Security

Pretexting

A social-engineering approach that uses an invented but believable story, such as a supplier, colleague or official, to obtain information or action. Verify the request through a separate, known contact route.

How it works

Pretexting invents a situation or role to obtain information or cooperation under false pretences. It is a form of social engineering. The attacker’s story explains why the request supposedly makes sense, using details that can sound plausible without proving entitlement to the information or action.

A practical example

Someone pretending to arrange a repair could request a resident’s schedule or account details. Another could claim an internal audit requires a password reset. These hypothetical examples use context to lower suspicion; a believable explanation is still different from verified identity and permission.

What to check

Ask what information is actually needed and verify the person through an existing trusted route before providing it. Do not use a new phone number or link supplied as part of the story as the only check. Follow established approval steps for confidential documents, access changes and payments. Limit disclosure to the authorized purpose.

Limits and safe use

A genuine request may also need clarification, so verification is more useful than judging whether someone sounds confident. Personal details can be obtained elsewhere and do not prove legitimacy. If information was already shared, record exactly what was disclosed and notify the responsible person. The appropriate response depends on the information and access involved, not just the label of the scam.

Technical sources

← All glossary terms