July 29, 2026
Social Engineering — The Hack That Doesn’t Need a Computer
In 2013 a journalist called Mat Honan watched helplessly as his entire digital life was destroyed in minutes. His iPhone wiped. His iPad…

By Vaishnavi Kolape
4 min read
In 2013 a journalist called Mat Honan watched helplessly as his entire digital life was destroyed in minutes. His iPhone wiped. His iPad wiped. His MacBook wiped. His Gmail account deleted. His Twitter hijacked.
No vulnerability was exploited. No sophisticated malware deployed. The attackers simply called Apple support, convinced them they were Mat using basic personal information found online and got a password reset. Then they called Amazon and did the same thing. Each company's information was used to trick the next.
The whole attack took about an hour. And it required absolutely zero technical skill.
That's social engineering. And in many ways it's more dangerous than any technical attack because no patch can fix human psychology.
A Conversation That Stuck With Me
A few weeks ago I attended a cybersecurity summit in Birmingham. It was the first industry event I'd been to since starting my MSc and honestly it was eye opening in ways I didn't expect.
I got talking to a few industry professionals — people working in security for large organisations, people who do this every day for a living. I asked them what the biggest misconception people have about cybersecurity is.
The answer was unanimous and it hit harder than any lecture had.
Nothing is 100% safe.
Not a single one of them believed any system, any organisation or any individual was completely immune. The goal of cybersecurity isn't to achieve perfect security — it's to make attacks harder, slower and more expensive than they're worth. And the weakest point in almost every system they'd encountered wasn't the technology.
It was the people.
That conversation gave me a completely different lens for everything I'd been studying. And social engineering is exactly where that lens matters most.
What Is Social Engineering?
Social engineering is the art of manipulating people into giving up information or access they shouldn't. Instead of hacking the system attackers hack the person operating it.
It works because humans are wired to be helpful, to trust authority figures and to act quickly under pressure. Attackers exploit all three.
The Main Types
Phishing — fraudulent emails designed to look legitimate. A fake bank email asking you to verify your account. A fake IT department email asking for your password. A fake invoice from a supplier you recognise.
Modern phishing emails are frighteningly convincing. AI has made them even better — no spelling mistakes, perfect branding, personalised details pulled from your LinkedIn or social media.
Spear phishing — targeted phishing aimed at a specific person. An attacker researches you, finds your name, your company, your manager's name, a project you're working on and crafts an email that references all of it. The success rate is dramatically higher than generic phishing.
Vishing — voice phishing. Phone calls from fake bank fraud departments, fake HMRC agents, fake Microsoft support. In 2020 Twitter was compromised when attackers called Twitter employees pretending to be IT staff and convinced them to hand over internal credentials. Seventeen year old hackers took over accounts belonging to Barack Obama, Elon Musk and Joe Biden.
Pretexting — creating a fabricated scenario to extract information. "Hi I'm from your IT department, we've noticed unusual activity on your account, I just need to verify a few details." The pretext — the fake story — is the attack.
Baiting — leaving infected USB drives in car parks or reception areas and waiting for curious employees to plug them in. It sounds absurd. It works remarkably often. The US Department of Homeland Security ran an experiment dropping USBs in government car parks. 60% were plugged in by employees.
The Psychology Behind Why It Works
This is something that came up both in my MSc modules and in conversations at the Birmingham summit. The professionals I spoke to weren't just talking about technical defences — they kept coming back to human behaviour as the real battlefield.
Authority — people comply with requests from authority figures. An email from the CEO, a call from HMRC, a message from IT support. We're conditioned to respond.
Urgency — "Your account will be suspended in 24 hours." Urgency bypasses rational thinking. When people feel pressure they act before they think.
Social proof — "Everyone else in your team has already updated their details." If others are doing it it must be legitimate.
Reciprocity — someone does something nice for you and you feel obligated to return the favour. Attackers build rapport before making their request.
One security professional at the summit put it brilliantly — the most sophisticated firewall in the world means nothing if an employee reads an urgent email from what looks like the CEO and wires money without picking up the phone to verify it first.
Understanding these principles is half the defence. When you feel urgency or authority pushing you toward an action — pause. That feeling is exactly what attackers are engineering.
Real Cases Worth Knowing
Twitter 2020 — teenagers used vishing to compromise Twitter's internal tools and hijack high profile accounts. The attack exposed how easily human operators can be manipulated regardless of how strong the technical security is.
Ubiquiti 2015 — an employee was tricked through phishing into transferring $46.7 million to fraudulent accounts. The email appeared to come from a senior executive. This attack type — Business Email Compromise — costs organisations billions globally every year.
RSA Security 2011 — even a cybersecurity company wasn't immune. An employee opened a phishing email with a malicious spreadsheet attachment. The resulting breach compromised RSA's SecurID authentication products used by governments and militaries worldwide.
That last one is worth sitting with. A cybersecurity company. Breached through a phishing email. Nobody is immune — which is exactly what the experts at Birmingham told me.
How To Defend Against It
Awareness training — the most important defence. People who understand social engineering techniques are significantly harder to manipulate. Regular training and simulated phishing tests keep awareness high.
Verification procedures — always verify requests through a separate channel. If someone calls claiming to be IT support hang up and call IT support back on a number you already have. If an email requests an urgent transfer call the sender directly to confirm.
Slow down — urgency is a red flag not a reason to act faster. A legitimate bank, IT department or colleague will understand a brief delay for verification.
Multi-factor authentication — even if credentials are stolen MFA means stolen passwords alone aren't enough to gain access.
Culture — one thing that came up repeatedly at the Birmingham summit was organisational culture. Organisations where employees feel safe questioning unusual requests have far fewer successful social engineering attacks. If the culture punishes people for slowing down to verify something that culture is itself a security vulnerability.
The Takeaway
Nothing is 100% safe. The experts in Birmingham said it and every real world case study backs it up. But understanding how social engineering works — the psychology, the techniques, the red flags — makes you dramatically harder to manipulate.
The goal isn't perfection. It's making yourself a harder target than the next person.
Follow along — next post is about Zero Trust, a security model built on the assumption that you simply cannot trust anyone on your network.