Skip to content

Search ThreatNotes

Social Engineering Isn’t Just Email

We spent a decade teaching everyone to be suspicious of their inbox. Attackers responded by picking up the phone — where nobody is watching, nobody was trained, and being helpful is literally in the job description.

Yugesh9 min read

Ten years of awareness training genuinely worked. People hover over links now. They squint at sender addresses. They report things. Click rates on simulated phishing have fallen almost everywhere, and that’s a real achievement.

Attackers are not sentimental about their tools. When one door gets expensive, they use a different door — and every other door has had roughly none of the investment.

So you end up with this: the same person who would forensically examine a suspicious email will happily read a six-digit code down the phone to a polite stranger, because in ten years nobody ever mentioned that those are the same attack.

Some of the most damaging intrusions of recent years didn’t start with an exploit or a zero-day. They started with a phone call to a help desk, and someone being good at their job.

A pretext call, stage by stage

The structure is remarkably consistent. Once you’ve seen it laid out you can’t un-see it, which is rather the point of laying it out.

A pretext call, escalating stage by stage
  1. Step 1 of 6

    Homework — before the phone even rings

    Your org chart is on LinkedIn. Your email format is on a conference badge photo. Your helpdesk number is on your own support page. Somebody posted "excited to be starting at…" last Tuesday. None of this is stolen — you published it — and it is enough to write a convincing script.

  2. Step 2 of 6

    The opening — borrowed authority

    "Hi, it’s Dan from IT, I’m calling about the ticket for the mailbox migration." A named person, a named system, a reason. The first ten seconds are not trying to persuade you of anything — they are establishing that this is a normal call, so you stop assessing it and start cooperating.

  3. Step 3 of 6

    The small, harmless questions

    Which office are you in? Still on the old laptop? Nothing sensitive, and that is the point — each answer you give makes the next question feel more routine, and hands them details to reuse. Either on you, or on the next person they ring, who will hear their own office named back at them.

  4. Step 4 of 6

    A deadline you did not set

    The migration window shuts in twenty minutes. Your manager is copied in and waiting. Miss it and the account gets locked until Monday. Urgency is not set dressing — it is the mechanism. It exists for one purpose: to stop you hanging up and checking.

  5. Step 5 of 6

    The ask — and it always sounds tiny

    Read me the code that just came through. Approve the prompt on your phone. Let me connect for two minutes. Confirm your password so I can re-enter it my end. Each one sounds like an administrative step in a process. Each one is the entire account.

  6. Step 6 of 6

    And you were never the target anyway

    Your access becomes the credibility for the next call. "I’m already working with Sarah in Finance on this" is now completely true, and it is what makes the next person help. The prize is usually the support desk itself, because the support desk can reset anybody’s account.

The doors nobody is watching

Voice. Caller ID is trivially forgeable — “but it came from our internal number” means nothing at all. And voice cloning has quietly removed the other half of that defence: a few seconds of someone’s audio from a webinar or a podcast is now enough to build a convincing imitation. “It sounded like my boss” is no longer evidence of anything.

SMS. A missed delivery. A bank alert. “Hi mum, this is my new number, my phone broke.” Short, plausible, and read on a device where the full link is hidden and you’re walking somewhere.

Chat. A message in Teams or Slack borrows enormous credibility from simply being inside. But inside can mean a compromised colleague’s account, a guest in a shared channel, or a contractor’s tenant somebody federated in 2022 and forgot about.

The help desk, in reverse. This is the expensive one. Rather than tricking an employee, ring support pretending to be an employee, and ask for a password reset or a new MFA device. If your identity check is “confirm your employee number and date of birth” — both of which are discoverable — then your help desk will politely hand over the account and log a ticket about how quickly they resolved it.

In person. A hi-vis jacket and a clipboard is still, in 2026, a functioning security bypass. So is walking up to a badge door with your arms full of coffees and letting someone hold it open. Attackers rely on politeness far more than on technology, because politeness is more reliable.

QR codes. A sticker placed over the real code on a parking meter, a menu, a poster. The destination is completely unreadable before you commit — which isn’t a flaw in the attack, it’s the appeal.

