All termsFraudIntermediateUpdated April 10, 2026

What Is Social Engineering?

Social engineering is the manipulation of people into revealing confidential information or performing actions that benefit an attacker, bypassing technical security controls entirely. Attackers exploit trust, urgency, fear, or authority rather than software vulnerabilities.

Also known as: human hacking, pretexting attack, psychological manipulation fraud, people hacking

Key Takeaways

  • Social engineering attacks target people, not systems—no firewall stops a convincing impersonation.
  • Business email compromise and authorised push payment fraud are the two costliest social engineering vectors for merchants.
  • Effective defence requires both technical controls (MFA, anomaly detection) and human-layer controls (training, verification procedures).
  • Always verify payment detail changes through a separate, pre-established channel before processing.
  • Rapid response within hours of a fraudulent transfer significantly improves fund-recovery chances.

Social engineering is one of the oldest and most effective attack vectors in financial fraud. Unlike malware or network intrusions, it requires no technical sophistication—only the ability to exploit fundamental human tendencies: trust, helpfulness, fear, and deference to authority. For payment professionals and ecommerce merchants, understanding this threat is not optional; it is a baseline competency.

How Social Engineering Works

Every successful social engineering attack follows a recognisable sequence. The attacker researches the target, constructs a believable identity, and then exploits a psychological trigger to prompt action—typically bypassing the verification steps that would otherwise block a fraudulent transaction.

01

Reconnaissance

The attacker gathers intelligence about the target organisation: employee names, roles, email formats, suppliers, and current projects. Sources include LinkedIn, company websites, regulatory filings, and data from previous breaches. The goal is enough detail to build a convincing impersonation.

02

Establishing Pretext

Using the gathered intelligence, the attacker constructs a believable identity or scenario—a new supplier, an IT administrator, a senior executive, or a bank compliance officer. The pretext is crafted to match the target's reality closely enough to bypass scepticism.

03

Building Trust or Urgency

The attacker contacts the victim through a channel that appears legitimate (spoofed email, cloned website, spoofed caller ID). They either build rapport over time or, more commonly in payment fraud, inject urgency—a pending audit, a failed payment, a system breach—to compress the victim's decision window and suppress careful verification.

04

Exploitation

With trust or urgency established, the attacker requests the target action: sharing credentials, approving a wire transfer, updating bank details, or clicking a link. Because the victim believes the request is legitimate, they comply—often without triggering any automated fraud detection system, since the human authorised the action.

05

Exit and Cover

After extraction, sophisticated attackers take steps to delay discovery—deleting emails, forwarding rules that suppress bank notifications, or impersonating the victim to reassure colleagues. The longer the delay, the lower the probability of fund recovery.

Why Social Engineering Matters

The financial impact of social engineering fraud is staggering and continues to grow. According to the FBI Internet Crime Complaint Center (IC3) 2023 report, business email compromise alone caused over $2.9 billion in adjusted losses in the US—the single costliest cybercrime category for the fourth consecutive year. Globally, the Anti-Phishing Working Group (APWG) recorded over 4.9 million phishing attacks in 2023, a 150% increase from 2020.

For payment teams specifically, the Verizon 2023 Data Breach Investigations Report found that 74% of all breaches involved a human element—social engineering, privilege misuse, or errors—confirming that patching software alone is an insufficient defence strategy. Social engineering is particularly dangerous in payment workflows because many attacks result in authorised transactions: the victim willingly initiates or approves the transfer, which means standard fraud models trained on behavioural anomalies often miss them entirely.

Authorised Push Payment Risk

When a victim is manipulated into initiating a payment themselves, the transaction clears as legitimate. This is the defining characteristic of authorised push payment fraud and why recovery rates are significantly lower than for card fraud.

Social Engineering vs. Technical Hacking

Both social engineering and technical hacking aim to compromise systems or extract value, but they operate through fundamentally different mechanisms and require different defences.

DimensionSocial EngineeringTechnical Hacking
Primary targetHuman psychologySoftware / infrastructure
Skill requiredInterpersonal, researchTechnical, coding
Detection difficultyHigh — authorised actions look normalMedium — anomalies trigger alerts
Primary defenceTraining, verification proceduresPatching, firewalls, SIEM
Common payment vectorBEC, APP fraud, vishingCredential stuffing, skimming
Recovery after successVery difficult — authorised transfersModerate — transaction reversal possible
Regulatory liabilityContested — victim initiatedClearer — unauthorised transaction

Types of Social Engineering

Social engineering encompasses a broad family of attack techniques, many of which converge in complex payment fraud schemes.

Phishing is the mass-market variant: fraudulent emails or SMS messages impersonating trusted brands to harvest credentials or redirect victims to fake payment pages.

Spear phishing targets specific individuals using personalised intelligence, dramatically increasing success rates. Finance directors and accounts-payable staff are prime targets.

Vishing (voice phishing) uses phone calls, often with spoofed caller ID, to impersonate bank fraud teams, HMRC, or IT support. Attackers use real-time information to sound credible and pressure victims into transferring funds or revealing one-time passwords.

Smishing delivers social engineering payloads via SMS—increasingly common as email filters improve and mobile banking adoption grows.

Pretexting is the deliberate creation of a fabricated scenario to justify a request. In B2B payment fraud, a common pretext is posing as a new accounts-payable contact at a supplier to request a bank detail update.

