Cybercriminals do not always need advanced software to steal information or enter protected accounts. They can sometimes persuade an employee or customer to provide access willingly. Pretexting is a social engineering technique that uses a believable false identity and invented situation to gain trust. The attacker then uses that trust to request sensitive information, money, account access, or another harmful action.
A pretexting attack may begin through an email, phone call, text message, social media account, or face-to-face conversation. The attacker may pretend to be a manager, bank employee, technical support worker, supplier, government official, or trusted family member. Each detail is selected to make the false story appear reasonable to the target. NIST defines social engineering as deception used to obtain sensitive information, unauthorized access, or fraudulent action by gaining confidence and trust.
Pretexting attacks can affect individuals, small businesses, financial institutions, healthcare organizations, and government agencies. A successful attacker may steal login details, employee records, financial information, identity documents, or confidential business data. The stolen information may then support account takeover, identity theft, payment fraud, or a larger cyberattack. The FTC has historically used the term pretexting for obtaining sensitive financial or telephone information through fraud or false representation.
Understanding pretexting is important because the message may not contain an obvious virus or malicious attachment. The danger often comes from the attacker’s story, confidence, timing, and knowledge about the target. People can lower their risk by slowing down, checking identities, and following secure verification procedures. This article explains how pretexting works, how to recognize it, and how individuals and organizations can prevent it.
What Is Pretexting?
Pretexting is the creation of a false identity or situation to persuade someone to reveal information or perform an action. The invented situation is called a pretext because it gives the attacker a believable reason for making the request. Instead of immediately asking for a password, the attacker first explains why the information appears necessary. This preparation helps the request feel normal, urgent, or connected to the target’s responsibilities.
An attacker may claim to be checking an account, investigating fraud, fixing a technical problem, or completing an important payment. The person may know the target’s name, job title, supervisor, recent purchase, or service provider. These details can make the caller or sender sound informed and trustworthy. Information shared publicly on company websites and social media can help criminals build convincing stories.
The attacker normally wants the target to stop questioning the request and follow instructions quickly. Fear may be used by warning that an account will close or that the target has violated a rule. Authority may be used by pretending to be a manager, police officer, regulator, or senior executive. Trust may be used by pretending to be a colleague, customer, supplier, friend, or relative.
Pretexting belongs to the wider category of social engineering because it targets human judgment rather than only technical weaknesses. The attack can be used alone or combined with phishing, malicious websites, fake documents, and stolen accounts. It can also prepare the target for a second attack by collecting small pieces of personal information first. NIST describes social engineering as manipulating a person into disclosing information, granting access, or participating in fraud.
How a Pretexting Attack Works
The first stage of pretexting usually involves research about the intended target. An attacker may study social media profiles, company websites, professional directories, public records, and leaked information. The goal is to learn names, relationships, responsibilities, locations, routines, and communication styles. These details help the attacker create a story that matches the target’s real situation.
The next stage involves selecting an identity that the target is likely to trust or obey. The attacker may impersonate an executive when contacting an employee responsible for payments. A fake bank representative may contact a customer about an invented security problem. The FBI has warned that criminals impersonate financial institution support staff to obtain login credentials and take over accounts.
The attacker then presents a problem that appears to require immediate action. The target may be told that a payment is late, a computer is infected, or an account has been compromised. Urgency reduces the time available for careful checking and makes unusual requests feel necessary. The FTC warns that scammers often use fear and urgency while pretending to be trusted businesses or senior employees.
The final stage involves requesting information, access, money, or a change to a normal business process. The attacker may ask for a verification code, password reset, payment transfer, employee record, or remote computer connection. After receiving the first item, the person may continue requesting additional information because trust has already been established. The attack succeeds when the target follows the invented story instead of confirming the request independently.
Common Examples of Pretexting Attacks
A common example involves an attacker pretending to be a bank employee who has detected suspicious activity. The caller asks the customer to confirm account details, passwords, or one-time verification codes. The criminal may sound helpful and claim that the information is needed to stop an unauthorized transaction. The FBI has reported account takeover schemes in which criminals impersonate financial support staff through fraudulent calls, emails, and text messages.
