What Is Social Engineering?

Social engineering is the art of manipulating people into giving up confidential information or taking actions that compromise security. Unlike purely technical attacks, social engineering exploits human psychology — trust, helpfulness, fear, and urgency.

Kevin Mitnick, one of the most famous hackers in history, said: "I was so successful in that line of attack that I rarely had to resort to a technical attack. Companies can spend millions of dollars toward technological protections, and that's not going to help if you can call somebody on the phone and convince them to give you their password."

Social engineering is the most difficult attack to defend against because it targets the one component that can't be patched: human nature.

Common Social Engineering Techniques

Pretexting: Creating a fabricated scenario to engage the victim. "Hi, I'm from IT. We need to verify your account due to a security incident. Can you confirm your password?"

Phishing: Sending deceptive messages that appear to come from trusted sources to trick victims into revealing information.

Baiting: Offering something enticing (free software, USB drives left in parking lots) that contains malware.

Tailgating: Following authorized personnel into restricted areas without proper authentication.

Quid Pro Quo: Offering a service in exchange for information. "I'm calling from tech support. If you give me your login, I can fix the slowness issue you're experiencing."

Scarcity/Urgency: Creating artificial time pressure to prevent critical thinking. "This offer expires in 10 minutes" or "Your account will be permanently deleted if you don't act now."

Building Your Defenses

Psychological Awareness: • Recognize when someone is creating urgency — this is a manipulation tactic • Verify identities through independent channels before sharing information • Be suspicious of unsolicited contacts, even if they seem to know details about you • Remember: no legitimate organization will ask for your password

Procedural Defenses: • Establish verification procedures for sensitive requests • Use a callback number you independently verify (not one provided by the caller) • Never plug in unknown USB devices • Verify email addresses character by character for important communications

For Dead Man's Switch Security: • An attacker might try to gain access to your ZeroLatch account through social engineering (calling you pretending to be support, phishing for your credentials) • ZeroLatch will never ask for your password via email, phone, or chat • Use a unique, strong password for your ZeroLatch account • Enable MFA to ensure that even a socially-engineered password doesn't compromise your vault