Glossary
Pretexting
Pretexting is lying with a plan. An attacker might pretend to be IT support needing your password, or an auditor requiring financial records. They build a believable story to get what they want. The more convincing the story, the more likely you'll fall for it.
What is Pretexting?
A social engineering technique where attackers create a fabricated scenario (pretext) to engage victims and extract information or manipulate them into performing actions.
Why Should You Care?
Pretexting succeeds because it bypasses technical controls—firewalls and encryption don't stop a convincing phone call from someone claiming to be from HR or IT. Employees are often the unwitting entry point for attackers seeking credentials, network access, or sensitive data, making pretexting a direct threat to confidentiality and compliance. Organizations face regulatory exposure when pretext attacks lead to unauthorized data disclosure, and the social trust required for business operations can be weaponized against internal security policies.
Is your business exposed?
Real-World Example
In a typical pretexting scenario, an attacker calls an employee posing as a vendor or support contractor, explaining that a system upgrade requires credential verification. The attacker provides fabricated but plausible context—mentioning recent legitimate system maintenance or citing a policy change—to create urgency and bypass skepticism. Once the employee provides credentials or sensitive information, the attacker gains legitimate system access without ever needing to exploit a technical vulnerability.
How to Protect Against Pretexting
- 1.
Verify identities through independent channels
- 2.
Create verification procedures for sensitive requests
- 3.
Train employees on pretexting tactics
Related Terms
Is your business exposed?
Check if your company data is circulating on the dark web
Free scan • No credit card required