In September 2023, a threat actor called Scattered Spider social-engineered their way into MGM Resorts by calling the company's IT help desk. One phone call. That's all it took to trigger a shutdown that cost MGM an estimated $100 million. No zero-day exploit. No sophisticated malware. Just a convincing voice on the other end of a phone line.

Social engineering attacks remain the most effective weapon in a hacker's arsenal — not because the technology fails, but because humans do. If you're responsible for protecting an organization, this post breaks down the specific tactics attackers use, the psychology behind them, and what actually works to stop them.

What Are Social Engineering Attacks, Really?

Social engineering attacks are deliberate manipulation techniques that trick people into giving up confidential information, granting access, or taking actions that compromise security. They bypass firewalls, endpoint detection, and every other technical control by targeting the one thing you can't patch: human behavior.

The Verizon 2024 Data Breach Investigations Report found that 68% of breaches involved a human element — whether through social engineering, errors, or misuse of credentials. That number has barely budged in years. We keep buying better tools, and attackers keep picking up the phone.

I've investigated dozens of incidents where the initial access vector was social engineering. In every single case, the victim believed they were doing the right thing — helping a colleague, responding to an urgent request from their boss, or following what looked like standard IT procedure.

The 6 Tactics That Keep Working

1. Phishing — The Volume Play

Phishing emails remain the most common form of social engineering. According to the FBI's Internet Crime Complaint Center (IC3), phishing was the top reported cybercrime category in 2023 with over 298,000 complaints. Attackers send thousands of emails hoping a small percentage click. That small percentage is enough.

Modern phishing has evolved far beyond Nigerian prince scams. Today's phishing emails replicate Microsoft 365 login pages pixel-for-pixel. They use legitimate services like Google Docs and Dropbox to host malicious links. Your spam filter catches a lot, but not all.

2. Spear Phishing — The Precision Strike

Where phishing casts a wide net, spear phishing targets specific individuals. Attackers research your org chart on LinkedIn, read your company's press releases, and craft messages that reference real projects, real colleagues, and real deadlines.

I've seen spear phishing emails that referenced an actual board meeting happening that week. The attacker pulled the date from a publicly posted agenda. The CFO clicked because the context was perfect.

3. Pretexting — The Con Artist's Favorite

Pretexting is building a fabricated scenario to extract information. The MGM breach is a textbook example — the attacker impersonated an employee and convinced the help desk to reset credentials. No malware needed. Just a convincing story and a cooperative help desk agent.

Pretexting often targets HR, IT support, and finance teams. These departments are trained to be helpful, and attackers exploit that instinct ruthlessly.

4. Business Email Compromise (BEC)

BEC attacks impersonate executives or vendors to redirect payments or extract sensitive data. The FBI reported BEC losses exceeding $2.9 billion in 2023. That makes it the most financially damaging form of social engineering by a wide margin.

In a typical BEC scenario, your accounts payable team receives an email from what appears to be a vendor requesting a change in wire transfer details. The email address is one character off. The invoice looks legitimate. The money goes to an account the attacker controls.

5. Vishing — Voice Phishing

Phone-based social engineering is making a comeback, especially with AI voice cloning tools now widely available. Attackers call employees pretending to be IT support, law enforcement, or even the CEO. The urgency in a human voice creates pressure that email can't match.

6. Quishing — QR Code Phishing

A newer tactic involves malicious QR codes placed on parking meters, in email attachments, or even printed on physical mail. Scanning the code takes the victim to a credential theft page. It's effective because most people trust QR codes and scan them without thinking.

The Psychology That Makes These Attacks Devastating

Every social engineering attack exploits at least one of these psychological triggers:

  • Authority: An email from the CEO demanding immediate action bypasses critical thinking.
  • Urgency: "Your account will be locked in 15 minutes" forces hasty decisions.
  • Social proof: "Your colleague John already submitted his" reduces suspicion.
  • Reciprocity: An attacker who "helps" you first creates an obligation to help them back.
  • Fear: Threats of legal action, account closure, or job loss override rational analysis.

These aren't abstract concepts. They're the specific levers attackers pull in every engagement. Understanding them is the first step toward building real resistance in your workforce.

The $4.88M Lesson Most Organizations Learn Too Late

IBM's 2024 Cost of a Data Breach Report pegged the global average cost of a breach at $4.88 million — a record high. Social engineering and credential theft were among the most common initial attack vectors.

Here's what I keep telling executives: your employees are both your greatest vulnerability and your strongest potential defense. You can deploy multi-factor authentication, implement zero trust architecture, and segment your network. You absolutely should. But none of that matters if someone in your finance department wires $400,000 to a threat actor because they got a convincing email.

Technical controls reduce blast radius. Training reduces the likelihood of ignition.

How Do You Defend Against Social Engineering Attacks?

This is the question I get asked more than any other. Here's the framework that actually works:

Layer 1: Continuous Security Awareness Training

Annual compliance training doesn't change behavior. Continuous, scenario-based training does. Your team needs to see real-world examples of social engineering attacks — not cartoonish simulations, but realistic replications of what's actually hitting inboxes right now.

Our cybersecurity awareness training program covers the full spectrum of social engineering tactics with regularly updated content that reflects the current threat landscape.

Layer 2: Phishing Simulations

You don't know how your employees will respond to a phishing email until you test them. Regular phishing simulations identify who's clicking, who's reporting, and where your training gaps are. The goal isn't to shame anyone — it's to build muscle memory.

If your organization needs structured phishing simulation and training, our phishing awareness training for organizations provides exactly that — realistic simulations paired with immediate coaching for employees who engage with the test.

Layer 3: Technical Controls That Back Up Training

  • Multi-factor authentication (MFA): Even if credentials are stolen, MFA adds a second barrier. Prioritize phishing-resistant MFA like FIDO2 security keys.
  • Zero trust architecture: Never trust, always verify. Limit access based on identity, device posture, and context.
  • Email authentication: Deploy DMARC, DKIM, and SPF to reduce email spoofing.
  • Callback verification: Require out-of-band confirmation for any financial transaction changes or credential resets.

Layer 4: Culture

If employees are afraid to report a suspicious email because they might "look stupid," your security culture is broken. Build a culture where reporting is rewarded. Every reported phishing email is intelligence your security team can act on.

The organizations I've seen handle social engineering best are the ones where employees feel empowered to challenge requests — even from executives. Especially from executives.

What CISA Recommends Right Now

The Cybersecurity and Infrastructure Security Agency (CISA) maintains an extensive library of social engineering resources at cisa.gov. Their guidance aligns with everything I've outlined here: layer technical controls with human training, test regularly, and build organizational resilience.

CISA specifically recommends implementing phishing-resistant MFA across all critical systems and conducting regular tabletop exercises that include social engineering scenarios. If you haven't done a tabletop that includes a vishing or BEC scenario, add one to your 2026 calendar now.

The Uncomfortable Truth

Social engineering attacks aren't going away. They're getting more sophisticated with AI-generated voice clones, deepfake video calls, and LLM-crafted phishing emails that don't have the grammar mistakes we used to rely on as red flags.

Your technology stack matters. Your policies matter. But the human layer is where most breaches start and where most breaches can be stopped. I've seen a single well-trained employee save an organization from a six-figure wire fraud by pausing, picking up the phone, and calling the "CEO" who supposedly sent the urgent request. That call took 90 seconds. It saved everything.

Invest in your people. Test them. Train them again. That's how you beat social engineering.