Social Engineering Attacks: Real Examples and How to Spot Them

Learn the most common social engineering attacks with real world examples. Understand phishing, pretexting, baiting, and tailgating, plus proven defenses to protect yourself and your organization.
- Awareness
- Social Engineering
- Threats
- Ethics
- Confidence
Key facts
- Social engineering is involved in 98% of cyberattacks according to Proofpoint's 2024 Human Factor Report
- The 2020 Twitter hack began with phone-based social engineering targeting employees through a vishing campaign and led to the compromise of 130 high-profile accounts
- The 2023 MGM Resorts breach started with a 10-minute phone call to the IT help desk and resulted in an estimated $100 million in losses
- Organizations that run regular phishing simulations see a 75% reduction in click rates within 12 months according to KnowBe4 research
- The FBI Internet Crime Complaint Center reported $2.9 billion in losses from business email compromise in 2023 alone
TL;DR
Social engineering attacks exploit human psychology rather than technical vulnerabilities, and they are involved in 98% of cyberattacks according to Proofpoint research. This guide covers eight attack types with real case studies including the 2020 Twitter hack and 2023 MGM Resorts breach. Attackers weaponize authority, urgency, and reciprocity to bypass even the strongest technical controls. Defending against social engineering requires security awareness training, verification protocols, and a culture where employees feel safe questioning suspicious requests.
The phone rang at 8:47 AM on a Monday morning. The caller ID displayed the CEO's direct office number. The voice on the other end was calm, professional, and unmistakably familiar. "This is David. I'm at the airport heading to the board meeting in Zurich, and my laptop won't connect to our VPN. I need you to reset my credentials right now so I can pull up the quarterly report before we land. The board presentation is in three hours."
The IT helpdesk technician hesitated for exactly four seconds. The voice sounded right. The urgency made sense. The CEO did have a board meeting scheduled that week. She pulled up the credential reset tool and asked the standard verification question: "What is your employee ID number?"
"Sarah, I hired you six months ago. I do not have time for this. Just reset the password and send it to my personal email."
She reset the password. Fifteen minutes later, the real CEO called from his hotel room in Zurich. His account was already compromised. The attacker had used caller ID spoofing, publicly available meeting information from a press release, and the simple psychology of authority pressure to walk through the front door of the company's network without writing a single line of code.
This is social engineering. No malware. No exploit. No vulnerability scan. Just a human being manipulating another human being. And it works more consistently than any technical attack because it targets the one component that every security architecture relies on and cannot fully control: people.
What Social Engineering Actually Means
Social engineering is the deliberate manipulation of people into performing actions or divulging confidential information. Unlike technical attacks that exploit software flaws, social engineering exploits the predictable patterns in human decision making. It preys on our instinct to trust, help, and comply with authority.
The term is broad by design. Any attack where the primary vector is human behavior rather than a software vulnerability qualifies. That includes a carefully written phishing email, a phone call from a fake IT technician, a USB drive left in a parking lot, and a stranger following an employee through a badge controlled door. The delivery mechanism changes. The underlying principle does not: people are easier to manipulate than software is to exploit.
According to CISA, social engineering is the most common initial access vector in cyberattacks against both government agencies and private sector organizations. The reason is straightforward. Every organization, regardless of its security budget, employs humans who answer phones, read emails, open doors, and make decisions under pressure.
The Eight Types of Social Engineering Attacks
Phishing
Phishing is the broadest and most common social engineering attack. The attacker sends emails, messages, or creates websites that impersonate trusted entities, such as banks, employers, or software vendors, to trick recipients into clicking malicious links, downloading infected attachments, or entering credentials on fake login pages.
A typical phishing email creates urgency ("Your account will be suspended in 24 hours"), presents a plausible scenario ("Unusual login detected from Moscow"), and provides a convenient action ("Click here to verify your identity"). The link leads to a replica of the real login page. Every credential entered goes directly to the attacker.
Phishing accounts for over 80% of reported security incidents. Its effectiveness comes from volume. An attacker can send 100,000 phishing emails in an afternoon. Even a 0.1% success rate yields 100 compromised accounts.
Spear Phishing
Spear phishing narrows the target. Instead of blasting generic emails, the attacker researches specific individuals and crafts personalized messages. They reference real projects, use correct internal terminology, and impersonate known colleagues. A spear phishing email to a finance director might reference an actual vendor relationship, include a realistic invoice, and come from an email address one character different from the real vendor's domain.
