluctant to question a request that looks like it came from their boss. That's the entire mechanism. It works on the same instincts that make people good colleagues, and that's exactly why it's so hard to train away completely.

▶ WATCH · STICKMANCYBER

Hackers Don't Hack, They Log In

Michael Warnock on why most breaches start with a legitimate-looking login rather than a technical exploit, the same idea this post opens with.

 

62%

of breaches globally involved a human element in 2026, up from 60% the year before (Verizon 2026 DBIR)

60%

of incidents reported to the ACSC in FY2024–25 involved phishing, a form of social engineering (ASD Annual Cyber Threat Report 2024–25)

6%

of all incidents in the 2026 DBIR now start with pretexting specifically, newly named as a primary initial access method (Verizon 2026 DBIR)

 

Why it works: exploiting how people think, not what they know

Social engineering doesn't rely on a victim being careless or slow to catch on. It relies on a handful of cognitive shortcuts everyone uses to get through a busy day.

Authority bias. an email that looks like it's from the CEO gets less scrutiny than one from a stranger, simply because of who it claims to be from.

Recency bias. an attacker who references something that actually happened recently, a real project, a real vendor, a real invoice, borrows credibility from that context.

The halo effect. a polished email or a confident voice on the phone reads as trustworthy, regardless of whether the content actually holds up.

Psychologist Robert Cialdini's six principles of influence, reciprocity, commitment and consistency, social proof, liking, authority, and scarcity, show up constantly in attack pretexts, because they're the same principles that make persuasion work in any legitimate context. An attacker creating false urgency (“this needs to be paid in the next hour”) is leaning on scarcity. One posing as IT support fixing your “account issue” is leaning on reciprocity, you feel like you owe them a moment of cooperation.

How an attack actually unfolds

Most social engineering attacks, whether it's a two-minute phishing email or a weeks-long impersonation campaign, move through the same four stages.

1. Reconnaissance: the attacker researches the target, often from what's publicly available on LinkedIn, a company website, or social media. The more specific detail they gather, the more convincing the next stage becomes.

2. Engagement: first contact. This is usually low-pressure and designed to build rapport or establish a plausible reason for contact before asking for anything.

3. Exploitation: the actual ask, click this link, verify these details, approve this transfer, using whichever cognitive lever the reconnaissance phase suggested would work.

4. Exit: the attacker disengages cleanly, often before the target has any reason to suspect something was wrong, which is part of why so many incidents aren't reported until well after the fact.

The vectors attackers use

Social engineering isn't just email anymore. Phishing remains the most common vector, but Verizon's 2026 data shows voice calls and text messages now pulling a 40% higher click rate than email-based attempts, and pretexting (impersonating someone with a fabricated scenario) has become common enough that Verizon now tracks it as its own initial access category. We've gone deeper on each of these in our companion post on the common types of social engineering attacks.

Why this matters for your organisation

Technical controls, firewalls, endpoint protection, network monitoring, don't touch this problem, because social engineering isn't aimed at your infrastructure. It's aimed at the people who operate it. That's precisely why it remains one of the highest-return methods available to attackers even as every other part of the attack surface gets harder to reach. The good news is that the same fact that makes it hard to solve with technology also makes it solvable with the right combination of awareness, testing, and process, which is what we cover in our post on eight ways to prevent social engineering attacks.

▶ WATCH · STICKMANCYBER

Most Cyber Security Breaches Are Due to Stolen or Compromised Credentials

A short breakdown of why weak identity security, not a lack of technical defences, is the root cause behind breaches like the Medibank hack.

Sources

Verizon, 2026 Data Breach Investigations Report

Australian Signals Directorate, Annual Cyber Threat Report 2024–25

Prashant

Prashant

Prashant is an experienced Marketing leader with a keen interest in cybersecurity. His interests lie at the intersection of human behaviour, systems and processes.

Cybersecurity As A Service for Australian Organisations

StickmanCyber helps mid-market businesses across Australia and New Zealand reduce cyber risk, strengthen compliance, and build security maturity without the cost and complexity of managing it all internally.

Combining experienced cybersecurity specialists with AI-powered delivery, StickmanCyber provides practical, Cyber Done support across risk assessments, compliance, remediation, and ongoing protection — acting as a trusted partner from strategy through to certification and beyond.

CREST Accredited PCI-DSS ISO 27001 Essential Eight Since 2006
Book a free consultation
Risk Assessment & Essential EightUnderstand your current maturity and gaps
Compliance & CertificationISO 27001, PCI DSS, SOC 2 and more
Penetration & VAPTFind gaps, strengthen controls, build resilience
24/7 Monitoring via StickSecureContinuous visibility across your environment