Another example involves a fake executive asking an employee to make an urgent payment. The message may claim that the executive is attending a meeting and cannot follow the normal approval process. The attacker may request a wire transfer, gift cards, cryptocurrency, or a change to supplier banking information. The FBI describes business email compromise as a damaging fraud in which criminals send requests that appear to come from a known and trusted source.
Technical support pretexting occurs when a scammer claims that a computer or online account has a serious problem. The target may be asked to install remote access software, open a website, or share login information. The scammer can then steal information, install unwanted software, or demand payment for a fake repair. The FTC warns that technical support scammers use false warnings to obtain money, financial information, or remote computer access.
Attackers may also impersonate human resources staff, delivery companies, government agencies, police officers, or family members. A fake human resources message might request payroll credentials or ask an employee to change direct deposit details. A family emergency story may claim that a relative needs immediate money and cannot speak freely. The FTC explains that imposter scams generally involve someone pretending to be trusted in order to persuade the target to send money.
Pretexting Versus Phishing
Pretexting and phishing are both forms of social engineering, but they describe different parts of an attack. Pretexting focuses on the invented identity, relationship, and situation used to gain the target’s trust. Phishing usually involves a deceptive digital message designed to steal information or lead someone to a fake website. NIST describes phishing as a digital social engineering method that uses authentic-looking messages or websites to obtain personal information.
A phishing message may be sent to thousands of people with the same general warning or offer. A pretexting attack is often more carefully designed around a particular person, department, or organization. The attacker may spend time learning internal names, projects, suppliers, and business procedures. This preparation can make pretexting harder to identify than a poorly written mass email.
The two techniques are frequently combined during a real attack. A criminal may first call an employee while pretending to be technical support. The caller then sends a phishing link and explains that it contains the required security update. The false technical support story is the pretext, while the deceptive link is the phishing element.
Pretexting can also be delivered through voice calls, text messages, social media, video meetings, or physical interaction. Voice-based social engineering is often called vishing, while text-message phishing is commonly called smishing. These terms describe the communication method, while pretexting describes the false story used within that method. The FBI advises people to verify unexpected calls and messages through independently located contact information rather than information provided by the sender.
Why Pretexting Attacks Are Effective
Pretexting works because people regularly depend on trust to complete everyday tasks. Employees respond to managers, customers cooperate with banks, and users follow instructions from technical support teams. Attackers copy these normal relationships so their unusual request appears connected to a familiar process. The target may therefore focus on solving the invented problem instead of questioning the person’s identity.
Authority can make a request feel difficult or inappropriate to challenge. An employee may worry that delaying an executive payment will cause trouble for the business. A customer may believe that refusing a bank security request will leave an account exposed. Attackers use this pressure to move the target away from normal verification procedures.
Urgency also reduces careful thinking by suggesting that immediate action is required. The attacker may claim that funds are disappearing, an account will be suspended, or an important deadline is approaching. The target may act quickly to avoid a negative outcome without checking whether the story is real. The FTC recommends ignoring unexpected requests for money and independently contacting the organization through a known website, application, or telephone number.
Pretexting becomes more convincing when the attacker includes accurate personal or business information. A message containing the correct supervisor name, project title, or recent transaction may appear legitimate. However, criminals can collect these details from public profiles, stolen data, earlier conversations, and compromised accounts. Familiar information should therefore be treated as supporting detail rather than proof of identity.
Warning Signs of a Pretexting Attack
An unexpected request for passwords, verification codes, financial details, or confidential records is a major warning sign. Legitimate organizations rarely need someone to reveal a password during a telephone call or email conversation. A one-time code is often the final requirement needed to enter an account or approve a transaction. The FBI warns people never to provide two-factor codes through email, text message, or encrypted messaging applications.
Urgent language is another common sign because it discourages independent verification. The sender may claim that the request must be completed secretly or before a short deadline. An employee may also be told not to contact a supervisor because the matter is confidential. Real emergencies can occur, but they should not automatically cancel basic security checks.
Unusual communication channels should also cause concern. A manager who normally uses company email may suddenly request payment through a personal messaging account. A bank representative may ask the customer to continue the conversation on an encrypted application. The FBI has documented impersonation campaigns in which attackers quickly moved targets to secondary messaging platforms after establishing contact.
