Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Pretexting is a social-engineering attack in which someone invents a believable situation and pretends to be a trusted person or role to make you reveal information or take an action. The request may come from a supposed manager, bank representative, help-desk agent, employer, government official, vendor, or customer-support worker. The objective can be a password, one-time code, identity document, payment, account reset, customer record, or physical access.

How pretexting works

MITRE CAPEC-407 describes pretexting as creating an invented scenario and assuming an identity or role to persuade a target to release information or perform an action. The Federal Deposit Insurance Corporation (FDIC) similarly describes it as staging a scenario that baits a victim into providing information they would not otherwise disclose.

  1. Reconnaissance: The attacker gathers details about a person, job, organization, vendor, or current event. Public profiles, company directories, leaked data, and previous conversations can provide enough context to sound credible.
  2. Pretext creation: The attacker selects a role and reason for contact—for example, “I’m from IT and need to verify your account” or “I’m calling from your bank about a suspicious transaction.”
  3. Trust and pressure: The conversation relies on authority, familiarity, helpfulness, urgency, fear, or secrecy. A request may be framed as an emergency or as protection from a problem.
  4. Requested action: The target is asked to disclose a password, multifactor-authentication code, identity evidence, customer data, payment details, or to approve a reset, transfer, login, or facility entry.
  5. Follow-on abuse: The attacker uses the result for account takeover, fraud, data theft, extortion, unauthorized access, or another round of impersonation.

Examples of pretexting attacks

Scenario Impersonated role Typical request Pressure tactic Control that can stop it
Help-desk call Employee or contractor Change a username, password, recovery address, or other login setting Urgency and a claim that work is blocked Use the organization’s documented identity-proofing and callback process
Executive or manager request Senior executive or supervisor Make an exceptional payment, share records, or bypass a normal approval Authority, confidentiality, and time pressure Confirm through a separately known channel and require normal approvals
Fake employer verification Potential employer or recruiter Identity documents or other evidence of identity Opportunity and fear of losing the job Verify the employer independently and submit documents only through a validated process
Government or service-provider impersonation Government office, bank, utility, or familiar business Payment, account details, login information, or a code A problem, penalty, prize, or urgent deadline End the contact and call the organization using a number you already trust
Phishing combined with a pretext Supervisor, colleague, or known organization Click a link, sign in, reply with information, or approve a request Urgency or fear delivered by email, text, social media, or phone Open the official site or app yourself and verify the request out of band

Pretexting versus phishing

Phishing is a digital social-engineering technique that uses a bogus email, message, website, or other electronic contact to solicit information or send a victim to a fake site. Pretexting is defined by the fabricated identity and story. It can occur by phone, email, text, social media, or in person, and phishing can be one channel used to deliver a pretext.

For example, an email that simply asks you to click a counterfeit login link is phishing. An email that claims to be from your supervisor, explains that a confidential payroll issue must be fixed immediately, and sends you to that link uses a pretext delivered through phishing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Warning signs to recognize

  • An unexpected request for a password, one-time code, identity document, customer record, payment, or access change.
  • A caller or message that uses authority, familiarity, fear, a prize, or an urgent deadline to prevent careful checking.
  • Instructions to keep the request secret or to bypass a help-desk, payment, approval, or identity-verification procedure.
  • Caller-ID or sender details that look correct but cannot be independently confirmed.
  • A request to use a new phone number, link, email address, or remote-access method supplied by the contact.

How to stop a pretexting attack

For individuals

  1. Pause. Do not let an emergency story choose your next action.
  2. Refuse sensitive disclosure in the incoming conversation. Never provide passwords or one-time codes merely because a caller appears authoritative.
  3. Verify independently. End the call or message and contact the person or organization through a phone number, directory entry, official website, or in-person route you already trust. Do not use contact details supplied in the suspicious request.
  4. Use the official service yourself. Open the organization’s known app or website rather than following an unexpected link.
  5. Report it. Tell the organization being impersonated. Consumers can report suspected fraud to the Federal Trade Commission at ReportFraud.ftc.gov.

For organizations

  • Require documented identity proofing before help-desk resets, account changes, payments, data releases, or facility access.
  • Use out-of-band confirmation, such as notifying a validated address or calling a separately verified number, for high-risk changes.
  • Train staff to stop and verify requests involving urgency, secrecy, exceptional approvals, or procedure bypasses.
  • Give employees a simple escalation path so verifying a senior person’s request is expected rather than embarrassing.
  • Run recurring, realistic awareness exercises. Training should cover phone, email, text, social media, and in-person approaches—not only suspicious links.
  • Limit the information exposed in directories and public profiles, and review recovery and administrator processes for social-engineering weaknesses.

What to do if you already responded

  1. Stop communicating with the suspected attacker and preserve messages, phone numbers, email headers, payment instructions, and timestamps.
  2. From a trusted device, change affected passwords and any reused passwords; revoke active sessions where the service supports it.
  3. Contact the real bank, employer, service provider, or IT team using an independently verified channel. Ask whether account resets, payment holds, or additional monitoring are needed.
  4. Notify your security or fraud team immediately if a work account, customer record, identity document, payment, or multifactor code was involved.
  5. Report the impersonation to the organization and the appropriate authorities, including the FTC reporting channel for consumer fraud.

Key points to remember

  • Pretexting combines a made-up scenario with an assumed identity or role.
  • The requested outcome may be information, money, a credential reset, identity evidence, or access to a system or facility.
  • Authority, urgency, fear, familiarity, and helpfulness are common manipulation cues.
  • Phishing is a possible delivery channel; pretexting is not limited to digital messages.
  • Independent verification and refusing to bypass established procedures are the most practical first defenses.
  • Training and layered identity-proofing controls reduce risk, but no technology removes the need for human judgment.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.