Human layer

What is Social Engineering?

The business guide to social engineering, the attacks that target your people instead of your systems, and the controls that actually stop them.

Key takeaways
  • Social engineering attacks the person with legitimate access rather than the software, which is why technical hardening alone does not close it.
  • ENISA found that phishing in its various forms accounted for about 60 percent of observed initial access cases in its EU dataset for 2025, ahead of vulnerability exploitation at 21.3 percent.
  • The channel is moving. CERT-EU reported that email spearphishing fell from 41 percent to 31 percent of initial access attempts in 2025 as voice phishing, ClickFix and device-code abuse grew.
  • Of 33,514 attempted frauds reported to the Swedish Police in 2025, 25,199 were attempted vishing, which is 75.2 percent of all attempts.
  • Swedish Police estimate VD/BEC fraud generated about SEK 214 million and vishing about SEK 320 million in criminal proceeds during 2025.
  • Losses are concentrating. Victims losing more than SEK 1 million to VD/BEC fraud rose from 4 in 2023 to 21 in 2025, and proceeds in that bracket rose from about SEK 19 million to about SEK 161 million.
  • Business email compromise accounted for about 3.05 billion dollars in losses reported to the FBI in 2025, from a record 1,008,597 complaints.
  • A randomised trial of more than 19,500 employees, published at IEEE Security and Privacy in 2025, found no significant relationship between recent annual awareness training and failing a phishing simulation.
  • The lure matters more than the learner. In the same trial one lure drew 1.82 percent of clicks and another drew 30.8 percent.
  • Phishing-resistant MFA, help desk identity proofing and callback verification are the controls that hold, and NIS2 Article 21.2g makes awareness training a legal duty under Cybersäkerhetslagen.

Social Engineering Defined in Plain Terms

Social engineering is the manipulation of people into handing over access, information or money. Instead of breaking into a system, the attacker persuades someone who already has legitimate access to act against their own organisation. It arrives as an email, a phone call, a text message or a visitor at reception and it works because the request looks routine.

The technique is old. What has changed is that it is now the main way attackers get in.

The ENISA Threat Landscape 2025, published in October 2025 and built on 4,875 incidents affecting the EU, found that social engineering remains the primary entry point for threat actors. Phishing in its various forms accounted for about 60 percent of observed initial access cases. Exploiting a software vulnerability came second at 21.3 percent.

That ratio is the business problem. Most organisations have spent a decade hardening the technical perimeter and comparatively little on the decisions their staff make under pressure. An attacker who can get a help desk agent to reset a password does not need an exploit, a zero-day or any malware at all. They log in.

Social engineering covers a family of attacks. Phishing, voice phishing, business email compromise and help desk impersonation all sit inside it and they share one mechanism. A person is asked to do something reasonable-sounding by someone who is not who they claim to be.

How a Social Engineering Attack Works

Almost every campaign follows the same five steps whether it takes ten minutes or ten weeks.

  • Research: The attacker maps the organisation from public sources, company websites, professional networks, job adverts and breach data to learn names, reporting lines, suppliers and the words your business actually uses
  • Pretext: They build a believable reason to make contact, usually an identity that carries authority or urgency such as a new starter locked out, an auditor, a supplier chasing payment or an executive travelling
  • Contact: They reach the target on the channel with the least verification which is increasingly a phone call, a chat message or a QR code rather than email
  • Pressure: They introduce time pressure, secrecy or the appearance of authority so the target skips the step that would expose them
  • The ask: They request one specific action, a password reset, an MFA approval, a payment, a bank-detail change or an app authorisation, then leave quickly
How a Social Engineering Attack Works

The last step is the tell. The attacker needs one narrow action completed before anyone thinks to check it.

Three things have made this easier since 2023. Personal and corporate data is cheap and plentiful, so a pretext can be filled with accurate detail. Generative AI removes the language barrier which historically protected Swedish organisations because clumsy Swedish was the giveaway. Phishing-as-a-service platforms sell ready-made campaigns to operators with no technical skill, a trend ENISA documented in its 2025 report.

