What Is Pretexting in Cyber Security? Social Engineering Tactics Explained
Pretexting is a social engineering tactic where an attacker fabricates a believable scenario or false identity, an executive, a vendor, a bank employee, to build trust with a target before extracting money, information, or access, relying on constructed credibility rather than a single deceptive message.
If deepfakes have you worried that voice and video verification are now useless, the Arup and WPP cases below show exactly why vigilance still works, and exactly where it fails.
What Is Pretexting?
Pretexting in cyber security means fabricating a believable scenario or identity to manipulate someone into an action they wouldn’t otherwise take. The attacker isn’t just sending a deceptive link. They’re constructing an entire, plausible story: a persona, a reason, an urgency, all built to survive a moment of scrutiny.
That’s what separates pretexting from a simple scam attempt. It’s not a single lie. It’s a constructed narrative designed to hold up under a target’s natural skepticism.
Pretexting vs Phishing — the Channel vs. the Technique
Here’s a distinction most content blurs entirely, treating these two terms as interchangeable. They’re not the same thing, and understanding why clarifies a lot of confusion.
Phishing specifically refers to the channel: email used to deliver a scam. Pretexting is the underlying technique, the fabricated scenario itself, and it can travel through any channel at all: email, phone call, video conference, or even in person.
A phishing email absolutely can use pretexting, a fake invoice claiming to be from a known vendor is both phishing and pretexting at once. But pretexting doesn’t require email in any form. A phone call impersonating your bank’s fraud department is pure pretexting with zero email involved. Understanding this relationship, technique versus delivery channel, is what makes the rest of this topic click into place.
What Is Vishing, and How Is It Just Pretexting Delivered by Voice?
Vishing is voice-based phishing, a phone call built around a fabricated scenario designed to extract information or money directly. It’s pretexting delivered by voice, the exact same underlying technique, just riding a different channel than email.
Caller ID spoofing frequently accompanies vishing attempts, displaying a trusted, familiar number on the target’s phone before they even answer. That single, small detail does enormous work convincing a target the call is legitimate before a single word of the fabricated scenario has even been spoken.
How Does a Pretexting Attack Unfold?
- Research, using OSINT, open-source intelligence gathered from LinkedIn, company websites, press releases, and social media, to build a genuinely convincing, personalized identity and scenario.
- Establishing contact, reaching the target through whatever channel fits the constructed scenario best, email, phone, or video.
- Building trust, layering fabricated urgency, apparent authority, or manufactured familiarity to overcome the target’s natural skepticism.
- Extracting the target action, the money transfer, the credential, the access grant, before the victim has time or reason to independently verify what’s actually happening.
Real Examples: the HP Scandal, MacEwan University, and What Deepfakes Have Changed
HP’s 2006 boardroom scandal remains a foundational, well-documented pretexting case. Investigators hired by the company used pretexting to illegally obtain phone records belonging to journalists and HP’s own board members, impersonating those individuals directly with phone carriers to extract the records, a scandal that ultimately led to congressional hearings and real legal consequences.
MacEwan University lost millions of Canadian dollars in 2017 to an email-based pretexting attack impersonating one of the university’s actual vendors, convincing staff to redirect legitimate payments to a fraudulent bank account through carefully fabricated, seemingly routine correspondence.
Deepfake technology has since added something genuinely new to this same fundamental technique: real-time, interactive audio and video that responds convincingly to questions asked live, rather than a static, pre-recorded lie a target simply has to accept or reject.
Arup, WPP and LastPass — Two Failures and One Success, Side by Side
Here’s a comparison most content never makes, despite these cases being genuinely, remarkably similar in structure.
In January 2024, a finance employee at engineering firm Arup’s Hong Kong office received an email claiming to be from the company’s UK-based CFO, requesting a confidential transaction. The employee was initially skeptical of the email alone. That skepticism dissolved once he joined a video call where the CFO and several familiar colleagues appeared and spoke naturally, answering questions in real time. Every single person on that call, other than the employee himself, was an AI-generated deepfake, built from publicly available footage scraped from prior online meetings and company video content. Following instructions given during that call, the employee authorized 15 separate transfers totaling $25.6 million to five different Hong Kong bank accounts.
Months later, WPP’s CEO Mark Read was impersonated in an almost identical setup: scammers built a fake WhatsApp account using a publicly available photo, arranged a Microsoft Teams meeting, and deployed an AI voice clone alongside real YouTube footage to convincingly impersonate Read and a second senior executive. The target this time, an agency leader, was asked to set up a new business arrangement designed to solicit money and personal details. This attempt failed. The targeted employee stayed skeptical enough to question the request properly, and WPP confirmed the fraud was prevented specifically because of that vigilance.
