Skip to content

Recognizing social engineering — and verifying out of band

Attackers manipulate people, not just computers. Learn the pressure tactics they use and the simple rule that stops them: verify through a channel you already trust.

EveryoneIntro6 min· Updated Jul 22, 2026
TL;DR

The short version

Social engineering is manipulation — pretending to be someone you trust to get you to act against your interests. It exploits helpfulness, authority, and urgency. The defense is to verify any unusual or urgent request through a separate, trusted channel before you act, no matter who it appears to come from.

Not every attack goes after a computer. Many go after a person — the assistant who can reset a password, the finance clerk who can move money, anyone who can be persuaded to open a door. Social engineering is the art of that persuasion: the attacker builds a believable story and applies just enough pressure that helping them feels like the natural thing to do.

The levers they pull

  • **Authority** — posing as an executive, IT, a police officer, or a vendor, because we're trained to comply with authority.
  • **Urgency** — "I need this in the next ten minutes or we lose the deal," to stop you from pausing to check.
  • **Familiarity and trust** — using a colleague's name, a real project detail, or a spoofed number so it feels routine.
  • **Fear** — a threatened account suspension, a fake legal problem, or claimed fraud on your account.
  • **Helpfulness** — most people want to be helpful, and attackers count on it.

These come in many forms: a phone call ("vishing"), a text ("smishing"), an email, or even someone in person tailgating through a secure door. The channel changes; the playbook doesn't.

Pitfall

Caller ID and email names can be faked

A call that shows your bank's name, or an email from what looks like your CEO's address, proves nothing — both are easy to spoof. Never let a familiar-looking name substitute for actually verifying the request.

The one rule: verify out of band

"Out of band" means using a different, independent channel than the one the request came in on. If your "CEO" emails asking you to urgently buy gift cards or change payroll details, call or message them on a number you already have — not the one in the email. If "IT" calls asking for your password or a code, hang up and call the IT helpdesk on the official number. Verifying through a trusted channel costs you a minute and costs the attacker everything, because their whole scheme depends on you staying inside the conversation they control.

Requests that should always trigger a check

  • Any request to move money, change bank or payroll details, or buy gift cards.
  • Anyone asking for your password, a one-time code, or to approve an MFA prompt.
  • Pressure to bypass a normal process "just this once" or to keep it secret.
  • A vendor or executive whose request is urgent, unusual, and hard to question.

Verifying an unusual request is never an insult and never a career risk — any real leader wants you to check. If someone pressures you not to verify, that pressure is itself the biggest red flag.