The Phone Call That Cost One Company $25 Million
In early 2024, a finance worker at engineering firm Arup was tricked into transferring $25 million after a video call with what appeared to be the company's CFO. Every person on that call was a deepfake. The attackers never touched a firewall, never exploited a software vulnerability, never brute-forced a password. They exploited something far more reliable: human trust.
That's what social engineering attacks look like in 2026. They don't break in. They get invited in. And if you think your organization is too sophisticated to fall for these tactics, I'd ask you to reconsider. The Arup incident wasn't pulled off against amateurs — it targeted trained financial professionals at a global firm.
This post breaks down exactly how social engineering attacks work, the psychological levers threat actors pull, and the specific defenses that actually reduce your risk. If you're responsible for protecting people or data, this is the most important attack vector you need to understand right now.
What Are Social Engineering Attacks?
Social engineering attacks are deliberate manipulation techniques that trick people into giving up confidential information, credentials, money, or access. Instead of targeting systems, the threat actor targets the person sitting in front of the system.
According to the Verizon 2024 Data Breach Investigations Report, the human element was involved in 68% of breaches. That's not a fluke — it's been a consistent pattern for years. Attackers go after people because people are predictable.
The most common forms include phishing emails, pretexting phone calls (vishing), SMS-based attacks (smishing), business email compromise, and increasingly, AI-generated deepfake impersonations. Every single one of these relies on the same core principle: exploiting trust, urgency, or authority.
The Psychology Behind the Attack
I've spent years studying why smart people fall for these schemes. It's not stupidity. It's neuroscience. Social engineering attacks exploit cognitive shortcuts that our brains use thousands of times a day.
Authority Bias
When an email appears to come from your CEO asking for an urgent wire transfer, your brain processes the authority signal before it processes the logic. Threat actors know this. They impersonate executives, IT departments, law enforcement, and vendors — anyone whose requests you'd instinctively comply with.
Urgency and Fear
"Your account will be locked in 15 minutes." "This invoice is past due — legal action pending." These messages bypass rational thought. When you're panicked, you click first and think second. That's the entire design.
Reciprocity and Helpfulness
An attacker calls your help desk, sounds friendly, mentions a few internal details they scraped from LinkedIn, and asks for a password reset. Your employee wants to be helpful. That helpfulness becomes the vulnerability.
The 5 Social Engineering Tactics I See Most in 2026
1. Phishing and Spear Phishing
Still the king. Mass phishing casts a wide net. Spear phishing targets specific individuals with personalized lures. A well-crafted spear phishing email referencing a real project you're working on — pulled from a public Slack channel or LinkedIn post — is devastatingly effective. Running regular phishing awareness training for your organization is one of the few proven countermeasures.
2. Business Email Compromise (BEC)
The FBI's IC3 has consistently ranked BEC as one of the costliest cybercrime types. In their 2023 Internet Crime Report, BEC accounted for over $2.9 billion in reported losses. Attackers compromise or spoof a legitimate business email account and use it to redirect payments or steal data. No malware required.
3. Vishing and Smishing
Voice phishing and SMS phishing have surged as organizations hardened email defenses. A phone call from "your bank's fraud department" or a text with a malicious link can bypass every email filter you own. These channels often feel more personal and trustworthy to the recipient, which is exactly why attackers use them.
4. Pretexting
This is long-con social engineering. The attacker creates a fabricated scenario — a pretext — to build trust over time. They might pose as a new vendor, a journalist, or an IT auditor. They gather small pieces of information across multiple interactions until they have enough for credential theft or account takeover.
5. AI-Powered Deepfakes
The Arup case wasn't isolated. Deepfake voice and video attacks are now commercially accessible. Attackers can clone a voice from a few seconds of audio pulled from a conference talk or podcast. When your CFO's voice calls and asks for something urgent, most employees comply. This is the frontier of social engineering attacks, and most organizations have zero defenses against it.
Why Technology Alone Won't Save You
I've seen organizations spend millions on endpoint detection, SIEM platforms, and next-gen firewalls — then lose everything because an accounts payable clerk opened a convincing PDF. Technology is essential, but it addresses the wrong half of the problem when it comes to social engineering.
Multi-factor authentication helps. It prevents stolen credentials from being immediately useful. Zero trust architecture helps. It limits what an attacker can access even after getting inside. Email filtering helps. It catches the obvious stuff.
But none of these tools can stop someone from willingly typing their credentials into a convincing phishing page, or verbally confirming a wire transfer to an impersonator. The only thing that addresses that gap is trained, skeptical humans.
Building a Human Firewall That Actually Works
Here's what I recommend based on what I've seen work across hundreds of organizations:
- Continuous security awareness training. Annual compliance videos don't change behavior. Ongoing, scenario-based training does. Start with a comprehensive cybersecurity awareness training program that covers the latest social engineering tactics, not just checkbox compliance.
- Regular phishing simulations. Send simulated phishing emails monthly. Track who clicks, who reports, and who improves. Simulations create muscle memory — the kind that makes someone pause before clicking a real attack.
- Verification protocols for financial requests. Every wire transfer, every payment change, every new vendor bank account should require out-of-band verification. Call the requester at a known phone number. Not the number in the email. A known number.
- Encourage reporting without punishment. If employees fear consequences for clicking a phishing link, they'll hide it. That delay between click and report is where ransomware spreads. Reward reporting. Punish cover-ups.
- Implement multi-factor authentication everywhere. MFA won't stop social engineering, but it adds friction that buys you time and blocks the simplest credential theft attacks.
How Do You Spot a Social Engineering Attack?
This is the question I get asked most. Here are the red flags that should trigger immediate skepticism:
- Unexpected urgency — "Do this now or else."
- Requests to bypass normal procedures — "Skip the approval process this time."
- Unusual sender addresses or phone numbers, even if the display name looks right.
- Requests for credentials, payment details, or sensitive data via email or text.
- Emotional manipulation — flattery, threats, or appeals to helpfulness.
- Too-good-to-be-true offers or unexpected attachments.
Train your people to verify before they trust. A 30-second phone call to confirm a request has prevented more data breaches than any piece of software I've ever deployed.
The Real Cost of Ignoring Social Engineering
A successful social engineering attack doesn't just cost money. It costs reputation, customer trust, regulatory standing, and sometimes the entire business. The Cybersecurity and Infrastructure Security Agency (CISA) has repeatedly warned that social engineering remains the top initial access vector for both nation-state actors and criminal organizations.
Small and mid-sized businesses are hit hardest. They often lack dedicated security teams, formal verification processes, and ongoing training programs. They're also less likely to recover from a major incident. A single ransomware deployment triggered by one phishing email can shut down operations permanently.
Your Move
Social engineering attacks aren't going away. They're getting more sophisticated, more targeted, and more difficult to detect. AI is making impersonation trivially easy. Remote work has dissolved the informal verification that happened naturally when everyone sat in the same office.
The organizations that survive this environment are the ones investing in their people — not just their perimeter. Start with training. Build verification processes. Run simulations. Create a culture where healthy skepticism is rewarded, not punished.
Your technology stack matters. But the person sitting at the keyboard matters more.