Most cyberattacks don’t start with code. They start with a conversation.
An attacker doesn’t need to break your firewall if they can convince someone to open the door. That’s social engineering: manipulating people into handing over access, information, or money. It skips the technology you’ve invested in and goes straight for the person using it. And it works.
According to Verizon’s 2025 Data Breach Investigations Report, the human element was involved in 60% of breaches last year.
For businesses across Southeast Asia, this is not a distant or Western problem. The same tactics that hit global firms land in Jakarta and Singapore inboxes every day, often better localized than the security training meant to stop them.
This article explains what social engineering is, how an attack actually unfolds, the main types to know, what it costs, and the specific steps that reduce your exposure.
What Is Social Engineering?
Social engineering is the use of deception to manipulate people into giving up confidential information, access, or money. Instead of exploiting a software flaw, the attacker exploits a human one: trust, urgency, fear, curiosity, or the simple wish to be helpful.
Think of it this way. A technical hacker looks for an unpatched server. A social engineer looks for a helpful employee. The second approach is often faster, cheaper, and harder to detect, because nothing about it looks like an attack.
An email that asks for a password reset, a phone call from “IT,” a LinkedIn message from a recruiter: each can be the opening move.
What makes it effective is that it targets behavior no security tool fully controls. Your firewall can’t stop an employee from choosing to trust the wrong person. That’s why social engineering sits behind so many major breaches. It’s the entry point, not the whole attack.
How a Social Engineering Attack Works
Social engineering isn’t a single trick. It’s a sequence. Understanding the stages helps you see where an attack can be interrupted, because there’s an opportunity to catch it at each one.

1. Reconnaissance
The attacker gathers information first. Names, job titles, reporting lines, email formats, vendor relationships, an upcoming acquisition mentioned in a press release. Much of this is public, sitting on LinkedIn, the company website, or social media. The more detail they collect, the more convincing the eventual approach.
2. Pretext
The pretext is the believable scenario the attacker uses to justify their request: a new employee who needs help, an executive in a hurry, a supplier chasing an overdue invoice, a support technician resolving a ticket. A good pretext answers the target’s natural question, “why are you asking me this?”, before they think to ask it.
3. Exploitation
Now the attacker acts. They make the request: click this link, approve this transfer, reset this password, read out this code. Because the groundwork is laid and the story holds together, the target complies. This is the moment the attack succeeds or fails, and from the outside it looks like a normal interaction.
4. Escalation
One success rarely ends it. A single set of stolen credentials becomes a foothold. From there the attacker moves deeper: accessing more systems, escalating privileges, reaching data or funds. What began as one fooled employee turns into a network-wide compromise.
This is why treating social engineering as a minor “human error” underestimates it. The human step is just the beginning.
Types of Social Engineering
Social engineering attacks are usually grouped into three categories, based on how the attacker reaches the target. Here are the main techniques in each.

1. Human-based
These rely on person-to-person contact, in person or by phone.
- Impersonation: Pretending to be someone with a legitimate reason for access, such as a new hire, an executive, or a contractor.
- Pretexting: Building an invented scenario to justify a request for information or access.
- Vishing (voice phishing): Using phone calls to extract information or push an action, often by posing as IT support or a bank.
- Tailgating/piggybacking: Following an authorized person through a secure door, sometimes by asking them to hold it.
- Baiting: Leaving something tempting, like a USB drive labeled “payroll,” where a curious person will find and use it.
- Quid pro quo: Offering a service or favor in exchange for information or access.
- Dumpster diving: Recovering sensitive documents, notes, or hardware from the trash.
- Shoulder surfing: Watching someone enter a password or PIN in a public space.
2. Computer-based
These use email, websites, and software to reach many targets at once.
- Phishing: Fake emails that look legitimate and ask the recipient to click a link, open a file, or enter credentials.
- Spear phishing: A targeted version aimed at a specific person, using personal detail to raise credibility.