The success rate of spear phishing is dramatically higher than generic phishing because personalization eliminates most red flags that trained users look for. When the email references a real project you are working on and appears to come from someone you communicate with regularly, your guard drops.
Vishing (Voice Phishing)
Vishing uses phone calls instead of emails. The attacker calls the target, impersonates a trusted entity (IT support, a bank, a government agency, or a company executive), and extracts information or directs the victim to take specific actions.
Vishing is uniquely effective because voice communication creates a sense of immediacy and personal connection that email cannot match. It is difficult to "hover over a link" to verify a phone call. Caller ID spoofing is trivial and inexpensive, which means the number displayed on the victim's phone can match any number the attacker chooses.
Smishing (SMS Phishing)
Smishing delivers the same deception through text messages. "Your package delivery failed. Update your address here." "Your bank detected suspicious activity. Reply YES to confirm or call this number." The shortened URLs in SMS messages make it nearly impossible to verify the destination before tapping.
Smishing exploits the fact that people trust text messages more than emails. Spam filters protect most inboxes from phishing emails, but SMS filtering is far less mature. Messages arrive directly on the lock screen, creating urgency before the recipient has time to think critically.
Pretexting
Pretexting is the creation of a fabricated scenario to extract information or gain access. The attacker invents a plausible identity and context to justify their request. The helpdesk call from the opening of this article is pretexting. The attacker built a scenario (CEO at the airport, urgent board meeting) and an identity (the CEO himself) to justify an unusual request (immediate credential reset without standard verification).
What separates pretexting from other attack types is the depth of preparation. A skilled pretexter researches the target organization's structure, identifies key personnel, learns internal jargon, and constructs a narrative so coherent that questioning it feels unreasonable. The attack does not succeed because the victim is careless. It succeeds because the pretexter made compliance feel like the rational choice.
Baiting
Baiting offers something enticing to the victim in exchange for access or information. The classic example is a USB drive labeled "Employee Salary Review Q4" left in a company parking lot or lobby. Curiosity drives someone to plug it in, and the drive installs malware automatically.
Digital baiting includes fake software downloads ("Free premium VPN"), pirated content bundled with keyloggers, and online advertisements offering free tools that require "admin access" to install. The common thread is offering something the victim wants in exchange for an action that compromises security.
Tailgating (Piggybacking)
Tailgating is a physical social engineering attack. The attacker gains access to a restricted area by following an authorized person through a secured entrance. It works because most people hold the door for others out of politeness. An attacker carrying a box of "server parts" or wearing a delivery uniform rarely gets challenged.
Tailgating bypasses all digital security controls. It does not matter how strong your encryption is if an unauthorized person can walk into the server room. Physical access to a network often means unrestricted access to critical systems.
Quid Pro Quo
Quid pro quo attacks offer a service in exchange for information. The attacker calls employees, posing as IT support, and offers to "fix a problem" with their computer. In exchange for "helping," they ask the employee to disable antivirus software, install a remote access tool, or share their login credentials.
This technique preys on reciprocity. When someone offers to help you, you feel obligated to cooperate. The attacker positions the exchange so that compliance feels like common courtesy rather than a security violation.
Real Case Studies
The 2020 Twitter Hack
On July 15, 2020, attackers compromised 130 high profile Twitter accounts including Barack Obama, Elon Musk, Jeff Bezos, and Apple. The attackers posted messages promoting a Bitcoin scam, collecting over $120,000 in cryptocurrency before the scheme was shut down.
The attack did not begin with a software exploit. It started with phone calls. According to the U.S. Department of Justice investigation, the attackers used vishing to target Twitter employees, calling them while pretending to be colleagues from the IT department. They directed employees to a credential harvesting website that looked identical to Twitter's internal VPN login page. Once they had employee credentials, they accessed internal admin tools that allowed them to reset passwords and bypass two factor authentication on any account.
The Twitter hack demonstrates that social engineering can breach companies with sophisticated security programs. Twitter's technical controls were not the weak point. Human trust was.
The 2023 MGM Resorts Breach
In September 2023, the ALPHV/BlackCat ransomware group brought MGM Resorts International to its knees. Slot machines went dark. Hotel room keys stopped working. The website went offline. Guests checked in with paper forms. The estimated financial impact exceeded $100 million.
