Pretexting builds a false scenario to extract information. The attacker invents a reason to call, email, or visit. They are an IT technician fixing a problem. A vendor updating records. An auditor verifying compliance. The story gives them a reason to ask questions, and the answers give them what they need. Pretexting is pure social engineering. No malware, no exploit. Just a convincing lie.
The technique works because people want to be helpful. A caller who knows the right names and department structure sounds legitimate. A visitor with a clipboard and a badge-shaped lanyard walks past reception. Pretexting often combines with other techniques. A phone call establishes the pretext. A follow-up email with a malicious link exploits the trust built in the call. The 2020 Twitter hack used pretexting to convince employees to hand over credentials for internal tools. The attackers then took over high-profile accounts. Defense requires verification. Call back on a known number. Confirm identity through a separate channel. Train staff to question unusual requests, even when the requester sounds authoritative.
Common pretexts
- IT support — fixing a problem that requires your credentials
- Vendor verification — updating account or payment details
- Executive request — urgent task from a senior leader
- Auditor — compliance check requiring sensitive data
- New employee — needs access or information to do their job
Pretexting exploits trust and process gaps. Strong verification procedures make the lie harder to sustain.
Comments (2)
Leave a comment