Social engineering

The weak point is not the computer: it is people, and attackers know it.

Request a consultation

What it is

Social engineering is the psychological manipulation of people to obtain access, data or money. It does not exploit technical flaws but trust, urgency, authority and curiosity. It is the basis of phishing, vishing, CEO fraud and many other attacks, and AI makes it more believable and cheaper.

How it works

  1. 1The attacker gathers public information about the person and the organisation.
  2. 2They build a believable pretext: the IT colleague, the supplier, the courier, the boss.
  3. 3They make contact by email, phone, chat or in person and create emotional pressure.
  4. 4They get the action they wanted: a credential, physical access, a transfer.

How to spot it

  • Urgency, authority or secrecy used to make you skip procedures
  • Unusual requests from people you know, or too much familiarity from strangers
  • Offers or prizes too good to be true
  • Information about you that a stranger should not have

How to defend

  • Verification procedures nobody can skip, not even at the boss’s request
  • Slow down: a pause before acting defuses almost any pressure
  • Verify on a second channel with a contact you already know
  • Build a culture where “let me verify first” is normal
  • Regular training with real examples and simulations, and less personal information made public

If you think you have been hit

  • Report at once, even if it is embarrassing: every minute counts
  • Change the credentials you shared and tell IT or your bank
  • Write down what happened: it helps block the attacker and protect others

And there are many, many more

The attacks above are only some of the most common: there are hundreds, and new ones appear every week. If the one that concerns you is not among them, write to me: I will tell you whether it really affects you and how to defend.

Contact me

Other attacks

Watch the Shorts on YouTube

Matteo Russo · Updated October 2026

Let's talk
no strings attached

Want to know how exposed you are, train your team, or just ask a question? Write to me: I reply personally.

  1. You writeA couple of lines about your case: person, company, doubt or request.
  2. We talkA short intro call to understand what you really need.
  3. Practical defenseAssessment, consulting or training, with clear, prioritized actions.

Request a consultation

For security, the email address is not written on the page: press the button to reveal it and copy it in one click.

For companies and individuals. No scaremongering, just practical defense.