Why people comply (it isn’t stupidity)

This is the bit that matters, and it’s where most training goes wrong. If your model is “some people are gullible”, you will build defences that don’t work, because the techniques exploit behaviours that are correct almost all of the time.

Authority. From your first day you’re trained to be responsive to IT, to finance, to anyone senior. “Question your manager’s urgent request” fights every other incentive the organisation has ever given you.

Urgency. Time pressure measurably degrades careful reasoning. That’s not a character defect, it’s how attention works under load. Every single pretext manufactures a deadline, and it’s not a coincidence.

Helpfulness. Support staff are measured on resolving things fast and being pleasant about it. An attacker calling the help desk isn’t exploiting a personality flaw — they’re exploiting the job description, and the KPIs.

Social cost. Challenging someone risks looking paranoid, or rude, or like you don’t recognise a colleague you’re supposed to know. Most organisations have never explicitly said that challenging is expected, so the individual carries that awkwardness alone. Most people, reasonably, decide it isn’t worth it.

Consistency. Once you’ve answered three harmless questions, saying no to the fourth feels strange — like changing your mind halfway through. Those small questions aren’t small talk. They’re the setup.

What actually helps

One rule, small enough to remember when you’re flustered:

Never give out a code, approve a prompt, or grant access because someone contacted you. Email, phone, chat, in person — no exceptions.

If the request is genuine, it survives you hanging up and calling back on a number you already had. Genuine IT will not mind. Genuine IT will be delighted.

Make the callback socially free — and say so out loud. This is an organisational job, not an individual one, and it’s the single highest-value thing on this page. Leadership has to state plainly: hanging up on anyone claiming to be IT and ringing the known number is correct behaviour, and will never be held against you. Without that, people will know the right answer and do the wrong thing anyway, because the social cost lands on them personally and the security benefit lands on everyone diffusely. That maths never works out in your favour.

Fix how the help desk proves identity. Anything discoverable is not verification: employee number, date of birth, manager’s name, last four digits of anything. Use a callback to the number on record, or a code pushed through an already-trusted channel, or manager sign-off for high-risk actions like MFA resets. This is where the genuinely expensive attacks land, and it is usually the cheapest thing on the list to fix.

Give people a fast, blameless way to report. If denying takes one tap and reporting takes a ticket form with a mandatory dropdown, you will get lots of denial and zero signal — and your security team will find out a campaign is running when the third person falls for it.

Rehearse the awkward sentence. Knowing the theory does not prepare you for a confident, slightly irritated person on the phone implying you’re being difficult. So have the words ready, literally: “I’m going to call you back on our internal number.” Say it once now, in your head. Having the sentence pre-loaded is most of the battle, because you will not compose it gracefully under pressure.

The one thing to take away

Security awareness that stops at the inbox leaves every other door wide open, and attackers have noticed. The attack was never the email. The attack is a stranger creating a reason to act quickly, through a channel where you can’t check.

So stop trying to defend each channel separately, and take the check off the channel entirely:

Whoever contacts you, however plausible, however urgent — verify through a route they did not give you.

That one habit generalises across email, phone, SMS, Teams, QR codes on lamp posts, and the confident bloke in reception with a clipboard and a lanyard he printed this morning.

Liked this? There's one every week.

New write-ups, course drops, and the Tuesday roundup — in a single email. No sponsors, one-click unsubscribe.

See what you’d get

Suggested for you

  • Course

    Intro to Phishing Defense

    How phishing actually works, how to spot it under time pressure, and exactly what to do in the first ten minutes after someone clicks.

  • Post

    Why MFA Fatigue Attacks Work

    The failure is not that users are careless. It is that push approval asks a question the user has no way to answer correctly — and asks it dozens of times until they slip.

  • Post

    Anatomy of a Phishing Email

    Stop trying to sense whether an email “feels off”. A phishing message has five jobs it must do to work, and every one of them leaves a mark you can check in about eight seconds.

Comments

Reactions and replies are powered by GitHub Discussions. Signing in with GitHub is required to post.