Quishing uses QR codes embedded in emails or physical mail to route victims to credential-harvesting sites, bypassing URL-scanning email security tools.

Account takeover frequently begins with social engineering—tricking a customer service agent into resetting credentials or bypassing identity verification, then using the compromised account to initiate payments.

Best Practices

For Merchants

Train all finance, accounts-payable, and customer-facing staff on social engineering tactics at least annually, with simulated phishing exercises to measure and reinforce awareness. Establish a written callback procedure: any request to change supplier bank details, redirect payroll, or authorise unusual transfers must be verified via a pre-registered phone number—never one provided in the request itself. Implement dual-authorisation controls for payments above defined thresholds so a single compromised employee cannot unilaterally approve a transfer. Review your cyber insurance policy to confirm social engineering fraud is explicitly covered; many policies exclude it by default.

For Developers

Implement FIDO2 / passkey authentication for all administrative and payment-related portals—hardware-bound credentials cannot be phished. Build anomaly detection that flags high-risk events: first-time payee, payment amount above user average, bank detail changes followed immediately by a payment request. Expose a clear, in-app mechanism for users to report suspected fraud and pause pending transactions. Log all authentication events and administrative changes with tamper-resistant audit trails to support post-incident investigation. Apply rate limiting and out-of-band confirmation (e.g., push notification to a registered device) for sensitive account changes.

Common Mistakes

Trusting caller ID or email display name. Both are trivially spoofed. Caller ID spoofing requires no specialist equipment; email display names are independent of the actual sending address. Always verify through an independent channel.

Using the contact details provided in the suspicious message. If a fraudster sends a fake invoice with a new bank account and a helpline number, calling that number connects the victim to the fraudster. Pre-register supplier and bank contact details in a separate, secured system.

Assuming internal requests are safe. Business email compromise frequently involves a compromised or spoofed internal email address. A message appearing to come from the CFO does not make a payment request legitimate. Senior-executive impersonation is one of the most common pretexts.

Delaying incident response. Every hour between a fraudulent transfer and the first bank notification reduces recovery probability. Many merchants wait days before escalating. Establish a documented, practised incident response playbook that begins within the hour.

Over-relying on spam filters. Modern spear-phishing emails often pass DMARC, DKIM, and SPF checks because attackers compromise legitimate email accounts or register convincing lookalike domains. Technical email authentication is necessary but not sufficient.

Social Engineering and Tagada

Tagada is a payment orchestration platform that routes transactions across multiple acquirers and processors. While Tagada itself does not hold customer funds, social engineering attacks targeting merchants using the platform can have direct payment consequences—particularly attempts to manipulate merchant staff into changing payout bank details, adding fraudulent API credentials, or approving unusual configuration changes.

Protecting Your Tagada Integration

Enable two-person approval for any configuration changes affecting payout accounts or API keys in your Tagada dashboard. Any request to update these settings—even one that appears to come from Tagada support—should be verified via your account manager's pre-registered contact details before action is taken. Tagada will never ask for your secret API keys over email or phone.

Frequently Asked Questions

What is the most common type of social engineering attack in payments?

Phishing is by far the most prevalent form, typically delivered via email or SMS. Attackers impersonate banks, payment processors, or known merchants to steal credentials or trick victims into authorising fraudulent transfers. In the payments context, business email compromise—where fraudsters impersonate executives to redirect supplier payments—is the costliest variant, responsible for billions in annual losses globally.

How does social engineering differ from hacking?

Traditional hacking exploits software vulnerabilities, bugs, or misconfigured systems. Social engineering exploits human psychology—trust, urgency, authority, or fear. The attacker does not need to break through a firewall if they can convince an employee to hand over credentials or approve a wire transfer. This makes it far harder to defend against with purely technical controls.

Can strong authentication stop social engineering attacks?

Partially. Multi-factor authentication raises the bar significantly, but social engineers adapt. SIM-swapping attacks, real-time phishing proxies, and one-time password interception are all techniques used to defeat MFA. The most resilient defences combine hardware security keys (FIDO2/passkeys), employee training, and out-of-band payment verification procedures.

What industries are most targeted by social engineering in payments?

Ecommerce merchants, financial institutions, crypto exchanges, and B2B companies with high-value supplier payments are the primary targets. Finance and HR teams handling payroll or vendor payments are especially exposed. A 2023 Verizon DBIR found that 74% of all breaches involved a human element—social engineering, errors, or misuse—confirming no vertical is immune.

How should a merchant respond to a suspected social engineering attempt?

Immediately halt the transaction or communication without disclosing suspicion. Verify the request through a completely separate, pre-established channel—never reply to the same email or phone call. Report the incident internally and, if a payment was made, contact your payment provider or bank within hours to maximise chargeback or recall prospects. Document everything for law enforcement and insurer notification.

What is the role of pretexting in social engineering fraud?

Pretexting is the creation of a fabricated scenario—a pretext—to gain a victim's trust before extracting information or action. In payments fraud, common pretexts include impersonating IT support to obtain VPN credentials, posing as a bank compliance officer demanding account verification, or faking a supplier identity to update payment details. The pretext lowers the victim's guard by providing seemingly legitimate context.

Tagada Platform

Social Engineering — built into Tagada

See how Tagada handles social engineering as part of its unified commerce infrastructure. One platform for payments, checkout, and growth.