The initial access method was a phone call to the MGM IT help desk that lasted approximately 10 minutes. As reported by KrebsOnSecurity, the attackers identified an MGM employee on LinkedIn, gathered enough personal information from their public profile to pass identity verification, and called the help desk to request a credential reset. With valid credentials in hand, they escalated privileges, moved laterally through the network, and deployed ransomware across critical systems.
Ten minutes. One phone call. One hundred million dollars. The MGM breach is now a textbook example of why social engineering is the most cost effective attack vector available.
The Psychology Behind Social Engineering
Social engineering does not work because victims are unintelligent. It works because it targets cognitive biases that exist in all humans. Understanding these psychological principles is the first step toward recognizing when they are being used against you.
Authority
People comply with requests from perceived authority figures without questioning the legitimacy of the request. When someone claims to be the CEO, a police officer, or a government agent, the default human response is compliance. The pretexter in the opening scenario exploited this directly: "I hired you six months ago" establishes dominance and makes questioning the request feel insubordinate.
Urgency
Time pressure suppresses critical thinking. When an attacker says "this must be done in the next five minutes or we lose the deal," the victim's brain shifts from analytical processing to reactive processing. Urgency is the single most exploited psychological trigger in social engineering because it reliably overrides training and common sense.
Reciprocity
Humans feel compelled to return favors. When a "helpful IT technician" spends 20 minutes walking you through a problem (that may not have existed in the first place), you feel obligated to cooperate when they ask you to install a "diagnostic tool" or share your password. The favor creates a debt, and the attacker collects immediately.
Social Proof
People look to others to determine correct behavior. An attacker who says "everyone on your team has already completed this security update" leverages social proof to make compliance feel normal rather than suspicious. If your colleagues supposedly did it, it must be legitimate.
Liking and Similarity
People are more likely to comply with requests from people they like or perceive as similar. Attackers build rapport by referencing shared interests, using humor, or expressing empathy. A pretexter who spends five minutes chatting about the local sports team before making their request is not wasting time. They are building the psychological foundation that makes the request harder to refuse.
How to Defend Yourself and Train Others
Individual Defenses
Verify through a separate channel. If you receive a suspicious email from your bank, do not click any links in the email. Open a new browser tab, navigate to the bank's website directly, and log in. If you receive a suspicious phone call from a colleague, hang up and call them back using the number listed in your company directory. Verification through a separate channel defeats nearly every social engineering technique because the attacker controls only one communication channel.
Pause before acting on urgency. Legitimate requests survive a five minute delay. If someone insists that you must act immediately or face catastrophic consequences, that pressure itself is the strongest indicator of a social engineering attempt. Tell the caller you will call back in five minutes, and watch how they respond. Legitimate requesters will understand. Attackers will escalate pressure or hang up.
Treat unsolicited contact with skepticism. You did not win a contest you never entered. Your computer is not infected with a virus that only a phone caller can detect. The IRS does not demand immediate payment via gift cards. If someone contacts you unexpectedly with an alarming claim or an attractive offer, the correct default assumption is that the contact is malicious until verified otherwise.
Organizational Defenses
Implement callback verification for sensitive requests. Any request involving credential resets, wire transfers, or access changes should require verification through a pre-established callback number. Not the number the caller provides, but the number on file in the company directory. This single control would have prevented both the Twitter and MGM breaches.
Run phishing simulations regularly. Organizations that run monthly phishing simulations see a 75% reduction in click rates within 12 months. Simulations work because they provide consequence free practice in recognizing social engineering in a realistic context. Pair simulations with immediate training feedback: when an employee clicks a simulated phishing link, redirect them to a brief educational module explaining what they missed.
Build a culture where reporting is rewarded. Employees who fall for social engineering often delay reporting because they fear punishment. That delay is far more damaging than the initial compromise. Organizations must create an environment where reporting a potential incident, even one caused by your own mistake, is treated as a contribution to security rather than a failure. The CISA security awareness resources emphasize this cultural shift as foundational to effective defense.
Technical Controls That Support Human Defenses
Technical controls do not replace human judgment, but they reduce the volume and sophistication of social engineering that reaches employees. Multi-factor authentication ensures that stolen passwords alone cannot grant access. Email filtering with DMARC, DKIM, and SPF authentication blocks a significant percentage of phishing emails before they reach inboxes. Endpoint detection tools can identify and quarantine malware delivered through baiting attacks even after the user opens the malicious file.
