In 2025, a threat group walked into a corporate network by making a phone call. No exploit, no malware, no vulnerability. Someone rang an IT help desk, said they were an employee who had been locked out, and asked for a password and MFA reset. Mandiant's M-Trends 2026 reporting recorded that group going from that first call to full domain administrator access in roughly forty minutes.
Nothing in that intrusion would have shown up in an endpoint detection tool, because nothing malicious was installed. The attack ran entirely on trust. And the reason it worked is not that the help desk agent was careless. It is that the caller pulled four separate psychological levers in about ninety seconds, and human beings are not built to notice that happening in real time.
That is what this article is about. Not the tools attackers use, but the specific pressure points they aim at, why those pressure points exist in all of us, and what actually works as a defense when your instincts are the thing being exploited. The social engineering psychological tactics below are drawn from current incident data rather than theory. If you can name the lever while it is being pulled, you have already broken most of its power.
Why Attackers Target People Instead of Systems
Start with the economics, because they explain everything else.
Breaking modern encryption is hard. Finding an unpatched, internet-facing zero-day is hard, expensive, and perishable. Convincing a stressed human being to approve something is none of those things. Verizon's 2026 Data Breach Investigations Report, built on more than 31,000 real-world incidents across 145 countries, found the human element present in 62 percent of breaches, up from 60 percent the previous year. Palo Alto Networks found social engineering was the leading initial access vector in 36 percent of its incident response cases, with two thirds of those aimed at privileged or executive accounts.
The money follows the same logic. The FBI's Internet Crime Complaint Center logged 16.6 billion dollars in US social engineering losses in 2024, a 33 percent jump from the year before, with business email compromise alone accounting for 2.77 billion of it. IBM's Cost of a Data Breach research puts the average breach at around 4.8 million dollars, with phishing the most common entry point.
Set against a corporate security budget, manipulating one person is the cheapest intrusion available. So the interesting question is not why attackers do this. It is why it keeps working on intelligent, trained, well-meaning people. The answer is that these tactics do not exploit stupidity. They exploit the mental shortcuts that make normal social and professional life possible.
The Six Classic Levers
Most of what attackers do maps onto the six principles of influence documented by psychologist Robert Cialdini, originally developed to explain sales and marketing, and now the standard framework for understanding social engineering. Microsoft's security team uses exactly this framework to explain the psychology of these attacks, and a substantial body of academic research has since tested how each principle performs in a security context.
Here they are in the form defenders actually encounter them.
| Lever | The shortcut it exploits | What it sounds like |
|---|---|---|
| Authority | We defer to people who outrank us or hold expertise | "This is the CFO. I need this processed today." |
| Urgency and scarcity | Time pressure shuts down deliberation | "The window closes in ten minutes." |
| Liking | We say yes more readily to people we like | Warmth, shared context, small talk before the ask |
| Social proof | We take our cues from what others are doing | "Everyone on your team has already completed this." |
| Reciprocity | A favor received creates pressure to return one | Unsolicited help, then a request |
| Commitment and consistency | We act in line with what we have already agreed to | A trivial first yes, escalating to a costly one |
Authority is the workhorse. It is why business email compromise so consistently impersonates executives, and why research on BEC finds that even the terse, clipped writing style of a busy senior leader functions as an authority signal. The trick is that authority is inferred from surface cues, a title in a signature block, a familiar voice, a confident tone, and those cues are trivially cheap to fake.
Urgency and scarcity work by removing the resource you most need in order to detect a scam, which is time. Studies of phishing compliance repeatedly find scarcity among the strongest predictors of whether someone acts on a fraudulent request. Deadlines do not just pressure you; they narrow your attention onto the deadline itself and away from the anomalies around it.
Liking is the quiet one, and it is arguably the most dangerous, because there is research suggesting that messages using authority and urgency are perceived as more suspicious than messages built on likeability. In other words, the lever people are least trained to spot is the one that raises the fewest alarms. An attacker who spends ninety seconds being pleasant and relatable has bought more compliance than one who barks orders.
Social proof turns your colleagues into unwitting accomplices. If the request implies that this is normal, that others have already done it, the question shifts from "should I do this?" to "why am I the only one hesitating?"