Small inconsistencies can reveal that the person does not fully understand the organization or relationship being copied. The message may use an unusual greeting, incorrect job title, unexpected tone, or unfamiliar payment method. Telephone numbers and email addresses may look similar to genuine contact details without being identical. People should judge the complete situation rather than allowing one correct personal detail to remove every concern.
How Individuals Can Protect Themselves
The safest response to an unusual request is to pause before providing information or taking action. Do not allow urgency, fear, authority, or sympathy to remove your normal caution. End the conversation politely when necessary and contact the person or organization through a method you already trust. CISA recommends avoiding links and telephone numbers contained in suspicious messages and verifying the request separately.
Never share passwords, account recovery codes, or one-time verification codes with an unexpected caller or sender. These details may allow the attacker to enter your account, change the password, and remove your access. Multi-factor authentication can provide useful protection, but it cannot help when the user willingly approves the criminal’s request. Treat every unexpected authentication prompt as a possible warning that someone already knows your password.
Limit the amount of personal and professional information visible on public social media accounts. Attackers may use names, photographs, job details, travel plans, and family relationships to create a convincing pretext. Review privacy settings and avoid publishing information that could help someone answer security questions or imitate a trusted person. The FBI recommends being careful about information shared online because it may support spoofing, phishing, and impersonation attacks.
Use long and unique passwords, a trusted password manager, and strong authentication for important accounts. Protect email carefully because it may control password recovery for other services. Review login activity and remove unknown devices or connected applications. The FTC recommends protecting personal information through secure accounts, updated devices, and careful handling of unexpected requests.
How Businesses Can Prevent Pretexting
Businesses should establish clear verification procedures for payments, password resets, payroll changes, and sensitive information requests. Employees should know which requests require a second approval or confirmation through another communication channel. A senior title should not allow anyone to bypass basic security controls. Consistent procedures protect employees by removing the pressure to make difficult security decisions alone.
Payment and banking changes should be confirmed through trusted contact information already stored by the organization. Employees should not use a telephone number, email address, or website included in the new request. High-value transactions may require approval from two authorized people before funds are released. The FBI recommends independently verifying changes in payment information before completing financial transactions.
Security awareness training should use realistic examples based on the organization’s actual risks. Employees need practice identifying authority pressure, false urgency, impersonation, and requests for secrecy. Training should also explain how to report concerns without embarrassment or fear of punishment. A supportive reporting culture can stop an attack before money or information leaves the organization.
Businesses should limit access according to job responsibilities and review permissions regularly. An employee should not be able to view or send every sensitive record simply because an attacker asks confidently. Strong identity proofing, multi-factor authentication, logging, and approval controls reduce the damage one manipulated person can cause. NIST’s digital identity guidance emphasizes controls designed to reduce impersonation, false representation, authentication failure, and social engineering risks.
The Role of Artificial Intelligence in Pretexting
Artificial intelligence can help attackers create more polished messages with fewer spelling and grammar mistakes. It can also help them translate messages, imitate writing styles, and prepare personalized scripts quickly. These abilities may make older warning signs less reliable than they were in the past. A professional-looking message should not be treated as proof that the sender is genuine.
Voice-cloning technology can imitate the voice of a manager, customer, friend, or family member. A criminal may use a short public audio recording to create a believable emergency call. The familiar voice can increase emotional pressure and make the target respond before verifying the story. The FTC has warned that scammers can use short online audio clips to support AI-assisted family emergency scams.
AI-generated video and audio can also appear during online meetings or recorded messages. The target may believe that seeing or hearing a familiar person confirms the request. The FBI has warned that criminals increasingly use AI-powered voice and video cloning to impersonate trusted people and obtain sensitive information or fraudulent payments.
Organizations should respond by strengthening procedures rather than trying to detect every fake voice or image visually. A known callback number, second-person approval, shared verification phrase, or separate secure channel can confirm an unusual request. Verification should focus on evidence that the attacker cannot easily copy from public material. The FBI advises listening carefully for unusual tone and wording while also confirming suspicious communications independently.
What to Do After a Pretexting Incident
Act quickly when you realize that information, money, or account access may have been provided to an attacker. Contact the affected bank, employer, service provider, or security team through an official channel. Explain exactly what was shared and when the conversation occurred. Quick reporting may allow the organization to stop a payment, disable access, or preserve important evidence.