Here’s the genuinely important insight this direct comparison reveals. The technical sophistication in both cases was nearly identical, real-time deepfake audio and video, built from scraped public footage, targeting a specific, researched individual. What differed wasn’t the technology. It was whether the targeted employee’s skepticism survived contact with a convincing, synthetic authority figure, or collapsed under it. That’s the practical, actionable lesson worth taking from placing these two cases side by side: technical defenses alone didn’t decide the outcome. A verification habit, one that doesn’t defer to a face or voice just because it looks and sounds right, was the actual deciding factor both times.
LastPass’s 2022 breach adds a different but related lesson. A DevOps engineer’s home computer was compromised through vulnerable third-party software, ultimately giving attackers access to encrypted customer vault backups. While not a pure pretexting case, it reinforces the same underlying theme: attackers consistently target the human and endpoint layer surrounding a system, rather than attacking hardened core infrastructure directly.
The Warning Signs, and Why “Verify Through Official Channels” Isn’t Specific Enough
Here’s honest, direct criticism worth stating plainly. “Verify through official channels” is the single most repeated piece of pretexting advice, and it’s genuinely useless as written, because it doesn’t specify which channel, contacted how, or by whom.
Genuine verification means something specific: calling a number saved in your own contacts or company directory beforehand, never a number provided within the suspicious message or call itself, since a fabricated scenario frequently includes its own fake “verification” contact designed to confirm the lie rather than expose it. It means confirming through an actual person on that call, not simply replying within the same email thread or chat window the original request arrived through, since an attacker controlling that channel controls every reply within it too.
Watch for a few concrete red flags specifically: any request framed as secret or confidential that nobody else should know about, unusual urgency pressuring immediate action before normal checks can happen, and a request arriving through a channel slightly different from how that person normally communicates with you.
A Practical Verification Protocol for Finance and Wire-Transfer Requests
- Call the requester back on a number saved before the request arrived, never a number supplied within the suspicious message, call, or video invite itself.
- Confirm through a second employee independent of the original communication thread, someone who wasn’t copied on or present for the initial request.
- Apply mandatory dual authorization for any transfer above a clearly defined threshold, regardless of how senior the requester appears or how urgent the framing.
- Treat any request labeled confidential, secret, or “don’t tell anyone yet” as an automatic trigger for the full protocol, not an exception to it.
- Document and rehearse this protocol specifically with finance and executive-adjacent staff, the roles most consistently targeted by exactly this pattern.
Cyber Security Solutions Ltd routinely helps businesses build this level of specificity directly into their own procedures, since a policy simply stating “verify requests” leaves every employee to improvise their own definition of verification in the exact moment they’re least equipped to think it through carefully.
Conclusion
Pretexting succeeds by building a story convincing enough to survive scrutiny, and deepfakes have only made that story sound and look more real, not made it unbeatable. Arup and WPP faced nearly identical attacks; only one had a verification habit specific enough to hold. Build that specificity into your own finance procedures before you need it. If you want help creating a verification protocol your team can actually follow under pressure, Cyber Security Solutions Ltd can walk through it with you.
FAQs
Pretexting is a social engineering tactic where an attacker fabricates a believable scenario or false identity to build trust with a target before extracting money, information, or access, relying on a constructed, plausible narrative rather than a single deceptive message.
Vishing is voice-based phishing, a phone call built around a fabricated scenario designed to extract information or money. It’s pretexting delivered by voice, often combined with caller ID spoofing to display a trusted, familiar number.
Phishing specifically refers to the email channel used to deliver a scam. Pretexting is the underlying technique, a fabricated scenario, that can travel through any channel: email, phone, video call, or in person, not just email.
A pretexting attack starts with research using publicly available information, then establishes contact, builds trust through fabricated urgency or authority, and extracts the target action before the victim has time to independently verify what’s actually happening.
A Hong Kong finance employee received an email impersonating Arup’s CFO, then joined a video call where AI-generated deepfakes of the CFO and colleagues, built from public footage, convinced him to authorize 15 transfers totaling $25.6 million.
Call the requester back on a number saved before the request arrived, never one supplied in the message itself, confirm through a second employee independent of the original thread, and apply mandatory dual authorization above a defined transfer threshold.
