Social Engineering Attacks: How to Protect Your Business

Social engineering is the act of manipulating people into revealing confidential information, approving fraudulent requests or granting system access. It works on people and processes rather than on a technical weakness, though it is often combined with one. The attacker persuades someone who already has access to act on their behalf.

A hacker does not need to break into your systems if they can talk their way in. And they no longer need much of your voice to do it. How much they need depends on the tool and the quality of the recording, but research systems have synthesised speech from samples of a few seconds, and a single conference recording holds far more than that.

New Zealand’s own numbers put the problem in proportion. In its report for April to June 2026 the National Cyber Security Centre lists scams and fraud as the most reported incident category, followed by phishing and credential harvesting. Those are reports from New Zealanders generally rather than a count of attacks on businesses. Social engineering can feature in both, sometimes alongside malware or a compromised account.

What has changed is not the psychology. It is the cost of impersonating someone convincingly. This guide covers the pressures these attacks apply, what they look like now, and the verification process that gives staff a reliable way to check.

Why Does Social Engineering Still Work?

Because it targets people and processes rather than systems. No firewall blocks a convincing phone call, and no antivirus catches a message that contains no malware. Social engineering succeeds by exploiting the way people make decisions under pressure, and those decision-making shortcuts have not changed in decades. Technical controls still matter, because the same attempt often ends in a compromised account or a payment that phishing-resistant authentication and enforced approval rules would have stopped.

Phishing and credential harvesting work the same way: they convince someone that a message or a caller is genuine, then rely on that person to hand over information, credentials or money. The technique is the constant. The delivery is what keeps changing.

What Psychological Triggers Do Attackers Actually Pull?

Five common ones, and they tend to be used in combination rather than alone. This is not a complete taxonomy, and other motives get used too. Recognising the pressure is more reliable than trying to spot the fake, because the pressure is what the attacker needs and cannot disguise.

  • Authority. The request appears to come from a manager, an executive, or someone from IT. Questioning it feels like insubordination.
  • Urgency. It must be done now, which removes the time in which someone would otherwise check.
  • Familiarity. The sender sounds or looks like someone already known and trusted, so the usual scrutiny never engages.
  • Fear. Not complying is presented as having consequences, for the business or for the person being asked.
  • Reciprocity. The attacker does something helpful first, which makes refusing the follow-up request feel rude.

Urgency, authority and familiarity can pressure people into acting before they check. They are reasons to use the verification process, not proof that a request is fraudulent. Clear approval rules and technical controls should support staff even when a request looks convincing, and a request that resists being checked at all is the one worth pausing on.

Five social engineering triggers: authority, urgency, familiarity, fear and reciprocity, with urgency disabling the others

What Are the Main Social Engineering Techniques?

The social engineering techniques below are examples of how a deceptive request reaches people, across the channels it tends to arrive on. Message-level detail on deceptive emails and links sits in our guide to phishing scams, which this page does not repeat.

Technique How it reaches you What it is asking for
Phishing and smishing An email or text message posing as someone you deal with A reply, a login entered on a fake page, or a payment. See phishing scams
Vishing A phone call, increasingly using cloned audio of someone you know A payment approved, a bank account changed, or a password read out
Deepfake video A live or recorded video call with a familiar face on it Authorisation for a transfer, usually framed as confidential
Pretexting An invented identity or situation, used in a single contact or across several Information or access that the invented story makes seem reasonable to give
Baiting An offer of something appealing, physical or digital A click, a download, or a device plugged in
Quid pro quo An offer of help, most often posing as IT support Credentials, handed over as part of the fix
Tailgating A person following a staff member through a secure door Physical access to a server room, a desk or an unlocked screen

Tailgating is the one businesses forget, because it arrives at a door rather than through a device. If you have a server room, a comms cupboard or a reception area that leads to unlocked desks, it belongs on your list.

What Does Social Engineering Look Like in Person?

In-person social engineering uses a doorway instead of a phone line, but it applies exactly the same pressures.

