Attack vector
Social engineering of a person
Social engineering is deceiving a person into granting access on an attacker's behalf. The target might reset a password, enroll a new MFA device, approve a request or read out a code. Phone calls to the help desk, impersonated executives and urgent messages are common forms. The technology works as designed; the human decision is what fails.
A human was deceived into granting access, resetting a credential, or approving a request. Includes vishing and help-desk pretexting.
How attackers use it
Attackers research a target on social media and company sites, then call the help desk posing as an employee who is locked out or has a new phone. They rely on urgency, authority and just enough personal detail to sound real. A single successful call can hand over a password reset or a new MFA enrollment, which turns a conversation into a working login.
What breach letters say
12 distinct incidents in California breach filings name this vector in the letter’s own words (January 1, 2023 – August 14, 2026).
The 3 most recent of 12:
“Our investigation determined that the service outage was related to unauthorized access to our IT network, resulting from a user responding to a vishing call on May 29, 2026.”
Quantum Health, Inc. · filed Aug 14, 2026 · letter
“We then determined that an unauthorized party used sophisticated social engineering tactics to access some of our systems between May 26, 2026 and June 1, 2026.”
Lennar Mortgage, LLC · filed Aug 14, 2026 · letter
“Through this investigation, we learned that the unauthorized third-party gained access to our systems on June 5 through a social engineering attack targeting a single company user account and took with them certain data, including patient information.”
AdaptHealth, LLC · filed Aug 14, 2026 · letter
How to stop it
Verify a caller's identity at the help desk without relying on facts an attacker can look up, for example with a verified callback or a check against the user's existing authenticator. Require a second approver for resets on privileged accounts.
Terms under this vector
- Business email compromise
Business email compromise is a fraud in which an attacker uses a hacked or impersonated business email account to trick staff into sending money or sensitive data.
- Deepfake voice
A deepfake voice is synthetic speech, made with AI, that imitates a real person closely enough to fool listeners.
- Pretexting
Pretexting is social engineering built on an invented story, the pretext, that gives the attacker a believable reason to ask for information or access.
- Vishing
Vishing is voice phishing: using phone calls or voice messages to trick someone into handing over access.
Threat actors tied to it
- ALPHV Blackcat
Profile with government sources
- Black Basta
Profile with government sources
- Lazarus Group
Profile with government sources
- Scattered Spider
Profile with government sources
Last reviewed Oct 2, 2026