Social Engineering

Social engineering is the practice of manipulating people, rather than exploiting technical systems, into taking an action that compromises their own security, clicking a malicious link, revealing a password, transferring money, or granting access to a device or property. Where a technical attack exploits a flaw in software, social engineering exploits something much harder to patch: human trust, urgency, empathy, and authority. This is precisely why it remains effective even against people and organisations with strong technical defences the vulnerability being targeted isn’t in the system, it’s in the person.

What Makes it Work?

Social engineering succeeds by manufacturing the conditions under which people make poor decisions quickly. Common psychological levers include:

  • Urgency — creating time pressure so the target acts before they can think it through or verify the request
  • Authority — impersonating a bank, government agency, police officer, or trusted institution to discourage questioning
  • Trust and rapport — building a relationship over time (as in romance scams) before making a request
  • Fear — threatening legal consequences, account suspension, or harm to a loved one
  • Reciprocity and kindness — exploiting a target’s willingness to help, particularly effective against people who are naturally trusting or isolated

Attackers are often highly practised: they rehearse scripts, study behavioural patterns, and adapt in real time to how a target responds, rather than following a rigid, generic script.

Common forms

  • Phishing — deceptive emails or messages designed to trick a recipient into clicking a malicious link or revealing credentials
  • Spear phishing — a phishing attack tailored to a specific individual using researched, personal details to appear credible
  • Vishing and smishing — the same manipulation carried out over phone calls or SMS text messages
  • Business email compromise (BEC) — impersonating a trusted figure, often an executive, to trick an employee into transferring funds or data
  • Pretexting — fabricating a false scenario or identity (a tech support agent, a utility worker, a family member in distress) to extract information or access
  • Baiting — offering something enticing, like a fake prize or a USB drive left somewhere visible, to lure a target into compromising their own system
  • Romance scams — building a long-term emotional relationship, often over months, before requesting money under a fabricated hardship

Who is most exploited

Social engineering doesn’t primarily succeed against people who are unintelligent or careless — it succeeds against people caught in a vulnerable moment, and some groups face those moments more often or more severely than others. In Australia, Cybercrime in Australia shows adults 65 and over consistently report the highest scam losses of any age group, First Nations communities are disproportionately represented in loss reports relative to population share, and people with disability report substantial losses each year. Social isolation is one of the strongest known risk factors: someone with fewer people to informally check a suspicious call or message against is significantly more likely to act on it before the deception is noticed, and may feel too ashamed afterward to report it or tell anyone.

Case example — an older person with disability living independently

Elise

Elise is woman in her late 60s, living independently with a mobility-related disability. She manages her own banking, medical appointments, and personal supports by phone and email/ internet.

She receives a phone call from someone identifying themselves as being from her bank’s fraud department, stating that unusual activity has been detected on her account and immediate action is needed to prevent further loss. The caller directs her to log on and check her account. The caller is calm, professional, and uses real details about her bank’s branch and product names, building credibility quickly. Because Elise lives alone and has no one to check in with and prompt her to pause and question the veracity of the caller. The caller creates urgency, insisting the “fraud” needs to be stopped immediately and guides her step by step to move funds into a secure “safe” account.

By the time her support worker becomes aware of Elise’s loss several days later, $3000 has been transferred and is unrecoverable. Elise feels shame rather than anger and refuses to talk about it or report it She feels that people will think she cannot manage her own affairs.

TacticApplication
AuthorityImpersonating a trusted bank fraud department
UrgencyFraming the situation as time-critical to prevent independent verification
IsolationLiving alone with limited immediate in-person contact reduced the chance of a second opinion before acting
Reliance on mobile communications systemsGenuine dependence on phone banking for independent living created a channel scammers already knew to target
Shame after the factFear of being perceived as incapable delayed reporting and support

This pattern is consistent with what’s documented more broadly: disabled and older Australians often rely on phone- and internet-based systems specifically because those systems support independent living, which paradoxically increases their exposure to exactly this kind of attack — the vulnerability isn’t a lack of awareness, it’s a structural reliance on channels scammers have learned to exploit.

Position in this Vault

This note sits under Cybersecurity and connects directly to Cybercrime in Australia and demonstrates how “successful” social engineering contact can fully compromise a human life. It speaks to a theme in this vault of why cybersecurity is as much a human and social issue as a technical one.