- Business email compromise (BEC): Impersonating an executive or supplier to trick an employee into wiring money or sharing data.
- Scareware: Fake warnings claiming the device is infected, pushing the user to install malware or pay for a bogus fix.
- Pop-up/spam attacks: Malicious pop-ups or bulk emails designed to harvest information or deliver malware.
- Watering hole: Compromising a website the target group is known to visit, then infecting them when they do.
3. Mobile-based
These target smartphones and the apps people trust on them.
- Smishing (SMS phishing): Scam text messages with malicious links or urgent requests.
- Quishing (QR code phishing): Malicious QR codes that lead to fake login pages or malware.
- Malicious/repackaged apps: Fake or tampered apps that copy a legitimate one but carry hidden code.
- Fake security apps: Apps posing as antivirus or protection tools that are themselves the threat.
The Business Impact of Social Engineering
A successful attack rarely stops at the initial trick. The real cost shows up in what follows.
1. Financial loss
The most direct damage is money leaving the business. Business email compromise alone is a major driver. According to the FBI’s Internet Crime Complaint Center (IC3), BEC has cost organisations more than $55 billion globally between 2013 and 2023.
These losses often move faster than the tools meant to catch them, because a legitimate-looking transfer request doesn’t trip a malware alarm.
2. Data breach and regulatory exposure
When social engineering leads to stolen credentials, it often opens the way to a full data breach. That carries legal weight.
Under Indonesia’s Personal Data Protection Law (UU PDP), organisations that handle personal data face obligations to protect it and to notify authorities and affected people after a breach, with financial penalties for failure. A single fooled employee can turn into a reportable incident and a regulatory problem.
3. Operational disruption
An attack that reaches core systems can halt the business. When ransomware or account takeover locks up booking systems, payment terminals, or internal tools, staff fall back to manual processes and service slows or stops. Downtime like that costs revenue every hour it continues.
4. Reputational damage
Trust is slow to build and quick to lose. Customers, partners, and regulators all take note when an organisation is breached, especially when personal data is exposed. The financial hit from a single incident eventually clears. The question in a client’s mind about whether their data is safe with you can linger far longer.
How to Defend Against Social Engineering
You can’t patch human judgment, so defense works best in layers, with each one covering what the others miss. These are ordered by how much protection they give relative to the effort involved.
1. Verify requests through a separate channel
Any request to move money, change payment details, or hand over credentials should be confirmed through a known, separate channel, never by replying to the original message or calling a number it provides.
Call the person back on a number you already have. This one reflex stops even a convincing impersonation, because the attacker can’t intercept a channel they don’t control.
2. Enforce phishing-resistant MFA
Multi-factor authentication (MFA) adds a second check beyond a password. But not all MFAs are equal. SMS codes can be intercepted or phished, so use phishing-resistant methods like hardware security keys or passkeys. This blocks the stolen-password-plus-code path that lets attackers walk straight in.
3. Harden help-desk verification
Attackers frequently target the help desk, calling to request a password or MFA reset while posing as an employee. Set strict identity checks before any reset, requiring more than a name and a job title. A missing check here is often all it takes for an attacker to talk their way in.
4. Apply least-privilege access
Give each account only the access its role actually needs. When an account is compromised, least privilege limits how far the attacker can move and how much they can reach. It’s the difference between losing one mailbox and losing the network.
5. Monitor for anomalous activity
Prevention will sometimes fail, so you need to see what happens next. Watch for unusual logins, odd access patterns, and signs of lateral movement. Once credentials are compromised, the speed of detection decides how bad the outcome gets. The damaging attacks are the ones that go unnoticed long enough to spread.
6. Run realistic awareness training
Training matters, but only if it reflects how attacks actually look now: deepfake calls, lookalike domains, urgent payment requests. Generic “spot the typo” advice won’t prepare anyone for a familiar face on a video call. Use role-based simulations, so finance sees wire-fraud scenarios and the help desk sees reset-request scenarios.