The most effective security programs layer technical controls with human training. Neither is sufficient alone. A phishing email that bypasses your email filter still reaches a human who has been trained to recognize it. A user who clicks a phishing link still encounters multi-factor authentication that prevents credential theft. Defense in depth means that no single failure, whether human or technical, leads to a full data breach.
Why Social Engineering Will Always Be Relevant
Technical security improves every year. Software becomes harder to exploit. Networks become better segmented. Encryption becomes stronger. But human psychology does not receive security patches. The cognitive biases that make social engineering effective, authority, urgency, reciprocity, liking, social proof, are features of the human operating system. They cannot be uninstalled.
This is precisely why social engineering skills are a core topic in cybersecurity interviews. Employers need professionals who understand both the technical and human dimensions of security. A SOC analyst who can detect a credential stuffing attack but cannot recognize a pretexting phone call has a critical blind spot.
The attackers who breached Twitter and MGM did not need zero day exploits. They needed research skills, confidence, and an understanding of human behavior. The defenders who stop the next attack will need the same understanding, applied from the opposite direction: recognizing when someone is attempting to manipulate them, and having the confidence and procedural support to push back.
Social engineering is not going away. It is becoming more sophisticated, more personalized, and more difficult to detect as attackers incorporate AI tools to craft convincing messages and deepfake audio to impersonate specific individuals. The organizations and individuals who invest in understanding these attacks, practicing recognition, and building verification into every sensitive process will be the ones who resist them.
Start with your own behavior. Review your social media profiles and consider what information an attacker could extract for a pretexting campaign. Test your organization's help desk by asking how they verify identity for credential resets. Have a conversation with your team about what a social engineering attempt would look like in your specific work environment. The best defense against manipulation is understanding how it works, and the best time to build that understanding is before the phone rings.
Frequently asked questions
- What is the most common type of social engineering attack?
- Phishing is the most common social engineering attack, accounting for over 80% of reported security incidents. Phishing uses emails, messages, or websites that impersonate trusted entities to trick people into revealing credentials, clicking malicious links, or downloading malware. Spear phishing, a targeted variant, is responsible for the majority of successful data breaches because attackers research their victims beforehand.
- How can I tell if I am being socially engineered?
- Watch for five red flags: manufactured urgency (act now or face consequences), requests that bypass normal procedures, appeals to authority (the CEO needs this immediately), unsolicited offers that seem too good to be true, and pressure to keep the interaction confidential. Legitimate requests can always withstand verification. If someone resists you confirming their identity through official channels, that resistance is the strongest indicator of a social engineering attempt.
- Why do social engineering attacks work even on smart people?
- Social engineering exploits cognitive biases that exist in all humans regardless of intelligence. Authority bias makes us comply with perceived superiors. Urgency suppresses critical thinking by activating our stress response. Reciprocity creates a sense of obligation when someone does us a favor. These are automatic psychological responses, not failures of intelligence. Even security professionals fall for well-crafted social engineering because the attacks are designed to bypass rational analysis.
- What should I do if I fall for a social engineering attack?
- Act immediately. Change compromised passwords and enable multi-factor authentication on affected accounts. Report the incident to your security team or IT department without delay. Do not attempt to fix the situation alone or hide what happened. Document everything you remember about the interaction: what information you shared, what links you clicked, and the timeline of events. Early reporting dramatically reduces the damage because security teams can contain the breach before attackers escalate access.
- How do organizations prevent social engineering attacks?
- Effective prevention combines three layers. First, security awareness training that includes realistic phishing simulations, not just annual compliance videos. Second, procedural controls such as callback verification for financial requests, dual approval for wire transfers, and strict visitor access policies. Third, technical controls including email filtering, multi-factor authentication, and endpoint detection. No single layer is sufficient. The goal is to create enough friction that attackers move to easier targets.
Daute built Unihackers after a decade defending airlines, managed SOCs and international organisations. He is an Associate C|CISO and a regular voice on AI and cybersecurity in international media. Silver Winner at the 2021 Cyber Security Excellence Awards. He teaches the way he wishes someone had taught him: skip the noise, train on what attackers actually do, and graduate people who are useful from day one.
View ProfileReady to Start Your Cybersecurity Career?
Join hundreds of professionals who've transitioned into cybersecurity with our hands-on bootcamp.