The channels have shifted too. CERT-EU, the cybersecurity service for the EU institutions, reported in April 2026 that email-based spearphishing fell from 41 percent to 31 percent of initial access attempts against EU entities during 2025 while voice phishing, adversary-in-the-middle attacks, ClickFix lures and device-code authentication abuse all grew. The pattern is a shift in channel, away from the inbox and towards the phone and the browser.

Types of Social Engineering Attacks

The names matter less than the channel and the ask, but a shared vocabulary helps a team report what it is seeing.

  • Phishing: Mass email designed to harvest credentials or deliver malware, now usually pointing at a cloned login page
  • Spear phishing: A targeted version written for one person using real details about their work
  • Business email compromise: Fraud that impersonates an executive or a supplier to redirect a payment, known in Sweden as VD-bedrägeri
  • Vishing: A phone call, increasingly with a cloned voice, aimed at a help desk, a finance team or a customer
  • Smishing: The same approach over SMS or a messaging app where there is no sender authentication and no security banner
  • Quishing: A QR code that carries the victim from a monitored corporate device to an unmonitored phone
  • Pretexting: The invented scenario that makes the request sound legitimate which is the engine inside most of the other types
  • Help desk impersonation: Calling internal IT while posing as an employee to obtain a password reset or an MFA factor transfer
  • MFA fatigue: Repeated push notifications sent until a tired user approves one also called push bombing
  • ClickFix: A fake CAPTCHA or error message that instructs the visitor to paste and run a command which ENISA flagged as a fast-growing technique in 2025
  • Baiting: A dropped USB stick, a pirated file or a free offer that the victim installs themselves
  • Tailgating: Walking into a building behind an employee still effective wherever a door badge is the only control
  • Insider recruitment: Bribing or coercing a person with access rather than deceiving them

Pretexting deserves its own definition because it is the term buyers ask about most. Pretexting in cyber security is the use of a fabricated identity and a fabricated reason to obtain information, access or money.

The attacker is not asking you to click anything. They are asking you to believe them, which is why technical controls rarely catch it and why the countermeasure is a verification procedure rather than a filter.

Voice phishing now runs at industrial scale. CERT-EU recorded a single 2025 campaign by the actor tracked as UNC6040 that used phone calls to persuade staff at more than 90 organisations worldwide to authorise a malicious application inside their Salesforce environments. Several suppliers to EU institutions were among those affected. No malware was needed because the victims granted the access themselves.

The Business Impact of Social Engineering

Sweden publishes unusually good numbers on this. Nationellt bedrägericentrum, the national fraud centre at Polismyndigheten, estimated in an April 2026 analysis that completed frauds reported to the Swedish Police during 2025 generated about SEK 5.7 billion for criminal actors, down roughly 10% on 2024. Two categories in that report are pure social engineering against organisations and their staff.

  • VD/BEC fraud: About SEK 214 million in estimated proceeds during 2025 down 12% year on year
  • Vishing fraud: About SEK 320 million in estimated proceeds during 2025 down 25% year on year

The headline decline hides the part that should worry a finance director. Within VD/BEC fraud the number of victims losing more than SEK 1 million rose from 4 in 2023 to 13 in 2024 and 21 in 2025 while the proceeds in that bracket went from about SEK 19 million to about SEK 34 million and then to about SEK 161 million. Fewer successful frauds, much larger individual hits.

Attempts tell the same story from the other end. Of 33,514 attempted frauds reported to the Swedish Police in 2025, 25,199 were attempted vishing which is 75.2% of all attempts and an 8 percent increase on 2024.

Three quarters of the fraud attempts reported in Sweden last year were somebody on the phone pretending to be someone else. These figures cover reported crime only and the police note that the true volume is higher.

For scale in another market, the FBI’s Internet Crime Complaint Center logged 1,008,597 complaints in 2025, up from 859,532 the year before, with business email compromise alone accounting for about 3.05 billion dollars in reported losses. That is US-reported data so it is not a global total but it establishes the order of magnitude for a single social engineering technique.

Money is only the first cost. A successful attack on an identity system can stop trading for weeks, trigger a 24-hour regulatory clock, expose customer data that is then used to defraud those same customers and put the board in the frame under NIS2 Article 20. The cases below are named because the public record shows exactly how each began.

Real-World Social Engineering Examples

MGM Resorts and the IT Help Desk

MGM Resorts disclosed a cybersecurity incident in September 2023 that took down hotel systems, casino floors and booking platforms across its US properties.

In a Form 8-K filed with the SEC on 5 October 2023, the company estimated a negative impact of approximately 100 million dollars on Adjusted Property EBITDAR from the September incident, plus under 10 million dollars in one-off expenses. It expected cyber insurance to cover the financial impact.

The intrusion pattern is documented by the FBI and CISA in joint advisory AA23-320A, updated in July 2025. The actor set behind this wave impersonates employees to IT help desks to obtain password resets and MFA factor transfers, then installs legitimate remote access tools rather than malware.

A help desk needs an identity-proofing standard that does not rely on facts an attacker can scrape from a professional network. No credential or MFA reset should complete on the strength of a voice alone.

Real-World Social Engineering Examples

Marks and Spencer and the Outsourced Service Desk

The UK retailer lost about six weeks of online trading after an attack in April 2025. Chairman Archie Norman told the House of Commons Business and Trade Sub-Committee on 8 July 2025 that initial entry happened on 17 April through social engineering which he described as a sophisticated impersonation rather than a simple request, and that a third party was involved in the point of entry.

Marks and Spencer told investors in May 2025 that it expected the incident to reduce operating profit by roughly 300 million pounds before mitigation. Online ordering restarted in June after about six weeks.

What makes this case instructive is where the weakness sat. A service desk operated outside the company could still reset an internal user’s password which places it inside the identity perimeter while sitting outside most threat models. Any supplier able to reset your credentials should meet your identity-proofing standard as a contract term alongside the usual response-time targets.

Arup and the Deepfake Video Call

In January 2024 a finance employee at the Hong Kong office of the engineering firm Arup received a message that appeared to come from the UK-based chief financial officer about a confidential transaction. Suspecting a phishing attempt, the employee did what training encourages and asked to speak to people directly.

The video call that followed contained the CFO and several familiar colleagues. All of them were AI recreations. The employee made 15 transfers to five Hong Kong bank accounts totalling HK$200 million, about 25.6 million dollars and the fraud surfaced only when he later checked with head office.

Arup confirmed publicly in May 2024 that fake voices and images had been used. It added that its financial stability and operations were unaffected and no internal systems were compromised. The money was not reported as recovered.

Verification failed because it happened inside the channel the attacker controlled. A callback on a number taken from the internal directory or a second approver on a payment of that size would have broken the illusion in seconds.

Coinbase and the Bribed Support Agents

Coinbase disclosed in a Form 8-K dated 14 May 2025 that criminals had bribed overseas customer support agents to steal customer records which were then used to run social engineering attacks against those customers. The company preliminarily estimated expenses of 180 million to 400 million dollars for remediation and voluntary customer reimbursement.

Coinbase refused the 20 million dollar extortion demand offered the same sum as a reward for information leading to arrests and said passwords, private keys and customer funds were never exposed.

Support tooling that can display bulk customer records needs least-privilege access and alerting on unusual volumes. Stolen customer data also becomes a fraud problem for those customers within days so warn them before the attacker calls.

Social Engineering and Compliance in Sweden

The human layer stopped being a matter of good practice in January 2026. Cybersäkerhetslagen, SFS 2025:1506, entered into force on 15 January 2026 and transposes the EU NIS2 Directive into Swedish law. For essential and important entities, the measures below are supervised obligations rather than recommendations.

  • NIS2 Article 21.2g: Basic cyber hygiene practices and security awareness training are a required risk-management measure
  • NIS2 Article 21.2b: Incident handling and reporting must be in place before you need it
  • NIS2 Article 21.2d: Supply-chain security covers the service desk you outsourced along with everything else
  • NIS2 Article 20: The management body approves and oversees these measures and can be held personally accountable for failures

The reporting cascade runs to MCF (formerly MSB) and the relevant sector authority. An early warning is due within 24 hours of becoming aware of a significant incident, a full notification within 72 hours and a final report within one month. A stolen credential obtained by phone starts that clock in the same way a ransomware detonation does.

Fines reach 10 million euro or 2 percent of global turnover for essential entities and 7 million euro or 1.4 percent for important entities.

Two other regimes usually apply at the same time. Under GDPR Article 33, a personal data breach must be notified to IMY within 72 hours and a phishing attack that exposes an employee mailbox is a common trigger. For financial entities, DORA Article 17 sets the ICT incident management requirements supervised by Finansinspektionen.

In practice, awareness training satisfies part of Article 21.2g and a documented verification procedure with evidence that people follow it is what satisfies an auditor asking how you manage the risk. Our NIS2 Sweden compliance guide covers the wider obligation set with parallel detail on GDPR compliance in Sweden and DORA compliance for financial entities.

How to Spot Social Engineering

Forget spelling mistakes. Generative AI writes fluent Swedish and fluent English and the branding on a cloned login page is usually perfect. The reliable tells are behavioural and procedural.

  • A request arrives with a deadline attached that only the sender set
  • You are asked to keep it quiet or told the normal approver is unavailable
  • The contact moves you to a channel with less verification such as a mobile number, WhatsApp or a personal address
  • The request asks you to step outside a normal process
  • Bank details, a delivery address or a payroll account need changing today
  • An MFA prompt appears that you did not trigger or several arrive in a row
  • Somebody resists a callback on a number you already hold
  • The story explains why the usual check cannot be done this time

The last one is the strongest signal in the list. A legitimate colleague may be in a hurry. Almost none of them will argue against being verified.

Now the caveat that most guidance leaves out. Human detection is not a control you can rely on. In a randomised controlled trial published at the IEEE Symposium on Security and Privacy in 2025, researchers ran ten simulated phishing campaigns against more than 19,500 employees of a large healthcare organisation over eight months. They found no significant relationship between having recently completed annual awareness training and failing a simulation.

The same study found that the lure mattered far more than the person. A fake Outlook password notice was clicked by 1.82 percent of recipients. A fake update to the organisation’s holiday policy was clicked by 30.8 percent.

Employees in the training groups failed at a rate only about 1.7 percentage points below the untrained control group and training delivered straight after a click improved matters by roughly 2 percentage points.

Read that as a design instruction rather than an argument against training. Spotting attacks is a useful supplement. Build the defence on controls that still hold after someone clicks because a well-timed message will get clicked in any organisation of any size.

How to Defend Against Social Engineering

The controls that work assume a person will eventually be fooled and remove the value of fooling them. Start with authentication then fix the procedures an attacker actually targets.

How to Defend Against Social Engineering

Technology

  • Deploy phishing-resistant multi-factor authentication, FIDO2 or WebAuthn security keys or PKI-based certificates. The FBI and CISA name this specifically in advisory AA23-320A because it defeats push bombing, SIM swapping and credential replay
  • Roll out a password manager that only fills credentials on the correct domain which the IEEE 2025 researchers recommend as a higher-return investment than more training
  • Alert on identity events rather than email content including MFA factor changes, new device enrolments, help desk password resets, mass application consent and impossible travel
  • Put a clear external-sender banner on inbound mail and give every user a one-click report button that reaches someone who acts on it

Process

  • Write an identity-proofing standard for the help desk that does not depend on information an attacker can buy, scrape or guess and require a second channel for any credential or MFA change
  • Make callbacks mandatory for payment and bank-detail changes, always to a number from your own records rather than one supplied in the request
  • Require two approvers above a payment threshold you set and treat urgency or secrecy as a reason to slow down instead of speed up
  • Bind outsourced service desks and managed IT suppliers to the same standard in the contract, then audit against it
  • Rehearse the 24-hour NIS2 early warning so the first hour of an incident runs on procedure

People

  • Teach the procedure, not the trivia. When a request feels wrong the answer is always the same. Stop, verify on a number you already hold and tell the security team
  • Report without blame. An employee who realises at 16:55 that they approved something odd must feel able to say so immediately because the response window is measured in minutes
  • Practise against realistic attempts including voice and help desk scenarios since email simulations alone no longer match how the attacks arrive

Our security awareness training is built around this behaviour and social engineering testing forms part of a penetration testing engagement. Where the concern is what happens after someone is fooled, managed detection and response exists to catch the identity misuse that follows.

If you do one thing after reading this, make it this one. Pick your highest-risk action, usually a payment or a credential reset and write down the verification step that must happen every single time before it completes. Then tell the people who perform it that following that step is never the wrong call.