Change exposed passwords from a trusted device and replace any password reused on another account. Sign out active sessions and review recovery details, connected applications, forwarding rules, and trusted devices. Enable strong multi-factor authentication when it was not already active. Contact the service provider immediately when the attacker has changed the password or locked you out.
Keep copies of messages, email headers, telephone numbers, transaction details, screenshots, and other available evidence. Do not continue communicating with the attacker simply to gather more information unless law enforcement directs you. Write down the sequence of events while the details remain clear. The FBI’s Internet Crime Complaint Center accepts reports and advises victims to retain relevant evidence connected with cybercrime complaints.
Warn affected colleagues, customers, friends, or family members when the attacker may contact them next. A compromised account can be used to create new pretexts that appear to come from you. Organizations should review logs, reset exposed credentials, and examine whether sensitive records were accessed. Individuals in the United States can also use the FTC’s identity theft guidance when personal information has been misused.
Common Pretexting Prevention Mistakes
One mistake is assuming that only careless or inexperienced people fall for social engineering. Skilled attackers design their stories around normal responsibilities, emotions, and workplace habits. A busy employee may follow a believable request because it resembles many legitimate tasks. Security programs should improve systems and verification procedures instead of blaming victims.
Another mistake is trusting caller identification, email display names, profile photographs, or familiar voices. These details can be copied, changed, spoofed, stolen, or generated with artificial intelligence. Contact information shown on a screen does not prove who controls the communication. Independent verification is necessary whenever a request involves money, access, or sensitive information.
Some organizations train employees to recognize poor spelling but ignore more convincing social engineering methods. Modern attackers may use correct language, accurate branding, real employee names, and knowledge of business processes. Training must focus on the requested action and verification process rather than appearance alone. The NIST Phish Scale research also recognizes that message context can affect how difficult a deceptive message is for users to identify.
A final mistake is creating complicated reporting procedures that discourage employees from asking for help. People may stay silent when they fear punishment for clicking a link or sharing information. Delayed reporting gives the attacker more time to use stolen access and approach additional targets. Businesses should provide a fast, simple, and supportive method for reporting suspected social engineering.
Conclusion
Pretexting is a social engineering technique that uses a false identity and believable story to gain trust. The attacker creates a reason for requesting information, money, account access, or an unusual action. This method targets human judgment and can succeed without exploiting a technical software weakness. It may appear through calls, emails, text messages, social media, video meetings, or direct conversation.
Pretexting is different from phishing because it focuses on the invented situation and relationship. Phishing focuses more directly on deceptive digital messages, links, attachments, or fake websites. Both techniques can be combined when an attacker uses a convincing story to make a malicious message appear legitimate. Understanding this difference helps people recognize the complete attack rather than only checking for suspicious links.
The best protection is to slow down and verify important requests through a separate trusted channel. Passwords, verification codes, payment changes, and confidential records should never be released only because someone sounds convincing. Businesses should support employees with clear approval rules, limited access, strong authentication, and simple reporting procedures. CISA, NIST, the FBI, and the FTC consistently recommend independent verification and careful handling of unexpected requests.
Artificial intelligence may make pretexting messages, voices, and videos more realistic. This change makes trusted procedures more dependable than judging a request only by appearance or sound. Individuals and businesses should assume that familiar details can be copied and confirm sensitive requests independently. A short verification step can prevent account takeover, identity theft, confidential data loss, and serious financial damage.
Frequently Asked Questions
What is pretexting in simple words?
Pretexting is when a scammer invents a believable identity and situation to gain someone’s trust. The scammer then requests information, money, account access, or another harmful action.
Is pretexting the same as phishing?
No, pretexting focuses on the false story and identity used to build trust. Phishing usually focuses on deceptive messages, links, attachments, or fake websites.
What is an example of a pretexting attack?
A criminal may pretend to be a bank employee investigating suspicious activity. The criminal then asks the customer to reveal a password or one-time verification code.
How can businesses prevent pretexting?
Businesses should use callback verification, two-person approvals, limited access, security training, and clear reporting procedures. Employees should never bypass controls because a request appears urgent or comes from a senior person.
Can artificial intelligence be used for pretexting?
Yes, criminals can use AI to create convincing messages, cloned voices, and fake videos. Sensitive requests should always be verified through a separate trusted communication method.


