Social engineering and cyber fraud: when people, not technology, are the target
Social engineering uses psychological manipulation to influence people's decisions. In the digital world, cybercriminals use these techniques to obtain confidential information, gain access to systems, interfere with internal processes or achieve financial gain.
Unlike other attacks that target technical vulnerabilities, social engineering exploits human factors such as trust, urgency, fear, empathy and situational pressure. This is why it can be effective even in corporate environments with advanced security measures in place.
Social engineering works because it exploits human behaviour, not just technological weaknesses.
Social engineering in today's cyber fraud
Many forms of digital fraud do not begin with a technical intrusion, but with an interaction that appears legitimate. An email, a phone call, a social media message or an urgent request can lead people to make hasty decisions if the attacker succeeds in creating a sense of trust or urgency.
In a business environment, email remains one of the most common channels used to initiate these attacks: it allows attackers to imitate legitimate communications, include malicious links or attachments and steer the victim towards a specific action.
■ Social engineering takes different forms depending on the context: it can target business processes, personal relationships or everyday communication channels.
CEO fraud: manipulating business processes
CEO fraud is a form of Business Email Compromise (BEC) that involves impersonating an executive or another person in a position of authority to request payments, changes to bank details or urgent transfers.
It is a targeted form of email-based attack. Rather than attempting to deceive large numbers of people, it seeks to persuade a specific individual to carry out a sensitive action or disclose information that is relevant to the business.
The attacker will often use publicly available or previously obtained information about the company: roles, email addresses, internal processes, suppliers, calendars or professional relationships. This information is used to construct a credible request and pressure the victim into acting without verifying it.
■ Internal verification procedures help reduce this risk. Any request involving money, sensitive information or changes to established processes should be verified through an alternative channel.
In CEO fraud, time pressure and the appearance of authority are designed to make the victim act before verifying the request.
Romance scams: emotional manipulation and trust
Romance scams use fake profiles on social media, dating apps or messaging services to build a relationship of trust with the victim. The aim is usually to establish an emotional connection before asking for money, personal information or favours that could result in financial loss or extortion.
This type of fraud usually develops in stages. First, the attacker creates an attractive or trustworthy identity; then the conversation moves to a more private channel; finally, a financial, family, medical or professional problem emerges to justify the request.
■ Warning signs include profiles with little history, inconsistent stories, excuses to avoid video calls, pressure to move the conversation to another channel, requests for secrecy or requests for financial help. No single warning sign confirms that fraud is taking place, but a combination of several should prompt caution.
In romance scams, the fraud does not begin with a request for money, but with the gradual building of trust.
How to reduce the risk of social engineering
Protection against social engineering combines procedures, a strong security culture and individual habits. The following measures can help reduce exposure:
- Verify sensitive requests through alternative channels. Confirm payments, changes to bank details or urgent requests using a different channel from the one used for the initial request.
- Follow internal procedures. Do not bypass approval steps, even if a request appears urgent or comes from someone in a position of authority.
- Limit publicly available information. Reduce the exposure of organisational structures, job roles, suppliers, working routines and personal information on websites and social media.
- Check senders, links and attachments. Pay close attention to email addresses, lookalike domains, unexpected messages and documents that ask for credentials or an immediate response.
- Protect corporate email. Phishing filters, impersonation detection, link and attachment analysis, email authentication and data loss prevention measures can help reduce exposure to email-based attacks.
- Be wary of emotional or time pressure. Urgency, demands for strict confidentiality and appeals to empathy are common techniques used in this type of fraud.
- Train teams and raise security awareness. Regular training helps people recognise patterns of manipulation and seek advice before acting when they are unsure.
- Report any suspicious attempts. Reporting incidents or attempted attacks to the security team can help prevent further cases and improve the organisation's response.
Conclusion
Technology is essential for protecting systems, data and processes, but Cybersecurity starts with people: it needs to be complemented by secure habits and sound decision-making. Social engineering shows that many attacks succeed when people act under pressure, place too much trust in others or are unaware of the risk.
That is why reducing risk requires technical controls, clear procedures and a culture that encourages people to stop, verify and ask for help before taking action.
Cloud & Business Apps
Cybersecurity
Data & AI
IoT & Connectivity
Industry
Health
Banking and Finance
Public Sector
Retail
Tourism and Leisure
Transport & Logistics
Energy & Utilities
Smart Cities