The Friendly Stranger: Recognizing Social Engineering Before It's Too Late
Social engineering attacks manipulate people — not technology — to gain unauthorized access to sensitive information or systems. This scenario follows Layla, a new office administrator, as she encounters a classic social engineering attempt and learns how to protect herself and her organization.
Social engineering attacks manipulate people — not technology — to gain unauthorized access to sensitive information or systems. This scenario follows Layla, a new office administrator, as she encounters a classic social engineering attempt and learns how to protect herself and her organization.
A Normal Tuesday Morning
Layla Al-Rashidi had been working as an office administrator at Gulf Horizon Trading Co. for only three weeks. She was still learning the ropes — the systems, the people, the processes. She was eager to help and always answered the phone with a bright "Good morning, Gulf Horizon, how can I assist you?"
On a Tuesday morning, her phone rang. The caller ID showed an internal extension — extension 4471. She picked up.
Caller: "Good morning! Is this Layla? Fantastic. This is Khalid from IT Support — we've had a security alert flagged on your account overnight. Nothing to panic about, but I need to verify your credentials quickly before our morning window closes."
Layla: "Oh! Yes, of course. What do you need?"
Caller: "Just confirm your username and the password you used to log in this morning. It'll take thirty seconds and I can get this cleared for you right away."
Layla: "Sure, my username is layla.rashidi and my password is—"
Layla was about to hand over her login credentials to a complete stranger. Legitimate IT departments never ask for your password over the phone, email, or chat — under any circumstances. This is a textbook social engineering attack called pretexting.
What Is Social Engineering?
Social engineering is the art of manipulating people into giving up confidential information. Unlike hacking, which targets software vulnerabilities, social engineering targets human psychology — our trust, our desire to be helpful, and our fear of authority or consequences.
The "IT support caller" wasn't from Layla's company at all. He had spoofed an internal extension using a simple online tool. His goal? Steal Layla's credentials to access Gulf Horizon's financial records.
Notice how the caller created a sense of urgency: "before our morning window closes." Attackers deliberately create time pressure so you don't stop to think or verify. If someone is rushing you, that's a red flag — slow down.
The Attack Continues — Email Phishing
Luckily, Layla's colleague walked by and she quickly ended the call. But the attacker didn't stop. An hour later, she received this email:
Subject: URGENT: Your Account Will Be Suspended in 2 Hours
Dear Layla,
Our security system has detected unusual login activity on your account. To avoid suspension, please verify your account immediately by clicking the link below:
Gulf Horizon IT Security Team
Look closely at the sender's email:
gulf-horiz0n-trading.com — the letter "o" has been replaced with the number "0." This is called a lookalike domain. The email also uses urgency, fear of consequences, and a suspicious link — all classic phishing tactics.The Real-World Impact
Social engineering is not rare. According to the 2023 Verizon Data Breach Investigations Report, 74% of all data breaches involve a human element — including social engineering, errors, and misuse. Phishing alone accounts for over 36% of all breaches.
In the Gulf region, cybersecurity firm Group-IB reported a 135% increase in phishing attacks targeting businesses in the Middle East between 2021 and 2023. The average cost of a data breach in the Middle East reached $8.07 million in 2023 — the second highest globally (IBM Cost of a Data Breach Report).
Attackers specifically target new employees like Layla because they're still learning processes, eager to please, and less likely to question unusual requests. If you're new to a role, be extra cautious about unsolicited calls or emails requesting sensitive information.
Layla did the right thing — she hung up, reported the call to her manager, forwarded the suspicious email to the real IT department, and did not click any links. Her quick thinking helped prevent what could have been a devastating breach.
Lesson: How to Recognize and Resist Social Engineering
Social engineering works because it exploits human behavior, not technical weaknesses. The good news? You can train yourself to recognize the warning signs and respond safely every time.
Common Social Engineering Techniques
| Technique | How It Works | Example | Red Flag |
|---|---|---|---|
| Pretexting | Attacker invents a scenario to gain your trust | "I'm from IT, I need your password to fix a security alert" | Unsolicited contact claiming authority |
| Phishing | Fake emails trick you into clicking links or sharing data | Fake "account suspension" email with a malicious link | Misspelled domains, urgent language, suspicious links |
| Vishing | Voice phishing via phone calls | "Your bank account has been compromised, verify now" | Caller creates urgency, asks for credentials |
| Baiting | Lures victims with something enticing (e.g., a USB drive) | A USB labeled "Salary List 2024" left in a parking lot | Found devices or "too good to be true" offers |
| Tailgating | Following an authorized person into a restricted area | "Can you hold the door? I forgot my access card" | Strangers asking to enter secure areas |
Your 5-Step Defense Checklist
- Pause before you act. Urgency is a manipulation tactic. Take a breath and think before responding.
- Verify the identity independently. If someone claims to be from IT or management, hang up and call them back using a number from the official company directory — not one they provide.
- Never share passwords. No legitimate IT team, manager, or bank will ever ask for your password — ever.
- Check email addresses and links carefully. Hover over links before clicking. Look for misspellings or extra characters in domain names.
- Report suspicious contacts immediately. Tell your IT security team about phishing emails, suspicious calls, or unusual requests. You may protect your entire organization.
When in doubt, don't act. It is always better to slow down, verify, and ask your security team than to respond quickly to a request that turns out to be an attack. No legitimate request will be permanently ruined by a short delay for verification.
Quick Reference: What Real IT Teams Will and Won't Do
✅ Real IT will send official emails from verified company domains
✅ Real IT will schedule planned maintenance in advance
❌ Real IT will never ask for your password
❌ Real IT will never pressure you to act "within minutes"
❌ Real IT will never contact you from personal phone numbers or external email addresses
Unlock This Scenario & Quiz
The Free plan includes 3 scenarios. Upgrade for full access to every scenario and quiz.
⬆️ View Plans