The familiar version is someone walking in behind a staff member with their hands full, or wearing a courier’s uniform, or carrying a ladder. Holding the door open for them is ordinary courtesy, which is precisely the point: reciprocity and familiarity do the work, and challenging a stranger feels ruder than letting them through. A contractor pretext runs on the same fuel. Almost nobody wants to be the person who demands identification from a tradesperson who says they are here for the air conditioning.

Once inside, what they are after is rarely dramatic. It is an unlocked screen at an empty desk, a comms cupboard propped open, a network port in a meeting room, a password on a note under a keyboard, or a printer tray with payroll sitting in it. A USB drive labelled with something interesting and left in reception or a car park is the same idea in physical form, and it works because the person who finds it plugs it in to see whose it is.

The controls against physical social engineering are unglamorous and they hold up:

  • A visitor sign-in that someone actually enforces, with visitors escorted rather than pointed in a direction.
  • Comms cupboards, server rooms and storerooms locked by default, not locked when somebody remembers.
  • Screens locked when people step away, set by policy rather than left to habit.
  • A named contact on each floor or site to raise an unfamiliar face with, so it does not fall to whoever happens to be nearest.
  • Unfamiliar removable media handed to IT rather than plugged in to see whose it is.
  • A stated rule that checking who someone is counts as doing the job properly, in the same way that verifying a payment does. Where their authority to be there is unclear, contact reception, the site lead or security and follow the visitor procedure rather than confronting them.

That last point carries more weight than the locks. The reason this works in a friendly office is social rather than technical, so the fix has to be social too.

How Do Attackers Research You Before They Make Contact?

By reading what you have already published, which for most New Zealand businesses is enough to build a convincing pretext in an afternoon. A call that sounds like it comes from someone who knows your business usually does, because the caller spent an hour on your website first.

The material an attacker works from is ordinary, and none of it is stolen:

  • Your team page. Names, job titles and who reports to whom, which is what makes an authority pretext land.
  • Recent arrivals on LinkedIn. Someone three weeks into a role does not yet know what a normal request looks like, and has every reason not to push back on a director.
  • Out-of-office replies. These routinely name a covering colleague and a return date, which hands over both the pretext and the window in which to use it.
  • Your own case studies and supplier logos. They tell an attacker which invoices you would find unremarkable.
  • Conference talks, webinars and video posts. This is where a voice sample comes from.
  • Tender documents and council records. Frequently published with a named contact and a direct line.

The answer is not to delete any of it. Most of this material exists because it wins work, and stripping it out would cost more than the risk it carries. The answer is to know it is there, and to brief people before the predictable moments when it gets used.

If a director’s leave is public knowledge, the fortnight they are away is a predictable window, and it is worth saying so to the people who approve payments before the leave starts rather than after it ends. That is a briefing on top of the standard check, not a reason to apply a lighter one to anybody else.

How Has AI Changed These Attacks?

It has not invented new ones. It has made the convincing versions cheap enough to use at volume, which is the same conclusion our guide to AI in cybersecurity reaches about attacks generally. Social engineering itself is old. The barrier to doing it convincingly has collapsed.

Voice and video impersonation is now sold as a service, which puts convincing social engineering within reach of attackers with no technical background at all. The identity provider Signicat reported in early 2025 that deepfakes had gone from 0.1% to around 6.5% of the fraud attempts it detects, roughly one in fifteen. Those are its own detection figures rather than a measurement of New Zealand, and they are best read as direction of travel.

The best-documented case remains the engineering firm Arup. In January 2024 a finance employee in its Hong Kong office made a series of transfers totalling HK$200 million, about US$25 million, after a video call on which the chief financial officer and several colleagues were all deepfakes. Arup confirmed to the Financial Times that false voices and images were used, and declined to give further details while the matter was investigated. No technical breach has been suggested. Someone was persuaded.

Impersonation is not confined to the deepfake framing either. In its reporting year to March 2025, the US Identity Theft Resource Center recorded impersonation as the most reported type of scam, with the impersonator posing as a business in about half of cases and as a financial institution in a fifth. That is US victim reporting rather than New Zealand data, and it is not a measure of AI, but the shape of it matches what the NCSC records here.

What Should Make Your Team Stop and Check?

