Avatier

Attack vector

Social engineering of a person

Social engineering is deceiving a person into granting access on an attacker's behalf. The target might reset a password, enroll a new MFA device, approve a request or read out a code. Phone calls to the help desk, impersonated executives and urgent messages are common forms. The technology works as designed; the human decision is what fails.

A human was deceived into granting access, resetting a credential, or approving a request. Includes vishing and help-desk pretexting.

How attackers use it

Attackers research a target on social media and company sites, then call the help desk posing as an employee who is locked out or has a new phone. They rely on urgency, authority and just enough personal detail to sound real. A single successful call can hand over a password reset or a new MFA enrollment, which turns a conversation into a working login.

What breach letters say

12 distinct incidents in California breach filings name this vector in the letter’s own words (January 1, 2023 – August 14, 2026).

The 3 most recent of 12:

  • “Our investigation determined that the service outage was related to unauthorized access to our IT network, resulting from a user responding to a vishing call on May 29, 2026.”

    Quantum Health, Inc. · filed Aug 14, 2026 · letter

  • “We then determined that an unauthorized party used sophisticated social engineering tactics to access some of our systems between May 26, 2026 and June 1, 2026.”

    Lennar Mortgage, LLC · filed Aug 14, 2026 · letter

  • “Through this investigation, we learned that the unauthorized third-party gained access to our systems on June 5 through a social engineering attack targeting a single company user account and took with them certain data, including patient information.”

    AdaptHealth, LLC · filed Aug 14, 2026 · letter

See the Identity Attack Ledger

How to stop it

Verify a caller's identity at the help desk without relying on facts an attacker can look up, for example with a verified callback or a check against the user's existing authenticator. Require a second approver for resets on privileged accounts.

Terms under this vector

  • Business email compromise

    Business email compromise is a fraud in which an attacker uses a hacked or impersonated business email account to trick staff into sending money or sensitive data.

  • Deepfake voice

    A deepfake voice is synthetic speech, made with AI, that imitates a real person closely enough to fool listeners.

  • Pretexting

    Pretexting is social engineering built on an invented story, the pretext, that gives the attacker a believable reason to ask for information or access.

  • Vishing

    Vishing is voice phishing: using phone calls or voice messages to trick someone into handing over access.

Threat actors tied to it

Last reviewed Oct 2, 2026