Pretexting
Social engineering built on an invented but plausible story: an audit, a vendor, a technician. The pretext justifies asking for data or access.
Full definition
Pretexting is a social engineering technique where the attacker builds an invented but plausible scenario, the pretext, to justify a request for information or access. Instead of scaring the victim, it gives them a context where helping feels like the right thing to do.
Classic pretexts include the external audit that needs documents, the technician who requires remote access, the vendor updating billing details, or the new employee from another office asking for help. The more public information the attacker has about the company, the more credible the script.
Pretexting underpins almost every other social engineering attack, from vishing to BEC. It is countered with verification protocols that do not depend on employee goodwill, and with a culture where verifying before helping is not perceived as distrust.
Related terms
Social engineering
Psychological manipulation that leads a person to hand over information, access or money. It is the starting point of most successful cyberattacks.
Vishing
Social engineering over a phone call. The attacker poses as tech support, a bank or a vendor to obtain access or payments in real time.
Business email compromise (BEC)
Fraud where the attacker poses as an executive or vendor from a legitimate or spoofed mailbox to divert payments or data. It usually carries no malware.
OSINT
Intelligence built from public sources: websites, social media, records. The same information serves defense and attack preparation.
From definition to data: measure your company's human risk
Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.