← All terms

Pretexting

Pretexting is a social engineering technique where the attacker creates a fabricated scenario to gain the victim's trust and extract information or access.

Pretexting is the art of constructing a false but believable scenario — a pretext — to manipulate a target into sharing information, granting access, or performing an action they would not normally do. While phishing is often a single interaction, pretexting can involve extended conversations and relationship-building over days or weeks.

How it works

A pretext is built from three elements:

  • A plausible identity. The attacker poses as someone the target would expect to interact with: an IT support technician, a vendor, a new colleague, a building inspector, or a recruiter.
  • A believable scenario. The story explains why the attacker needs what they are asking for. "I'm from IT and need to verify your credentials after a system migration" combines authority and urgency in a routine-sounding context.
  • Social proof and research. The attacker uses real names, department structures, project references, and internal jargon gathered from OSINT. The more accurate the context, the harder the pretext is to question.

Pretexting underlies many other attack types: a vishing call requires a verbal pretext, a BEC email uses a written one, and physical intrusions rely on in-person pretexts to bypass reception or tailgate through secure doors.

How to defend against it

  • Train employees to verify identity independently — call back on a known number, confirm with the supposed sender through a separate channel, check with a manager before acting on unusual requests.
  • Simulate multi-step pretexting scenarios that go beyond single-email phishing to test whether employees recognize sustained social engineering. NOUSEC supports multi-channel simulations combining email, voice, and SMS.
  • Reduce publicly available information where practical — review what employee details are exposed on the corporate website, LinkedIn, and social media.
  • Build a reporting culture where employees feel comfortable questioning unexpected requests without fear of being wrong or rude. Read more about building security culture in our phishing simulation best practices guide.

Related terms

Social EngineeringSocial engineering is the practice of manipulating people into giving up confidential information, access, or taking actions that compromise security.PhishingPhishing is a social engineering attack that uses fraudulent emails, websites, or messages to trick people into revealing sensitive information or installing malware.VishingVishing (voice phishing) is a social engineering attack conducted over phone calls to manipulate victims into revealing sensitive information or taking harmful actions.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo