Social Engineering: The Hack That Doesn’t Need a Computer

In July 2020, Twitter had a problem. The accounts of Barack Obama, Elon Musk, Bill Gates, Apple, and about 130 other high-profile users started tweeting a Bitcoin scam. The attackers didn't exploit a software vulnerability. They didn't find a zero-day. They called Twitter employees, pretended to be

In July 2020, Twitter had a problem. The accounts of Barack Obama, Elon Musk, Bill Gates, Apple, and about 130 other high-profile users started tweeting a Bitcoin scam. The attackers didn't exploit a software vulnerability. They didn't find a zero-day. They called Twitter employees, pretended to be from the IT department, and talked their way into internal admin tools.

The whole thing was masterminded by a 17-year-old from Florida.

That's social engineering in its purest form. No malware. No code. Just a human being convincing another human being to do something they shouldn't. And it works on everyone, including the security team at one of the largest social media companies on the planet.

Let me walk you through the main flavors of social engineering, because once you understand the mechanics, the attacks become a lot easier to spot.

Pretexting: the art of the believable lie

Pretexting is when an attacker creates a fabricated scenario (the pretext) to gain your trust or manipulate you into giving up information. It's the foundation of almost every social engineering attack.

The Twitter attackers used pretexting. They called employees claiming to be from Twitter's IT department, said they needed to verify account credentials, and created enough urgency and authority that people complied.

Here's a more common example for small businesses. Your office manager gets a call from someone claiming to be from your bank's fraud department. "We've detected suspicious activity on your business account. I need to verify your identity to secure the account." They already know your company name, your bank name (it's on your website's footer or your checks), and maybe even the last four digits of your account number (from a previous data breach). They sound professional. They sound concerned. They ask you to "verify" your full account number, your security questions, or a one-time code that was just texted to your phone.

That one-time code? It's the MFA code for your actual bank login. They're logging into your account in real time while they have you on the phone.

The FBI's 2023 IC3 report categorizes these as "confidence fraud/romance" and "tech support" scams, and together they accounted for over $1.3 billion in losses. The common thread is a fabricated scenario designed to bypass your judgment.

Vishing: phishing, but with a phone call

Vishing (voice phishing) is exactly what it sounds like. Instead of a suspicious email, the attacker calls you. And calls are surprisingly effective because most people's defenses are calibrated for email. We've been trained to look for typos, weird links, and unfamiliar senders. When someone calls and sounds competent and professional, our guard drops.

In 2022, the Lapsus$ group (a hacking group made up primarily of teenagers) used vishing to breach Microsoft, Okta, Nvidia, and Samsung. They called employees, posed as IT support, and convinced them to approve MFA prompts or share credentials. These aren't mom-and-pop shops. These are some of the most security-conscious companies in the world.

The reason vishing works so well is that phone calls create real-time pressure. An email sits in your inbox. You can think about it, check with a colleague, sleep on it. A phone call demands an immediate response. The attacker controls the pace of the conversation, and most people are too polite or too flustered to say "I'm going to hang up and verify this independently."

How to handle vishing attempts

This is simpler than most people think. If someone calls claiming to be from your bank, your vendor, your IT provider, or any company you do business with, and they ask for sensitive information or immediate action:

  • Say "Let me call you back."
  • Hang up.
  • Call the company directly using the number on their official website, your existing contact, or the number on the back of your card.

That's it. Any legitimate caller will understand. Any attacker will try to keep you on the line, which itself is the red flag.

Baiting: the USB stick in the parking lot

Baiting uses physical objects or digital downloads to exploit curiosity. The classic example is a USB drive left in a company parking lot, labeled something irresistible like "Salary Info Q4" or "Layoff Plans." Someone picks it up, plugs it into their work computer, and the drive installs malware.

You might think nobody falls for this anymore. A study by researchers at the University of Illinois dropped 297 USB drives on a university campus. 48% were plugged in, and the first one was opened within six minutes.

The digital version of baiting is just as common. Free software downloads, "free" versions of paid tools, pirated media. All potential vehicles for malware. Proofpoint's 2024 State of the Phish report found that nearly 30% of working adults admitted to taking a risky action online (clicking unknown links, downloading unverified software) despite knowing the risk. We know better. We do it anyway. That's what makes social engineering so effective.

Why smart people fall for this

Here's the part I genuinely find fascinating (and a little infuriating). Social engineering doesn't work because people are stupid. It works because it targets cognitive shortcuts that all humans use.

Authority. We comply with requests from people who appear to have authority. The "IT department," the "bank fraud team," the "CEO." Robert Cialdini's research on influence identified authority as one of the six universal principles of persuasion. Attackers know this and always establish authority first.

Urgency. "Your account will be locked in 30 minutes." "This wire needs to go out before end of business." Urgency short-circuits careful thinking. When you feel rushed, you skip verification steps that you'd normally follow.

Social proof. "We're calling all employees to update their credentials." If you think everyone else is doing it, it feels normal. Attackers use this to make unusual requests seem routine.

Reciprocity. The attacker does something helpful first ("I'm calling to help you fix this security issue") so you feel obligated to cooperate. It's a deeply ingrained social instinct, and attackers weaponize it.

Understanding these triggers doesn't make you immune, but it does give you a moment of recognition. When you feel a rush of urgency or find yourself complying with a request because the person sounds authoritative, that's the moment to pause.

Building real defenses

Technical controls help, and they help a lot. Email filtering catches most phishing. MFA stops most credential theft. DNS filtering blocks most malicious domains. Every layer you add to your small business cybersecurity makes the attacker's job harder.

But social engineering is the attack that bypasses all of those layers by targeting the human. The best defense is building a culture where it's completely normal and expected to:

  • Verify unexpected requests through a separate channel (call back using a known number)
  • Question urgency ("if this were really critical, there'd be a process for it")
  • Say "I need to check with someone before I do that" without feeling awkward about it

The 17-year-old who hacked Twitter didn't write sophisticated code. He picked up the phone and asked nicely. The defense isn't more software. It's making sure your team knows that "let me verify that" is always the right answer.