Social Engineering: Hacking the Human Instead of the Computer
The easiest system to break into is often a person. Social engineering is the art of persuading someone to help an attacker.
2 min readBeginner Aug 14, 2026
Explain Like I'm Not a Hacker
Social engineering is a con artist in a hi-vis vest: nobody stops them because they look like they belong.
The 30-second explanation
Instead of breaking through a firewall, the attacker calls, messages or visits and simply asks, in a convincing way, for what they want.
How it works
- 1
1. Research
The attacker learns names, roles and routines.
- 2
2. Pretext
They pose as someone you would trust.
- 3
3. Pressure
Urgency or authority pushes you to act quickly.
- 4
4. Ask
A small request that opens a bigger door.
Attackers research who you work with, then pretend to be one of them: IT support, a manager, a supplier, a delivery driver. They create pressure (a deadline, a problem, an important person) so you act before thinking. The request is usually small: reset a password, read out a code, hold a door, open a file. Each small yes can unlock a large breach.
Real-world example
Someone calls saying they are from the IT helpdesk and that your account will be locked in ten minutes unless you read out the code that was just texted to you. The code is the attacker's own login attempt. Reading it out hands over the account.
How to spot it
Unexpected urgency
A deadline or threat that leaves no time to check.
Requests for codes or passwords
Genuine support never needs your one-time code.
Unusual channel
A request that arrives through a route the person never normally uses.
Flattery or authority
Name-dropping executives to discourage questions.
What to do
- 1Slow down: verify the person through a channel you already trust, such as a number from the official directory.
- 2Never share one-time codes or passwords, whoever is asking.
- 3Report suspicious contacts even when you did not fall for them, so others can be warned.
Stay curious. Stay safer.
This is one piece of a bigger picture. Explore more real-world examples, concepts and tips to build your cybersecurity awareness.