What is pretexting?
Pretexting is a form of social engineering that relies on a fabricated scenario—a pretext—to trick victims into revealing confidential information or performing an action. Attackers develop convincing stories and establish a false sense of trust, often pretending to be IT support, HR staff or company executives. Unlike phishing emails that use fear and urgency, pretexting exploits human kindness and procedural compliance.
Common pretexting scenarios
- Fake IT support: A caller claims to be from the help desk and asks you to confirm your username and password to “resolve a technical issue.”
- HR or finance impostor: The attacker emails about a salary review or payroll update and asks you to log in to a spoofed portal or change banking details.
- Vendor or auditor ruse: A supposed external auditor contacts security staff and requests access to the building. Once inside, the attacker connects unauthorized devices or steals hardware.
- CEO fraud: In one notable case, Ubiquiti Networks employees received messages from attackers impersonating senior executives and were instructed to wire funds to fraudulent accounts. The company lost $46.7 million.
- SIM swap impersonation: A pretexter calls a mobile carrier pretending to be a customer who lost their phone, persuades the agent to transfer the number to a new SIM, then uses one‑time codes to hijack accounts.
Why pretexting works
Pretexting taps into our desire to be helpful and follow rules. Attackers create realistic scripts, use industry jargon and often spoof phone numbers or email addresses to appear legitimate. Because the request aligns with routine tasks—resetting passwords, processing invoices or granting access—employees don’t notice anything unusual. Attackers target individuals with elevated privileges, such as finance staff or executives, to maximize the payoff.
Warning signs and red flags
- Unsolicited requests for sensitive information or remote access, especially if the caller pressures you not to tell anyone.
- Emails or calls with minor mistakes in names, email addresses or domain names.
- Requests to bypass established procedures, such as changing payment details without verification.
- A caller refusing to answer basic questions about your organization’s internal processes.
- Instructions to keep a transaction secret or act quickly.
How to defend against pretexting
- Verify identities: Independently contact the person or department through a known channel before sharing information or making changes. Don’t rely on contact details provided in the message.
- Follow procedures: Never alter payment instructions or user credentials without secondary approval. Use out‑of‑band verification for financial transactions.
- Educate employees: Train staff to recognize social‑engineering tactics and encourage them to question unusual requests. Realistic phishing simulations and incident response drills help reinforce the lessons.
- Limit information exposure: Restrict the personal and corporate details available online. Attackers often research targets to craft more convincing pretexts.
- Use technology safeguards: Implement multi‑factor authentication, strong password policies, and email filtering that checks for domain spoofing.
Conclusion
Pretexting may feel polite on the surface, but its goal is to exploit your trust. Whether the scammer claims to be from HR, finance or your mobile carrier, always verify before complying. A simple call or message to confirm could save your company millions and keep your personal data secure.