Also Read: 20 Cybersecurity Tips Every Business Should Follow
Real-World Examples
1. The MGM Resorts Vishing Attack (2023)
In September 2023, the hospitality giant MGM Resorts was crippled by an attack that started with a phone call. The group behind it, known as Scattered Spider, identified an MGM employee on LinkedIn, then called the company’s IT help desk posing as that person and asked for a password reset. The help desk complied. Within about ten minutes, the attackers were inside.
From there it escalated fast. They reached MGM’s identity and cloud systems, then handed off to a ransomware operation that encrypted large parts of the environment. Key cards, slot machines, booking systems, and ATMs went down across more than 30 properties.
In its filing with the U.S. Securities and Exchange Commission, MGM reported the attack cut about $100 million from its third-quarter results and said it spent roughly $40 million responding. No malware opened that door. A conversation did.
2. The Arup Deepfake Wire Fraud (2024)
In early 2024, the global engineering firm Arup lost about $25 million to a single deepfake operation. A finance employee in the Hong Kong office received a message about a confidential transaction and was suspicious at first. Then he was invited to a video call. On it were people who looked and sounded like the company’s CFO and several colleagues. Reassured, he approved a series of transfers, 15 of them, totaling around HK$200 million.
Every person on that call was an AI-generated fake, built from public video and audio of real Arup executives. Arup confirmed to CNN that fake voices and images were used, while noting none of its internal systems were breached.
That’s the unsettling part. Nothing was hacked in the technical sense. The attack defeated the employee’s judgment by weaponizing the very thing we use to verify identity: a familiar face and voice. It’s a preview of where social engineering is heading.
Building a Complete Defence for Your Organisation
Social engineering aims at your people, and people can be trained but never patched. So the defenses that matter most assume someone will eventually be fooled: out-of-band verification, phishing-resistant MFA, strict help-desk checks, least privilege, and monitoring that catches an intruder early.
Prevention narrows the odds. It doesn’t close them.
Which leaves one question. If an attacker convinced one of your employees today, how long would they move through your systems before anyone noticed? For many organisations, the honest answer is days, not minutes. That gap is where a contained incident becomes a crisis.
Zentara’s Managed SOC closes that gap. Our certified analysts monitor your environment 24/7, hunting for the unusual logins and lateral movement a fooled employee can’t see, and responding to critical threats within 15 minutes. You get a full security operations center without the multi-year buildout.
Not sure how long an attacker could operate undetected in your systems? Talk to our cybersecurity specialists and find out.
Frequently Asked Questions
1. How is social engineering different from phishing?
Phishing is one type of social engineering, not a separate thing. Social engineering is the broad category of manipulating people for access or information; phishing is the version done through fraudulent messages, usually email.
2. Can you fully prevent social engineering?
No, and any vendor who claims otherwise is overselling. It targets human judgment, not a fixable flaw, so some attempts always get through. The realistic goal is to reduce how often attacks succeed and detect the rest quickly. That means pairing prevention with monitoring, not relying on training alone.
3. What is a deepfake social engineering attack?
It uses AI-generated video or audio to impersonate a real person and authorize a fraudulent action. In the Arup case, attackers faked a company’s CFO and colleagues on a live video call to approve $25 million in transfers, which is why out-of-band confirmation matters more than ever.
4. Why do trained employees still fall for social engineering?
Because modern attacks are built to beat the instincts training installs, using real detail, good timing, and pressure that makes hesitation feel awkward. When a “CFO” on a video call makes an urgent request, refusing feels costly while the risk feels abstract, which is why training works best as one layer among several, not the whole defense.
5. What laws apply to social engineering attacks in Indonesia?
If an attack exposes personal data, Indonesia’s Personal Data Protection Law (UU PDP), in force since October 2024, requires you to notify affected people and the authorities within 72 hours, with fines up to 2% of annual revenue. It also covers any organisation handling Indonesian citizens’ data, even from abroad.


