What Is Social Engineering in Cybersecurity? Definition & Examples

Introduction

Picture this: your program director receives an email from what appears to be your executive director's address. Subject line: "Urgent wire transfer needed — board meeting tomorrow." The message looks right, the tone sounds right, and the sender's name matches. Would your team pause before acting?

Most wouldn't — and that's the vulnerability social engineering exploits. It bypasses firewalls and antivirus software entirely by targeting the most unpredictable variable in any security setup: people. No exploit code required, just a convincing story and a moment of distraction.

For nonprofits and associations with lean IT resources and staff juggling multiple roles, this threat is both real and underestimated. IBM X-Force found that phishing and abuse of valid accounts each represented 30% of incidents remediated in 2023 — and social engineering sits at the root of both.

This article covers what social engineering is, why it works psychologically, the most common attack types with real examples, and concrete steps your organization can take to defend against it.


Key Takeaways

  • Social engineering exploits human psychology — not software — making everyone a potential attack surface
  • Phishing, pretexting, BEC, and baiting are the most common attack types facing small organizations
  • Smaller organizations with fewer security controls are often easier targets than large enterprises
  • MFA, staff training, and least-privilege access are the three most effective defenses
  • One successful manipulation can compromise an entire network, so response speed is critical

What Is Social Engineering in Cybersecurity?

Social engineering is the use of psychological manipulation to deceive people into revealing confidential information, granting unauthorized access, or taking actions that compromise security — without the attacker needing to exploit a single line of code.

The NIST Cybersecurity Resource Center defines it as: "An attempt to trick someone into revealing information (e.g., a password) that can be used to attack systems or networks."

Human Hacking vs. Technical Attacks

Traditional cyberattacks target technical vulnerabilities — software bugs, misconfigured servers, unpatched systems. Social engineering targets something harder to patch: human vulnerabilities like trust, fear, urgency, and the instinct to be helpful. That's why it's sometimes called "human hacking."

The distinction matters for how you defend against it. Software gets patched automatically — but people require ongoing awareness, practice, and culture change to develop the same resilience.

Why Smaller Organizations Are Attractive Targets

Nonprofits and associations face particular exposure:

  • Lean IT resources mean fewer people monitoring for threats
  • Staff wearing multiple hats means security tasks compete with urgent program work
  • Public leadership information (board members, executive directors, org charts) gives attackers easy research material for targeted attacks
  • Trust-based culture creates an environment where unusual requests may receive less scrutiny

Community IT's 2024 data from its nonprofit client base recorded 430 spoofing and spear-phishing reports and 472 suspected account compromises — a high incident volume for a sector that often assumes it isn't a priority target.

Social Engineering as the First Step

Social engineering is rarely the whole attack. More often, it's the entry point. An attacker tricks an employee into revealing their Microsoft 365 credentials, then uses those credentials to access email, redirect payments, or deploy ransomware across the organization's network. The manipulation opens the door — everything after that is a technical problem built on a human one.


The Psychology Behind Social Engineering: Why It Works

Social engineering succeeds not because victims are uninformed, but because it exploits predictable cognitive responses. Proofpoint surveyed 7,500 working adults and found that 71% admitted knowingly taking a risky action — and 96% of that group understood the action carried risk. Awareness alone doesn't prevent the behavior.

Attackers study human psychology and engineer situations designed to make people act before they think. The core psychological levers they use:

Trigger How Attackers Use It
Authority Impersonating executives, IT support, the IRS, or the FBI to trigger automatic compliance
Urgency and fear "Your account will be locked in 24 hours" — time pressure causes people to skip verification
Trust and familiarity Spoofing a known colleague, vendor, or brand to lower the target's guard
Reciprocity Offering something first (free tech help, a gift) to create a sense of obligation
Scarcity "Only you can resolve this" — making the target feel uniquely responsible to act now

5 social engineering psychological triggers used by attackers to manipulate victims

These triggers come directly from Robert Cialdini's Influence (1984) — principles originally studied in sales and persuasion, now repurposed as an attack playbook.

