← Glossary

Pretexting

Pretexting is a social engineering technique where an attacker invents a believable scenario to justify asking for information, access or money. It powers most business email compromise attacks.

Updated

Pretexting is a social engineering technique where an attacker invents a believable scenario, the pretext, to justify asking for information, access or money. While phishing often relies on a malicious link, pretexting relies on a story: the "CEO" who needs a payment approved before a deadline, the "supplier" with new bank details, the "IT technician" who needs a verification code.

Key facts:

  • Pretexting is the engine of business email compromise: the fraudulent instruction only works because the invented context makes it plausible.
  • Pretexts increasingly arrive without any malicious link or attachment, which is why they pass filters that only scan for known-bad content.
  • Generative AI has removed the effort barrier: researched, fluent, individually tailored pretexts can now be produced automatically.

Anatomy of a pretext

Effective pretexts combine four elements: a character (an authority the target expects to obey or help, like an executive, vendor or IT staff), plausible context (real project names, org charts and vendor relationships, harvested from LinkedIn, websites and breached data), urgency or confidentiality ("the acquisition is not public yet, keep this between us"), and a reasonable ask that grows once trust is established. The first message often asks for nothing at all ("Are you at your desk?"), which is exactly why it evades content filters.

Common pretexting scenarios in email

Modern variants extend the story across channels: an email followed by an SMS, or a deepfake voice call "from the CFO" that confirms the fraudulent email. The pretext is the constant; the channel varies.

Why pretexting beats traditional filters

Legacy email security looks for malicious payloads: bad links, infected attachments, known spam patterns. A well-built pretext contains none of that. It is a clean, well-written message from a plausible-looking sender, sometimes from a genuinely compromised vendor mailbox where every technical signal is legitimate. Detection therefore has to evaluate behavior and intent: Is this sender's address subtly different (see spoofing)? Does this request deviate from how this relationship normally communicates? Is a payment instruction appearing in a thread where none ever appeared before?

How to defend

Verification procedures beat vigilance: any request involving money, credentials or sensitive data gets confirmed through a second, known channel, no matter how legitimate it looks. Limit what attackers can research by tightening what employee and vendor details are public. Train teams on the psychology (authority, urgency, confidentiality) rather than on spotting bad grammar, which AI-written pretexts no longer have. And deploy email security that models relationships and intent rather than payloads. Targeted variants like spear phishing and broader social engineering techniques all rely on the same pretext mechanics.

How Sentaro detects pretexting

Sentaro's Behavioral and Message Defense vectors learn how each organization actually communicates: who requests payments, in which threads, with what language and cadence. A pretext succeeds by imitating authority, but it cannot imitate history. When an instruction deviates from the learned relationship, a lookalike domain appears, or an intent shift occurs mid-thread, Sentaro flags or blocks it, link or no link.

Questions we get asked.

What is pretexting in simple terms?

Inventing a believable story to trick someone into handing over money, information or access. The attacker plays a role (boss, supplier, IT support) and the story makes the request seem legitimate.

What is the difference between pretexting and phishing?

Phishing is the broad category of deceptive messages, often carrying malicious links or attachments. Pretexting is the narrative technique: a fabricated scenario that justifies the request. Many of the most damaging phishing and BEC attacks are pure pretexting with no payload at all.

Is pretexting illegal?

Yes, in most jurisdictions pretexting for fraud is a crime, and obtaining certain records under false pretenses is specifically outlawed in laws like the US GLBA. Authorized social engineering tests conducted with consent are the legal exception.

What is a real example of pretexting?

Vendor invoice fraud is the classic: attackers compromise or imitate a real supplier, reference genuine order history, and announce updated bank details. The next legitimate invoice payment goes to the attacker's account.

How do you detect pretexting?

Look for context anomalies rather than technical ones: unusual requests from familiar names, slight sender address differences, new payment details, pressure for speed and secrecy. Technically, behavioral email security that knows each relationship's normal pattern catches what content filters miss.

Stop reading about it. Watch it get blocked.

Free for one account. Four minutes to connect.