Reciprocity shows up in the "reject and retreat" pattern, where an attacker opens with a large request, accepts the refusal gracefully, then follows with a smaller one that now feels like a fair compromise. The target complies to reciprocate a concession that was never real.
Commitment and consistency is the engine behind multi-stage attacks. Once someone has answered two harmless verification questions, refusing the third feels inconsistent with what they have already done. Each small yes makes the next one structurally harder to refuse.
The Four Levers That Do Most of the Damage in 2026
Cialdini's framework is the foundation, but researchers have long argued it does not fully cover what security attackers actually exploit. Work by Stajano, Gragg, Ferreira and others extends it with triggers like strong emotion, distraction, overloading, and diffusion of responsibility. Four of these deserve their own treatment, because they dominate the current threat landscape.
Fear and threat. Where urgency creates pressure, fear creates panic, and panicked people stop evaluating. The lure is a suspended account, a security breach on your device, a legal notice, a payment that has already gone out. Fear is especially effective because it comes disguised as security itself. The message that says "your account has been compromised, act now" is exploiting your desire to be safe in order to make you unsafe.
Helpfulness. This is the one that breaks help desks, and it deserves more attention than it gets. Service desk agents, executive assistants, HR staff, and finance teams are hired, trained, and evaluated on their willingness to help people. When an attacker calls with a plausible problem, they are not fighting the target's instincts. They are riding them. This is why the help desk has become the single most reliable soft entry point in the enterprise, and why the fix cannot be "be less helpful."

A redacted phishing lure showing how authority, urgency, and fear are stacked in a single message.
Curiosity. The oldest one in the book and still effective. A file named "salary review 2026," a shared document with no context, a QR code on a poster. Microsoft's threat intelligence recorded QR-code phishing rising 146 percent in a single quarter of 2026, in part because scanning one moves the victim to a personal phone browser that sits outside corporate email scanning.
Cognitive overload and diffusion of responsibility. Attackers deliberately create noise. MFA fatigue attacks, where a target is flooded with authentication prompts until they approve one to make it stop, are pure overload; Verizon's data has tracked this prompt-bombing pattern as a distinct and growing category. Diffusion of responsibility works the other way, by making the target feel the decision is not really theirs: everyone is copied on the email, the request has apparently already been approved upstream, someone else will surely catch it.

MFA fatigue in practice: prompts sent minutes apart until one gets approved just to stop the noise.
They Are Never Used Alone
Here is the part that gets lost when these tactics are presented as a numbered list. Real attacks stack them, and the stack is what makes them work. Each lever buys a little compliance that funds the next one.
The pattern is not hypothetical. The group most associated with it, tracked as Scattered Spider, UNC3944, and Octo Tempest, has been running it successfully since 2022, and the victim list reads like a tour of the Fortune 500. Caesars in 2023, where attackers impersonated an IT user, convinced an outsourced help desk to reset credentials, and secured a reported 15 million dollar ransom payment. MGM Resorts weeks later, where an employee's details were lifted from LinkedIn and used to reset that employee's credentials, resulting in a six terabyte data theft. Transport for London. In 2025, UK retailers including Marks and Spencer, Co-op, and Harrods. Related activity attributed to ShinyHunters used vishing to reach Salesforce environments at Chanel, Pandora, Adidas, and Qantas.
Flashpoint's profile of the group notes that vishing became its primary initial access technique, with operators posing as employees to get help desk staff to reset passwords and MFA settings, and sometimes posing as the help desk to persuade employees to install remote monitoring tools under the guise of IT support. As one threat intelligence practitioner put it in a 2025 industry interview, the reason this tradecraft is so effective is that no malware or tooling is used for initial access, which places the entire activity outside the visibility of endpoint detection.
The 2026 Amplifier: Synthetic Voices and Faces
Everything above predates generative AI. What AI changed is not the psychology but the cost and the credibility of delivering it.
The canonical case remains the engineering firm Arup, whose Hong Kong finance employee made fifteen transfers totalling roughly 25.6 million dollars after joining a video conference in which every other participant, including the company's UK-based CFO, was AI-generated. Arup confirmed no internal systems were compromised. The entire breach happened on the human side of a video call.
