All articles
Social engineering

Social engineering

Manipulating people to bypass technical security controls.

What it is

Attackers call your support team, impersonate vendors, or pretend to be executives to get someone with access to do something they shouldn't.

How attackers exploit it

A confident phone call to IT to 'reset MFA' often works better than any 0-day. Helpdesk staff are the highest-value target after admins.

How to protect against it

  • Verify identity through a second channel before any account or MFA change.
  • Define escalation paths for unusual requests, even (especially) from execs.
  • Limit who can change MFA / recovery info — make it an internal request, not a self-service action.
Reference videos
Social engineering tactics
CBT Nuggets
Further reading

Want to see if your site is at risk?

Run a free scan and get a Hackability Score for your site.