Back to the glossary
    Social engineering & phishingCybersecurity glossary

    Pretexting

    Social engineering built on an invented but plausible story: an audit, a vendor, a technician. The pretext justifies asking for data or access.

    Full definition

    Pretexting is a social engineering technique where the attacker builds an invented but plausible scenario, the pretext, to justify a request for information or access. Instead of scaring the victim, it gives them a context where helping feels like the right thing to do.

    Classic pretexts include the external audit that needs documents, the technician who requires remote access, the vendor updating billing details, or the new employee from another office asking for help. The more public information the attacker has about the company, the more credible the script.

    Pretexting underpins almost every other social engineering attack, from vishing to BEC. It is countered with verification protocols that do not depend on employee goodwill, and with a culture where verifying before helping is not perceived as distrust.

    Related terms

    From definition to data: measure your company's human risk

    Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.