The enabling technology is now commodity. Voice cloning from roughly three seconds of clean audio is achievable with widely available tools, and the raw material for it, conference talks, podcasts, webinars, earnings calls, is published by organizations themselves. Ponemon research suggests around 40 percent of executives have already experienced some form of deepfake attack. IBM found that roughly one in six breaches now involve attacker use of AI.
Two consequences matter for defenders. First, the classic phishing tells are gone. Awareness training built around poor grammar, generic salutations, and clumsy phrasing is training people to detect a 2022 attack. AI-generated lures are fluent, personalized, and reference real projects and real colleagues. Second, and more subtly, verification by voice is no longer verification. Telling employees to "just call and check" fails if the attacker controls or can synthesize the channel they call.
Now the honest counterweight, because the AI panic has gotten ahead of the evidence. Mandiant's assessment in M-Trends 2026 is that 2025 was not the year breaches were the direct result of AI. The overwhelming majority of successful intrusions still came down to human and systemic failures: weak identity verification, over-permissioned accounts, and inconsistent MFA. AI made the manipulation cheaper and more convincing. It did not create the weakness. That distinction should drive your spending, because it means the highest-return investment is still process discipline, not a deepfake detector.
Why Awareness Training Alone Keeps Failing
If knowing about these tactics were sufficient, the numbers would be falling. They are not, and the reason is worth sitting with.
Recognizing manipulation and resisting it are different skills. Reading a list of red flags once a year does very little to change how someone behaves when a caller who sounds exactly like their CFO demands a wire transfer in three minutes. In that moment the target is not running a checklist; they are experiencing time pressure, deference, and the fear of being the person who blocked something important. Annual compliance training satisfies an auditor. It does not build a reflex.
There is also a design problem. Traditional programs are channel-specific, built around email, while modern campaigns move across email, SMS, phone, chat, and video, pivoting to whichever channel the target does not have their guard up on. And blame culture makes it worse: employees who fear discipline report incidents late or not at all, which turns a recoverable mistake into a full breach.
None of this means training is useless. It means training has to be frequent, multi-channel, and scenario-based rather than annual and email-shaped, and it has to be paired with controls that do not depend on any individual being alert on their worst day.
What Actually Works
The defenses that hold up share one property: they move the decision out of the moment of pressure and into a process that cannot be talked out of.
- Out-of-band verification, with no exception for urgency. Any request involving money movement, credential resets, MFA changes, or sensitive data gets confirmed through a separate channel, using contact details you already hold rather than any provided in the request. The critical clause is the second half. Attackers manufacture urgency precisely to buy an exception, so a policy with an urgency exemption is a policy with an attacker-shaped hole in it.
- Harden the help desk specifically. Both the UK's NCSC and CISA have urged organizations to review password reset procedures after the help-desk vishing wave. The workable pattern is to move privileged resets and MFA method changes out of phone-based identity checks entirely, into an out-of-band flow through your identity provider, so that a persuasive caller simply has no path to the outcome they want.
- Phishing-resistant authentication. FIDO2 keys and passkeys defeat a whole category of these attacks, because a credential the user cannot read aloud is a credential they cannot be talked into surrendering. This single change neutralizes MFA fatigue and most credential vishing.
- Named, mandatory friction on high-value actions. A required hold period before releasing a wire, dual approval that cannot be waived, and a rule that no payment is approved on urgency alone. These are deliberately slow by design, and the slowness is the control.
- Reduce the raw material. Every public org chart, conference bio, and detailed LinkedIn profile is pretext material. You cannot and should not eliminate a public presence, but knowing that it feeds attacker research changes what you publish.
- Build a no-blame reporting culture. The single best early-warning system you have is an employee who realizes mid-call that something is wrong and tells someone immediately. Fear of punishment destroys that system.
There is a genuinely encouraging case study buried in this. When LastPass was targeted with an audio deepfake of its CEO, the attempt collapsed, and it collapsed for a specific reason: the message arrived outside the executive's normal communication channel and it pushed urgency. The employee noticed both. That is not luck. Those two traits, wrong channel and manufactured time pressure, are the most reliable tells in the entire discipline, and they survive even when the voice is perfect.
What This Means for CTI Analysts
For a threat intelligence function, there is a specific discipline here that goes beyond awareness.