Myths & Facts

Myth

Social engineering means phishing emails.

Our staff have done the training, so we are covered.

Only careless or junior people fall for it.

Multi-factor authentication stops social engineering.

A live video call proves who you are talking to.

This is an IT problem.

Fact

Email is one channel and a shrinking one. CERT-EU found email spearphishing fell from 41 percent to 31 percent of initial access attempts in 2025 while voice phishing, ClickFix lures and browser-based tricks grew.

A randomised trial of more than 19,500 employees published at IEEE Security and Privacy in 2025 found no significant link between recently completing annual awareness training and failing a phishing simulation.

The same trial showed the message matters more than the recipient. A dull password notice drew 1.82 percent of clicks and a fake holiday-policy update drew 30.8 percent of the same population.

Push bombing, SIM swapping and help desk factor resets all defeat ordinary MFA. The FBI and CISA recommend phishing-resistant MFA using FIDO or WebAuthn, which these techniques cannot bypass.

At Arup in January 2024 a finance employee joined a call with the CFO and colleagues, all of whom were AI recreations, and transferred HK$200 million in 15 payments before checking with head office.

The targets are finance, HR, customer support and the help desk. Under NIS2 Article 20 the management body approves and oversees these measures and can be held personally accountable.

Test Yourself

Four real-world scenarios, then six knowledge questions. See how prepared you would be under pressure.

Scenario Simulation

  1. A caller reaches your IT help desk. They give a real employee name, the correct manager and a plausible story about being locked out before a customer meeting. They ask for a password reset and a new MFA device.

    What do you do?

    • Reset the password because the details all check out
    • Verify through a separate channel from your own records before resetting anything
    • Reset the password but not the MFA device
    • Ask them to email the request from their work address
  2. Your CFO joins a video call with two colleagues you recognise. They ask you to make an urgent confidential transfer today and to keep it off the normal approval chain.

    What do you do?

    • Proceed, since you can see and hear the people involved
    • Ask them to confirm in writing on the same call
    • End the call and confirm on a number from the internal directory before acting
    • Send a smaller test payment first
  3. A supplier emails from the usual address to say their bank details have changed and this month's invoice should go to a new account.

    What do you do?

    • Update the details, since the email came from the known address
    • Reply to the email to ask for confirmation
    • Call the supplier on the number already in your records and confirm the change
    • Pay the invoice and reconcile the details next month
  4. You approved an MFA push notification late in the afternoon without thinking, then realised you had not been logging in. It is 16:55 on a Friday.

    What do you do?

    • Wait until Monday and mention it to IT then
    • Change your password and assume that resolves it
    • Report it immediately so sessions can be revoked and the account checked
    • Disconnect from the network and say nothing

Knowledge Test

  1. According to ENISA's Threat Landscape 2025, roughly what share of observed initial access cases involved phishing?

    • About 20 percent
    • About 40 percent
    • About 60 percent
    • About 90 percent

    ENISA put phishing in its various forms at about 60 percent of observed cases, ahead of vulnerability exploitation at 21.3 percent.

  2. What is pretexting?

    • Sending malware disguised as an invoice
    • Using an invented identity and reason to obtain access or money
    • Intercepting traffic on a public network
    • Guessing passwords from leaked data

    Pretexting is the fabricated story and identity that makes a malicious request sound like a routine one.

  3. Of the 33,514 attempted frauds reported to the Swedish Police in 2025, what share were attempted vishing?

    • About 15 percent
    • About 40 percent
    • About 75 percent
    • About 95 percent

    25,199 of the attempts were vishing, which is 75.2 percent of everything reported as an attempt that year.

  4. What did the 2025 IEEE study of more than 19,500 employees find about annual awareness training?

    • It halved the failure rate
    • It had no significant relationship with failing a phishing simulation
    • It only worked for technical staff
    • It increased reporting tenfold

    The researchers found no significant relationship between recently completing training and failing a simulation, and only about a 1.7 percentage point difference against the control group.

  5. Which control do the FBI and CISA specifically recommend against push bombing and SIM swapping?

    • Longer passwords
    • Quarterly awareness training
    • Phishing-resistant MFA using FIDO or WebAuthn
    • Blocking external email

    Joint advisory AA23-320A names FIDO or WebAuthn and PKI-based MFA as resistant to push bombing and SIM swap attacks.

