Pretexting
Pretexting is social engineering with a prepared story. The attacker does not simply send a link and wait for a click; they build a scenario in which what they are doing looks normal. They present themselves as a colleague, technical support, an auditor, a bank, a supplier, a courier or an official.
Term
description · examples · notesPretexting is social engineering with a prepared story. The attacker does not simply send a link and wait for a click; they build a scenario in which what they are doing looks normal. They present themselves as a colleague, technical support, an auditor, a bank, a supplier, a courier or an official.
Description
The strength of pretexting is context. If the attacker knows an employee's name, the department, a supplier, a project or an internal process, the conversation no longer sounds like an attack. It sounds like work. The victim does not give things away out of carelessness but because the story fits their expectations.
Unlike mass phishing, pretexting requires thorough preparation. The attacker uses publicly available information, LinkedIn, the company website, job adverts, old emails and the habits of the organization. The goal can be a password, a document, access to a room, or a confirmation that opens the next step.
Examples
- The attacker presents themselves as a new member of the IT team and asks the user to confirm a password or an MFA code because accounts are supposedly being migrated.
- A call from a supposed auditor asks for urgent access to financial documents, citing the name of a real manager.
- Someone presents themselves as a courier or a service engineer and is let into the business premises because the story sounds routine.
Notes
- A good story is not proof of identity. The more detail somebody knows, the less it means they are legitimate and the more it means they prepared better.
- Identity is verified through an independent channel, not through the number, link or contact the attacker has just given.
Mentioned in the news
- 29. MAJ 2026. Novi proboj u Carnivalu — ukradeni podaci 6 miliona putnika →
- 5. MAJ 2026. FBI upozorava na krađu tereta preko lažnih logističkih firmi →
- 5. MAJ 2026. BlueNoroff cilja Web3 rukovodioce lažnim Zoom i Teams pozivima →
- 1. MAJ 2026. NASA zaposleni prevareni u kineskoj phishing kampanji za defense softver →
- 22. APR 2026. Severnokorejska kampanja preko lažnog Zoom ažuriranja cilja macOS korisnike →
- 22. APR 2026. Caller-as-a-Service prevara danas liči na organizovan call centar →
- 20. APR 2026. Microsoft upozorava na sve češće Teams lažno predstavljanje helpdeska →
Techniques
carried out with 2Techniques used to carry it out. Select one to open its page.
Defenses
countered by 4How it is defended against. Select one to open its page.