Pretexts are tradecraft, and tradecraft is trackable. The scenarios a group reaches for, the fake finance-team caller, the fake IT support, the vendor bank-change request, are as characteristic as their malware, and voice phishing has its own place in the MITRE ATT&CK framework as spearphishing voice. Documenting which pretexts a group favors, which roles they target, and which channels they pivot to gives detection and awareness teams something far more actionable than a generic warning.
The upstream work matters too. These campaigns run on research: leaked credentials, exposed org charts, and personal data that make a pretext credible. Monitoring your own organization's exposure in credential dumps and underground channels is how you find out what an attacker already knows about your people, which is exactly the kind of collection covered in our breakdowns of the initial access broker ecosystem and Telegram as a cybercrime marketplace. And when the manipulation succeeds, the payload increasingly arrives through techniques like ClickFix, where the victim is walked into running the command themselves, which is the same psychology applied to a keyboard instead of a phone call.
This is the kind of ecosystem literacy CTI Academy's Hunter track is built to develop. Our NullBase environment lets you practice reading actor tradecraft and persona behavior in a simulated underground, and LeakLens puts you inside the credential and breach data that attackers mine to build their pretexts in the first place. A phishing simulator and a SOC simulator are also on the CTI Academy roadmap, which will add the operational reps on the detection and lure-analysis side. If you want to learn to read this behavior the way an analyst has to, start with the Hunter track.
Frequently Asked Questions
What are the most common psychological tactics used in social engineering?
The most common are authority, urgency and scarcity, liking, social proof, reciprocity, and commitment and consistency, drawn from Cialdini's principles of influence. In current attacks, four more do heavy damage: fear, exploiting helpfulness, curiosity, and cognitive overload such as MFA fatigue. Real attacks stack several of these together.
Why does social engineering work on intelligent, trained people?
Because these tactics do not exploit ignorance, they exploit the mental shortcuts that make normal social and professional life work. Deferring to authority, responding to deadlines, and wanting to help colleagues are useful instincts, not flaws. Under time pressure, people do not run checklists, they run instincts, which is exactly what attackers target.
What is the most effective psychological tactic in social engineering?
Authority and urgency are the most used, especially in business email compromise, but research suggests messages built on likeability arouse less suspicion than those using authority or urgency. In enterprise attacks, exploiting helpfulness at the help desk has been the most consistently successful route, because it turns the target's job description into the attack path.
How has AI changed social engineering psychology?
AI has not changed the psychology, it has lowered the cost and raised the credibility of delivering it. Voice cloning needs only seconds of audio, and deepfake video enabled a 25.6 million dollar fraud at engineering firm Arup. Classic tells like poor grammar are gone. Mandiant notes that most 2025 breaches still stemmed from weak identity verification rather than AI itself.
Why does security awareness training fail to stop social engineering?
Because recognizing manipulation and resisting it under pressure are different skills. Annual, email-focused training teaches people to spot 2022-style phishing indicators, while modern campaigns are fluent, personalized, and move across phone, SMS, chat, and video. Effective programs are frequent, multi-channel, and scenario-based, paired with controls that do not rely on individual vigilance.
How can organizations defend against psychological manipulation?
Move decisions out of the moment of pressure. Require out-of-band verification for money movement, credential resets, and MFA changes with no exception for urgency, harden help desk reset procedures as NCSC and CISA advise, deploy phishing-resistant authentication like FIDO2 or passkeys, enforce mandatory holds and dual approval on high-value actions, and build a no-blame reporting culture.
What are the warning signs of a social engineering attempt?
The two most reliable tells are a request arriving through an unusual channel and manufactured time pressure. Both were what caused a deepfake attempt against LastPass to fail. Other signs include pressure to bypass normal process, requests to keep something confidential, and any caller directing you to a verification channel they supplied.
Sources
- Verizon, 2026 Data Breach Investigations Report
- Mandiant / Google Cloud, M-Trends 2026
- Microsoft Security, The psychology of social engineering, the soft side of cybercrime
- Flashpoint, Scattered Spider: A Threat Profile
- ReliaQuest, Scattered Spider Targets Tech Companies for Help-Desk Exploitation
- FBI Internet Crime Complaint Center, Internet Crime Report
- IBM, Cost of a Data Breach Report
- Springer / WISE 2024, On How Cialdini's Persuasion Principles Influence Individuals in the Context of Social Engineering