That's what makes social engineering so difficult to defend against: the attack surface is every person in your organization. A single employee — especially in a small nonprofit or association where staff wear multiple hats and trust internal requests quickly — can unintentionally hand over credentials, authorize a wire transfer, or open a foothold into the network. Security tools catch a lot, but they can't intercept a phone call where someone willingly reads out a verification code.


Common Types of Social Engineering Attacks

Phishing (and Its Variants)

Phishing uses deceptive emails, texts, or calls designed to appear from a trusted source, aimed at harvesting credentials or delivering malware. Within the Social Engineering incident pattern, Verizon's 2023 DBIR found that email supplied 98% of vectors.

Key variants your team should know:

  • Spear phishing — targeted attacks using personal research (job title, manager's name, recent projects). Particularly dangerous for nonprofits because leadership names and roles are often publicly listed on websites and donor pages
  • Whaling — spear phishing aimed specifically at executives or board members
  • Vishing — voice/phone-based phishing; Proofpoint reported 69% of organizations experienced vishing attacks in 2021
  • Smishing — SMS-based phishing; consumers reported $470 million lost to text scams in 2024, more than five times the 2020 figure

Four phishing attack variants spear phishing whaling vishing and smishing explained

Pretexting

The attacker fabricates a believable scenario to extract information. A common example: someone calls posing as IT support, claims there's an urgent security issue with your account, and asks you to confirm your login credentials to "verify your identity." The scenario sounds routine, the urgency feels real, and by the time the call ends, the attacker has what they came for.

Baiting

Baiting dangles something enticing to lure a victim into a harmful action. This can be digital (a free software download, a prize notification) or physical. In a well-known University of Illinois field study, researchers dropped 297 USB drives on campus — 98% were picked up, and 45% generated a callback after a user opened a file that connected to the research server. No executable code required.

Business Email Compromise (BEC)

BEC attacks involve an attacker impersonating a senior leader — sometimes via a lookalike email address, sometimes through a genuinely compromised account — to instruct staff to wire funds or change payment details. In 2015, Ubiquiti Networks discovered that fraudsters had impersonated employees and directed a subsidiary to transfer $46.7 million to overseas accounts. The FBI's IC3 recorded $2.77 billion in adjusted BEC losses in 2024 — across 21,442 complaints.

Tailgating and Physical Pretexting

Not all social engineering happens over email. An unauthorized person follows an employee through a secured door, or poses as a delivery driver to gain access to restricted areas. For organizations with shared office spaces, front-desk staff, or building lobbies, this remains a genuine risk.

Scareware and Quid Pro Quo

Social engineering also shows up in two less common forms that often fly under the radar:

  • Scareware — fake virus alerts or law enforcement notices designed to frighten users into installing malware or paying ransoms
  • Quid pro quo — offering something in exchange for access, such as "free IT help" in return for login credentials

Real-World Social Engineering Examples

Google and Facebook: $120 Million Lost to Fake Invoices

Between 2013 and 2015, Lithuanian national Evaldas Rimasauskas registered a company mimicking a real Asian hardware manufacturer, then sent fraudulent invoices, emails, and contracts to two of the world's most technically sophisticated internet companies. Both wired funds. The total exceeded $120 million. Rimasauskas was sentenced to five years and ordered to forfeit nearly $50 million.

No code was exploited — just convincing paperwork and a plausible story were enough to fool two of the most technically sophisticated companies on earth.

John Podesta's Email: One Click, Thousands of Documents

In March 2016, campaign chairman John Podesta received an email disguised as a Google security alert. He entered his credentials on a counterfeit sign-in page. The result: more than 50,000 documents stolen from his account, then released by WikiLeaks in 33 tranches over the final weeks of the presidential campaign. The Mueller report attributed the operation to Russia's GRU Unit 26165.

A single credential entered on the wrong page — that's all it took.

The Lesson for Smaller Organizations

If Google, Facebook, and a presidential campaign can be compromised through social engineering, the assumption that smaller nonprofits are "not interesting enough to target" is a serious mistake. Attackers often prefer smaller organizations because they count on less scrutiny, fewer controls, and more staff willing to act on an urgent-sounding request from leadership.


How to Protect Your Organization from Social Engineering

Defending against social engineering requires a layered approach — people, process, and technology working together. No single tool stops an attacker who convinces a legitimate employee to hand over access willingly.

