Social engineering is the manipulation of people, rather than the hacking of systems, to gain access, information or money. Instead of breaking through a firewall, the attacker exploits trust, authority, curiosity, urgency and fear. The majority of successful breaches involve this human element, and email is where most of it arrives.
Key facts:
- Social engineering targets the one vulnerability that cannot be patched: human decision-making under pressure.
- Most social engineering reaches its target through email, with SMS, QR codes, phone calls and deepfake media as reinforcing channels.
- Generative AI removed the traditional warning signs. Fluent language, correct context and even cloned voices are now cheap to produce.
The psychological levers
Every social engineering attack pulls one or more of six levers: authority (instructions from a boss, lawyer or agency are obeyed), urgency (deadlines suppress reflection), fear (threats of consequences force mistakes), trust (familiar names and brands lower defenses), curiosity (irresistible links and attachments), and helpfulness (people want to assist a colleague in trouble). Training that teaches these levers ages far better than training that teaches yesterday's scam formats.
The attack types, mapped
| Attack | Channel | Lever pulled | What it wants |
|---|---|---|---|
| Phishing | Trust, urgency | Credentials, malware | |
| Spear phishing | Trust, authority | Access, payments | |
| Business email compromise | Authority, urgency | Wire transfers, payroll changes | |
| Vishing | Voice call | Authority, fear | MFA resets, passwords |
| Smishing | SMS | Curiosity, urgency | Credentials, payments |
| Pretexting | Any | Trust, helpfulness | Information for a later attack |
| Baiting | USB drops, free downloads | Curiosity, greed | Malware execution |
| Tailgating | Physical | Helpfulness | Building access |
How these attacks actually land in the inbox
Most social engineering follows the same delivery pattern regardless of label. First contact is clean: no link, no attachment, nothing for a filter to flag ("Are you at your desk?", "Quick question about the invoice"). Trust builds over one or two replies. Then comes the ask: a payment, a credential, a document, sometimes moved to SMS or a phone call to escape email security entirely. This is why payload-scanning alone fails: by the time anything technically malicious appears, if it ever does, the psychological work is already done.
What AI changed
Three things. Quality: AI-written attacks have no grammatical tells, in any language, in any corporate tone. Scale: personalization that took hours of research per target is now automated against thousands. Channels: cloned voices and deepfake video turn "verify by phone" into a weaker control than it used to be. Meanwhile, employees' own unsanctioned AI use (shadow AI) hands attackers new pretexts and new OAuth-based ways in. The constant that remains: the attacker still has to behave abnormally somewhere, in sender infrastructure, in relationship history or in intent.
How to defend
Defense in three layers. Procedures: verification through a second known channel for anything involving money, credentials or sensitive data, with no urgency exceptions. People: train the six levers, run realistic simulations, and make reporting suspected manipulation fast and blame-free. Technology: behavioral email security that models normal communication and flags deviations, because AI-written attacks are precisely the ones human vigilance and payload filters miss.
How Sentaro fits
Vord, Sentaro’s engine, is built for the payload-free era of social engineering: Message Defense reads intent and the impersonation infrastructure behind it, Behavioral Defense knows each relationship's normal, and App Defense sees the OAuth side doors. The clean first message that every filter passes is exactly the message it was designed to question.