The tells staff were taught to look for, poor grammar and odd addresses, were symptoms of attackers working at volume in a second language. They still show up, but their absence no longer tells you anything. What remains reliable is the shape of the request rather than the quality of the writing.

  • Any instruction to move money, change bank details or grant access that arrives by phone or video alone.
  • Urgency that removes the time to verify, particularly near the end of a day or a week.
  • A known contact asking for something outside their normal role or authority.
  • Pressure to bypass an approval step, or to keep the request between the two of you.
  • Contact from an unfamiliar number claiming to be someone whose number you already hold.

None of these depend on the staff member detecting a fake. That is the point. Detection by ear or eye is no longer a defence you can reasonably ask people to provide, so the defence has to be procedural rather than perceptual.

How Do You Protect a New Zealand Business Against This?

With a verification rule that applies regardless of who appears to be asking, and a culture that makes using it safe. Technology helps, but the control that stops social engineering is a process one.

Write down a verification protocol, and make it cover more than money

Any high-risk request must be confirmed through a second, independent channel before it is actioned. Independent means a number you already hold, from a trusted directory or supplier record, not a number supplied in the message and not a reply to the message itself. If the usual contact is unavailable, use the agreed escalation route rather than treating urgency as permission to skip the check.

Most businesses that have this rule apply it only to payments. It should also cover requests for sensitive information, access grants and changes to who can approve things, because those are the requests that make the next fraud possible rather than the one in front of you. Bank account changes specifically are covered in more depth in our phishing scams guide.

Confirming who someone is does not make their request permissible. Check that the person has the authority to ask, and use a second approver where your payment or access policy requires one. Passwords, recovery codes and one-time authentication codes are never read out to a caller, and an unexpected sign-in prompt is never approved, however well the request has been verified. Where a shared service credential is genuinely needed, it goes through your approved access process rather than an ad hoc conversation.
Verifying a payment request on the attacker's channel versus a channel you already held, and the outcome of each

Back the protocol from the top

This is the part most policies leave out and the part that decides whether the rest works. Staff do not skip verification because they have forgotten it. They skip it because the person apparently asking is senior and in a hurry.

Say plainly, in writing, that staff will be supported when they follow the protocol in good faith, including when that delays a senior colleague. Make the escalation route clear, and make it easy to report a mistake quickly. Without that, the authority pressure beats the policy every time.

Be deliberate about public audio and video of key staff

Voice clones are built from whatever is publicly available: conference recordings, webinars, video posts, media interviews. This is not an argument for silence, and for most businesses the marketing value outweighs the risk. It is an argument for knowing which voices are easy to obtain, and for telling the people who approve payments that a familiar voice is not evidence of anything.

Train for the channel, not just the inbox

Awareness training is a programme rather than a single fix, and our guide to security awareness training covers cadence, simulations and how to measure whether it is working. The point specific to social engineering is scope: if your simulations only ever arrive by email, your staff are only rehearsed against one channel. Voice and pretexting scenarios belong in the programme too.

What Should You Do If Someone Has Already Acted on One?

Tell your IT or security contact and the responsible manager straight away, and treat a successful social engineering attempt as an incident rather than as somebody’s mistake. Say what actually happened: a payment made, information disclosed, a password entered, a sign-in approved, something downloaded, or someone let through a door. Do not wait to gather every detail, and run the steps below in parallel wherever you can rather than in sequence.

If money was sent or bank details were changed, contact the bank through its fraud channel immediately and ask about stopping or recalling the payment. A recall has a far better chance within hours than within days, though recovery is never guaranteed.

If an account may be compromised, have IT secure it rather than relying on a password change alone. Sessions need revoking, and sign-in activity, recovery methods, connected applications and mailbox rules all need checking, since forwarding rules are routinely added to hide the replies that would have given the game away. If software was run or a device was plugged in, say so, because the device needs looking at too. Keep the original message, the calendar invitation, the number that called and any voicemail. Delete nothing.

Warn colleagues and any affected contacts promptly, through a channel you trust rather than the one the request arrived on. These attempts usually go out as a batch aimed at several people at once, so whoever acted is rarely the only one who was asked.

