An umbrella term for attack techniques that exploit human psychology and assumptions, rather than technical vulnerabilities, to steal information.
Examples include impersonating an IT staff member to ask for a password over the phone, or manufacturing a false sense of urgency to prevent calm judgment. Many phishing and business email compromise attacks are a form of social engineering. Employee security education, not just technical measures, is considered an effective countermeasure.
© 2026 ITBGM