Skip to content

Pretexting (fabricated scenario)

In plain terms

The attacker first builds a credible role — new vendor, intern, technician, colleague from another department — and asks for nothing until that role is accepted. The request, when it comes, then seems normal.

Definition

Pretexting is the construction of a plausible identity and situation, sustained across several exchanges, in order to obtain information or access without ever making a request that seems abnormal.

How it works

Unlike techniques that rely on a shock — a threat, an urgency, good news — pretexting bets on ordinariness. The attacker first gathers public elements: an org chart, vendor names, internal vocabulary, a project's timeline. They use these to occupy a role no one thinks to question, then proceed with small, harmless requests: confirming a name, getting an extension number, asking for a procedure to be clarified. Each answer enriches the next scenario and makes it more credible, until the decisive request fits into a relationship that's already established. This is the foundation of several frauds on this site: the fake wire-transfer order and the fake bank advisor almost always start with a successful pretexting phase.

Warning signs

  • A new contact whose role no one internally can confirm
  • Harmless but repeated requests, about the organization rather than a specific subject
  • Familiarity with internal vocabulary, gained without your knowing how
  • Refusal to go through the usual channel, justified by a practical reason
  • Targeting a recently arrived employee or a peripheral department
  • Request to skip a step "just this once," so as not to delay a project

How to verify

Verify the role, not the story: a well-built scenario withstands questions, but an identity doesn't withstand a callback to a known internal number. Ask who the caller reports to within the organization, then confirm with that person through a channel you choose.

What to do

Treat any information about the organization — names, roles, procedures, vendors, schedules — as data, not as a courtesy. Following the usual procedure is a sufficient answer and never needs to be justified.

If it already happened

Note precisely what was shared and with whom, then alert the person responsible: the value of pretexting is to prepare another attack, so the alert is useful even if nothing appears to have been lost. Have the access and procedures mentioned during the exchanges checked.

Test yourself

A third, friendly exchange with an auditor. This time they ask for the staff directory.

Start the simulation

Frequently asked questions

Nothing was stolen — is it really worth reporting?
Yes. Pretexting is rarely an end in itself: the information gathered is used to make a later request credible, often addressed to someone else. An early report makes it possible to recognize that request when it arrives.
How do I refuse without seeming rude?
By making the verification impersonal: "I'll call you back on the internal line" or "I'll forward the request to the relevant department" doesn't accuse anyone. A legitimate contact accepts this answer; insistence following a polite refusal is itself a signal.

Official sources

This article is part of the Social engineering family. Last updated: 2026-09-02.