In 2020, attackers took control of the most high-profile accounts on Twitter — Obama, Musk, Apple, dozens more — and it started with a phone call. No zero-day. No malware. They called employees, posed as internal IT, and talked their way into the company's own admin tools. The most sophisticated breach of the year was, at its core, a conversation.
Social engineering isn't trickery. It's applied psychology, planned like a military operation — and it beats good people far more often than anyone wants to admit.
The Setup
Social engineering is the art of manipulating people into taking actions or revealing information that compromises security. It's the human side of hacking — and by almost every measure, it's the most effective attack vector in existence. The overwhelming majority of successful breaches involve a human element: someone clicked, someone replied, someone approved a request they should have questioned. Organizations pour fortunes into technical defenses while the most reliable way into almost any environment remains a well-crafted request to the right person.
What makes this worth examining isn't the fact that it happens — everyone knows phishing exists. It's how deliberate, researched, and psychologically precise a serious operation actually is. This is not a hooded figure guessing passwords. It's a planned campaign that studies its target, builds a believable story, and exploits the specific ways human judgment bends under pressure. Understanding how that campaign is built is the only thing that lets you see it coming.
What Everyone Assumed
The comforting assumption nearly everyone holds is this: I'm too smart to fall for that. We picture social engineering victims as careless or gullible — the person who wired money to a "prince," the one who used "password" as their password. So we reassure ourselves that awareness is protection. If I know phishing exists, I won't be phished. Intelligence and vigilance, we assume, are a reliable defense.
Social engineering doesn't target your intelligence. It targets your context — the moment, the pressure, the trust you've been maneuvered into. The smartest person in the company falls for the attack designed for the second they receive it, not the one they'd analyze at leisure.
This is the assumption that makes people vulnerable, because it aims the defense at the wrong thing. A skilled social engineer isn't trying to fool a calm, skeptical analyst studying an email in a training exercise. They're engineering a situation where your critical thinking is deliberately bypassed — where you're busy, distracted, under time pressure, wanting to be helpful, afraid of consequences, or simply doing what someone in authority appears to have asked. Intelligence offers almost no protection in that state, because the attack was never aimed at your intelligence in the first place.
How It Actually Works
A serious operation begins with reconnaissance, and the amount of information freely available about any organization is staggering. Consider a real pattern: an attacker spends a week reading a company's LinkedIn. They learn the new finance hire started three weeks ago, the CFO is speaking at a conference in Singapore this Thursday, and the company just announced a vendor partnership. That's everything needed. Thursday afternoon, the new hire gets a call — the CFO's assistant, calling from the conference, needs an urgent payment pushed to the new vendor before the CFO lands. The recon didn't find a vulnerability. It found a moment.
That call is the pretext — the believable story that justifies the request, and the craft at the heart of social engineering. A good pretext doesn't feel like an attack because it fits perfectly into the target's normal working reality. A call from "IT" during a known system migration. An email from a "vendor" the company genuinely uses, referencing a real invoice. A message from the "CEO" who, according to their public calendar, is actually traveling and plausibly hard to reach. The pretext borrows the target's own reality and turns it into a stage. It succeeds precisely because it doesn't feel remarkable.
The psychological levers
Authority: we defer to people who seem in charge. Urgency: pressure collapses careful thinking. Social proof: if others appear to have complied, we follow. Liking: we help people we find agreeable. Fear: the threat of consequences overrides caution. Skilled operators stack several at once.
Then comes the escalation, and this is the part people underestimate. Social engineers rarely ask for everything at once. They start with something small and reasonable — confirm your name, verify a department, a request too trivial to refuse. Each small compliance builds momentum and rapport, and makes the next, slightly larger request feel consistent with what you've already done. By the time the real ask arrives — reset this password, approve this transfer, read out this code — you're not evaluating it cold. You're several steps into a relationship the attacker carefully constructed, and refusing now would mean reversing a course you've been agreeing to for minutes. Compliance has momentum, and the operator has been building it the entire time.
And the pretext is about to become nearly unbeatable. In 2024, a finance employee at the engineering firm Arup joined a routine video call with the company's CFO and several colleagues, and — on their instruction — approved transfers totaling around 25 million dollars. Every person on that call except the victim was an AI-generated deepfake. The voices were cloned, the faces were synthetic, the whole meeting was a fabrication. The oldest attack in security just gained the ability to manufacture a face and a voice you trust. The recon still finds the moment. Now the pretext can look and sound like anyone.
Decoded
The mental model that changes everything is this: social engineering doesn't attack you, it attacks the situation you're in. The defense, therefore, isn't being smarter or more suspicious of people — it's recognizing the shape of the situation itself. Urgency combined with a request for access or information. An unusual ask wrapped in a completely normal-feeling context. Any moment where you feel pressure to act before you've had time to verify. The specific person contacting you barely matters — and in a world of deepfakes, the person you see and hear may not be real at all. The structure of the moment is the tell, and the structure is far easier to spot than the lie.
This reframes the defense entirely. You don't beat social engineering by detecting deception in real time — humans are genuinely bad at that, and deepfakes have now made the evidence of your own eyes and ears unreliable. You beat it by building a single reflex: when a situation carries urgency plus a request for access or money, you slow down and verify through a separate, trusted channel you initiate yourself. Not the number in the email. Not the link they sent. Not a callback on the same video call. A channel you already trust, reached the way you always reach it. That one habit — verify out of band, especially when you're being rushed — defeats the overwhelming majority of these operations, because it breaks the one thing every social engineering attack depends on: your decision, made inside the moment they built for you.
And here's the part that rarely gets said out loud. The people who fall for these operations are almost never foolish — they're helpful, busy, and doing exactly what a good employee should do, which is precisely why it works. The attacker didn't exploit a flaw in the victim. They exploited a virtue. What happens next is quieter and just as damaging: the shame. Victims replay the moment, certain they should have known, and that shame keeps them silent — which is exactly what the attacker is counting on, because every hour a compromise goes unreported is another hour of access. If it ever happens to you, the single most valuable thing you can do is say so immediately. Speed of reporting beats perfection of judgment every time.
So I'm curious, and I mean this genuinely: has anyone ever tried to social-engineer you — a strange call, an off email, a request that felt subtly wrong — and what was the detail that finally tipped you off? Hit reply and tell me. I collect these stories, because the tells are where the real learning is.
This week's question
Has anyone ever tried to social-engineer you — a strange call, an off email, a request that felt subtly wrong? What was the detail that tipped you off? Hit reply. I collect these stories.
Think clearly,
— DJ Brar
SKBSEC | SKB Decoded · www.skbsec.com