Pretexting

Pretexting is a social engineering technique where an attacker invents a believable scenario to justify asking for information, access or money. It powers most business email compromise attacks.

Pretexting is a social engineering technique where an attacker invents a believable scenario, the pretext, to justify asking for information, access or money. While phishing often relies on a malicious link, pretexting relies on a story: the "CEO" who needs a payment approved before a deadline, the "supplier" with new bank details, the "IT technician" who needs a verification code.

Key facts:

Anatomy of a pretext

Effective pretexts combine four elements: a character (an authority the target expects to obey or help, like an executive, vendor or IT staff), plausible context (real project names, org charts and vendor relationships, harvested from LinkedIn, websites and breached data), urgency or confidentiality ("the acquisition is not public yet, keep this between us"), and a reasonable ask that grows once trust is established. The first message often asks for nothing at all ("Are you at your desk?"), which is exactly why it evades content filters.

Common pretexting scenarios in email

PretextThe storyThe goal
CEO fraudExecutive needs an urgent, confidential paymentWire transfer
Vendor impersonationKnown supplier announces new bank detailsRedirect invoice payments
IT helpdesk"We are migrating mailboxes, confirm your login"Credentials or MFA codes
HR/payroll"Update your direct deposit before payday"Salary diversion
Legal/authorityLawyer or regulator demands confidential documentsData theft
New employeeRecent hire asks for "help" with internal systemsAccess and reconnaissance

Modern variants extend the story across channels: an email followed by an SMS, or a deepfake voice call "from the CFO" that confirms the fraudulent email. The pretext is the constant; the channel varies.

Why pretexting beats traditional filters

Legacy email security looks for malicious payloads: bad links, infected attachments, known spam patterns. A well-built pretext contains none of that. It is a clean, well-written message from a plausible-looking sender, sometimes from a genuinely compromised vendor mailbox where every technical signal is legitimate. Detection therefore has to evaluate behavior and intent: Is this sender's address subtly different (see spoofing)? Does this request deviate from how this relationship normally communicates? Is a payment instruction appearing in a thread where none ever appeared before?

How to defend

Verification procedures beat vigilance: any request involving money, credentials or sensitive data gets confirmed through a second, known channel, no matter how legitimate it looks. Limit what attackers can research by tightening what employee and vendor details are public. Train teams on the psychology (authority, urgency, confidentiality) rather than on spotting bad grammar, which AI-written pretexts no longer have. And deploy email security that models relationships and intent rather than payloads. Targeted variants like spear phishing and broader social engineering techniques all rely on the same pretext mechanics.

How Sentaro detects pretexting

Sentaro's Behavioral and Message Intelligence layers learn how each organization actually communicates: who requests payments, in which threads, with what language and cadence. A pretext succeeds by imitating authority, but it cannot imitate history. When an instruction deviates from the learned relationship, a lookalike domain appears, or an intent shift occurs mid-thread, Sentaro flags or blocks it, link or no link.

FAQ

What is pretexting in simple terms?

Inventing a believable story to trick someone into handing over money, information or access. The attacker plays a role (boss, supplier, IT support) and the story makes the request seem legitimate.

What is the difference between pretexting and phishing?

Phishing is the broad category of deceptive messages, often carrying malicious links or attachments. Pretexting is the narrative technique: a fabricated scenario that justifies the request. Many of the most damaging phishing and BEC attacks are pure pretexting with no payload at all.

Is pretexting illegal?

Yes, in most jurisdictions pretexting for fraud is a crime, and obtaining certain records under false pretenses is specifically outlawed in laws like the US GLBA. Authorized social engineering tests conducted with consent are the legal exception.

What is a real example of pretexting?

Vendor invoice fraud is the classic: attackers compromise or imitate a real supplier, reference genuine order history, and announce updated bank details. The next legitimate invoice payment goes to the attacker's account.

How do you detect pretexting?

Look for context anomalies rather than technical ones: unusual requests from familiar names, slight sender address differences, new payment details, pressure for speed and secrecy. Technically, behavioral email security that knows each relationship's normal pattern catches what content filters miss.