Report the incident to the National Cyber Security Centre, and assess whether personal information was involved and whether the Privacy Commissioner and the people affected need to be notified. Reporting matters beyond your own case, because it is what makes the quarterly picture accurate for everybody else. Once it is contained, the question worth asking is not who fell for it, but which control would have caught it, and our guide to building an incident response plan covers how to write that down before you need it.

Frequently Asked Questions

What is a social engineering attack?

A social engineering attack manipulates people rather than systems, tricking someone into revealing credentials, approving a fraudulent payment or granting access through deception rather than technical exploitation. It exploits trust, authority, urgency and familiarity, and the deception is often combined with a technical element such as a compromised account.

What are the five psychological triggers social engineering uses?

Authority, urgency, familiarity, fear and reciprocity. These are common pressures rather than a complete list, and they tend to be used in combination. Urgency matters most in training, because it removes the time in which someone would otherwise check. It does not switch off approval rules or technical controls, which is why those need to be in place as well.

What is pretexting in social engineering?

Pretexting is using an invented identity or situation to make a request seem legitimate, such as posing as IT support, a supplier or a bank. It can happen in a single conversation or across several contacts. The invented story is the defining feature, not its length. Verify the request through an established route before disclosing information or granting access.

What is vishing?

Vishing is social engineering conducted by phone. The caller creates a plausible scenario requiring urgent action, increasingly using AI-cloned audio of an executive, an IT staff member or a supplier. The defence is a callback on a number you already hold, never the number that called you.

What is a deepfake social engineering attack?

One that uses AI-generated audio or video to impersonate a known person, typically an executive or a trusted supplier. The attacker builds the clone from publicly available recordings, then calls or joins a video meeting to request a payment or access. It is harder to resist because the voice and face belong to someone the recipient knows.

What is Deepfake-as-a-Service?

Commercial platforms that sell ready-made voice cloning and video impersonation to anyone willing to pay, including criminals with no technical skill. Its significance is not that the technology is new but that the skill barrier has gone, which is why impersonation now arrives at businesses that would never have been worth the time of a specialist.

Has AI created a new kind of social engineering?

Not really. It has made the existing techniques cheaper, faster and available to less skilled attackers. The triggers being pulled are the same ones described a century ago in confidence tricks. What AI changed is how convincingly and how cheaply an attacker can pretend to be someone specific.

How can staff spot a social engineering attempt now?

By the shape of the request rather than the quality of the fake. Any request creating urgency, bypassing an approval step, asking for payment or credentials by phone or video alone, or asking for secrecy should trigger verification. Staff should not be asked to detect a deepfake by ear or eye.

What should a verification protocol cover?

Payments, bank account changes, sensitive information and access changes. Confirm the request through contact details you already hold, not a reply to the request and not a number it supplied, then check that the person has the authority to ask and follow the approvals your policy requires. It applies regardless of the apparent seniority of the requester, and verification is never permission to disclose a password or an authentication code.

Do social engineering attacks really target small New Zealand businesses?

Yes. Scams and fraud was the most reported incident category in the NCSC report for April to June 2026, followed by phishing and credential harvesting, though that covers reports from New Zealanders generally rather than businesses alone. Attacks of this kind are largely automated in their early stages, so business size is not much of a filter.

How does Exodesk help with social engineering?

We help design and document verification protocols, run phishing and voice-based simulations, and deliver security awareness training from our Christchurch and Dunedin offices. Where a business already has a programme, the more useful exercise is usually testing whether the verification rule survives contact with a senior person in a hurry.

NEXT STEP

Who verifies a payment request at your place?

If the answer depends on who is asking and how urgent it sounds, that is the gap social engineering walks through. We help New Zealand businesses write a verification protocol that holds, and test it against realistic attempts before someone else does.

Or read more about our cyber security services.

Start typing and press Enter to search

Proactive IT monitoring banner showing a fault intercepted on a monitoring line before it reaches staff systemsIT strategy banner: a short document with decisions ticked and one crossed out, beside a stack of unopened supplier quotes Call Us Now