Security Awareness Training

Training is the most direct defense against manipulation. Staff need to recognize phishing emails, suspicious callback scenarios, urgency tactics, and unusual requests for credentials or payments.

Critically, training must be:

  • Ongoing, not annual — susceptibility fades without reinforcement
  • Scenario-based — theoretical knowledge doesn't produce behavioral change
  • Non-punitive — staff who fear embarrassment won't report suspicious contacts

ETTE builds security awareness into its managed IT delivery as a baseline practice across all service tiers. For organizations where the person handling cybersecurity is also managing printer issues and laptop replacements, that built-in foundation matters — no dedicated internal security team required.

Verify Before You Trust

Instruct staff to independently verify any unusual request — especially those involving credentials, financial transfers, or access changes. The verification must use a known phone number, not one provided in the suspicious message itself.

That single habit prevents most social engineering incidents.

Multi-Factor Authentication (MFA)

MFA is one of the most effective technical controls available. Microsoft research found MFA associated with a 99.22% reduction in compromise risk across the studied population and a 98.56% reduction among accounts with leaked credentials.

Enable MFA on:

  • Email (Microsoft 365, Google Workspace)
  • Cloud applications and SaaS platforms
  • Remote access tools and VPNs
  • Financial systems

Multi-factor authentication coverage checklist showing four critical system categories to protect

ETTE enforces MFA as part of its standard managed security baseline across all service tiers. It's a requirement, not an optional add-on.

Access Controls and Least Privilege

Limit what each staff member can access to only what their role requires. If an attacker obtains a junior employee's credentials through social engineering, least-privilege access limits the blast radius. A program coordinator's login shouldn't open your donor database or financial records.

Enforcing this well means more than a one-time setup. Access needs to be granted correctly from day one and revoked promptly when staff change roles.

ETTE's Cloud Identity Protection service includes role-based least-privilege enforcement, privileged access controls, access reporting, and structured joiner/mover/leaver workflows to keep permissions accurate as your team evolves.

Incident Reporting Culture and Written Policies

Staff who fear embarrassment don't report suspicious contacts — and unreported incidents become undetected breaches. Make it psychologically safe to flag something that "feels off," even if the person isn't certain.

Pair that culture with plain-language written policies covering:

  • How to handle unexpected requests for credentials or funds
  • Password management requirements
  • What to do when an email or call seems suspicious

ETTE's quarterly service reviews and GuardRail board-ready reporting give leadership direct visibility into security posture — including training completion rates and phishing simulation performance. That means organizations can track whether social engineering defenses are actually improving over time, not just assumed to be in place.


Frequently Asked Questions

Who do hackers target the most?

While large enterprises attract headlines, attackers frequently target small and mid-sized organizations — including nonprofits and associations — because they tend to have fewer security controls, less trained staff, and more staff willing to act on urgent-sounding requests without verification. Verizon identifies social engineering as the second-largest threat pattern for small and medium businesses.

What are the four types of social engineering?

The four primary types are:

  • Phishing — deceptive emails, texts, or calls designed to steal credentials or deliver malware
  • Pretexting — fabricated scenarios used to extract sensitive information
  • Baiting — luring victims with enticing offers or objects, digital or physical
  • Tailgating — gaining unauthorized physical access by following an authorized person

What are the 6 principles of social engineering?

These map to Cialdini's influence principles applied to manipulation:

  • Authority — impersonating someone with power
  • Scarcity/Urgency — creating time pressure to force quick action
  • Social proof — claiming others have already complied
  • Reciprocity — offering something first to create obligation
  • Liking — building rapport to lower the target's guard
  • Commitment — securing small agreements that lead to larger ones

What is an example of a social engineering claim?

A common example: "Your account has been compromised — please verify your credentials immediately to restore access." This creates false urgency and fear, pressuring the recipient to hand over login information without pausing to verify whether the request is legitimate.

Is social engineering the same as phishing?

No. Phishing is one type of social engineering, not a synonym for it. Social engineering is the broader category covering all forms of psychological manipulation used to gain unauthorized access or information. Phishing specifically refers to deceptive emails, texts, or calls used to steal credentials or deliver malware.