  6. Under Cybersäkerhetslagen and NIS2, how quickly must an early warning reach MCF for a significant incident?

    • 24 hours
    • 72 hours
    • One week
    • One month

    The cascade is 24 hours for the early warning, 72 hours for the full notification and one month for the final report.

Why Training Matters

Training earns its place when it changes a procedure rather than transferring facts. The evidence is blunt about the difference. The 2025 IEEE study found annual awareness training had no significant effect on whether employees failed a phishing simulation, while an ETH Zurich study of 14,733 employees found that warning banners and an easy reporting button did measurably help.

So train for behaviour. Staff need to know the one verification step that applies to their highest-risk action, how to report in seconds and that pausing a suspicious request will never be held against them. Voice and help desk scenarios belong in the programme too, because that is where the attempts now arrive.

eBuilder Security delivers security awareness training for Swedish organisations through the Complorer platform, with phishing simulation and role-based scenarios for the teams that attackers target first.

Frequently Asked Questions

What is social engineering in cyber security?

Social engineering is the manipulation of people into giving away access, information or money. Rather than exploiting software, the attacker persuades someone with legitimate access to act for them. ENISA found it remains the primary entry point for attackers in the EU, with phishing alone accounting for about 60 percent of observed initial access cases in 2025.

What is pretexting in cyber security?

Pretexting is the use of an invented identity and an invented reason to obtain information, access or money. The attacker poses as an auditor, a new employee, a supplier or an executive and builds a story that makes the request sound routine. Because nothing malicious is attached, filters rarely catch it and verification procedures are the countermeasure.

What are the most common types of social engineering attacks?

The common types are phishing, spear phishing, business email compromise, vishing, smishing, quishing, pretexting, help desk impersonation, MFA fatigue, baiting and tailgating. In Sweden voice-based attacks dominate reported attempts. Of 33,514 attempted frauds reported to the Swedish Police in 2025, 25,199 were attempted vishing.

What is an example of a social engineering attack?

In April 2025 attackers impersonated an employee to an outsourced IT service desk and obtained a password reset at Marks and Spencer. The retailer's chairman described it to a parliamentary committee as sophisticated impersonation. The company told investors the incident would cost roughly 300 million pounds in operating profit before mitigation.

What is the difference between social engineering and phishing?

Phishing is one technique inside social engineering. Social engineering is the whole category of attacks that manipulate people, including phone calls, text messages, QR codes, in-person visits and bribery. Every phishing attack is social engineering, but a vishing call to your help desk is social engineering without any phishing email involved.

Does security awareness training stop social engineering?

Not on its own. A randomised controlled trial of more than 19,500 employees published at IEEE Security and Privacy in 2025 found no significant relationship between recent annual training and failing a phishing simulation. Training that teaches a verification procedure, backed by phishing-resistant MFA and payment controls, is what changes outcomes.

Does MFA protect against social engineering?

Ordinary multi-factor authentication helps but is bypassed routinely. Attackers use push bombing, SIM swapping, adversary-in-the-middle pages and help desk factor resets. The FBI and CISA recommend phishing-resistant MFA based on FIDO, WebAuthn or PKI certificates, which resists all four of those techniques.

What does NIS2 require about social engineering?

NIS2 Article 21.2g requires basic cyber hygiene practices and security awareness training as a risk-management measure, and Article 20 makes the management body accountable for approving and overseeing them. In Sweden this applies through Cybersäkerhetslagen, SFS 2025:1506, in force since 15 January 2026.

What should we do if an employee falls for a social engineering attack?

Revoke the session and reset the affected credentials and MFA factors immediately, then check for mailbox rules, new device enrolments and application consents. If the incident is significant, an early warning is due to MCF (formerly MSB) within 24 hours, and any personal data breach must reach IMY within 72 hours.

You Understand the Risk.
Now See Where You Stand.

Book a 30-minute briefing with one of our analysts, or run the free breach check first to find out what attackers already know about your organisation.

Book a 30-Min Briefing
No sales pitch, just a straight assessment

How eBuilder Security Can Help

Awareness is the first layer. These are the services that turn it into measurable protection.