How it works
Social engineering manipulates a person into disclosing information or performing an action that benefits an attacker. It can happen through email, telephone, messaging or in person. The central mechanism is influence over a decision, sometimes combined with technical deception, rather than necessarily breaking encryption or software.
A practical example
A supposed technician might ask an employee to approve remote access because a repair is urgent. A different approach could imitate a manager requesting a confidential document. These examples exploit authority and urgency; even a request involving a real project still needs an appropriate authorization check.
What to check
Separate the requested action from the story surrounding it. Verify unexpected requests through an existing trusted contact, not the contact details supplied in the message. For payments, sensitive files or account recovery, follow the established approval process. Give people a clear way to pause and ask without being rushed.
Limits and safe use
Good grammar, personal details or a familiar logo do not prove identity. Security software can block some delivery routes, but cannot decide every human authorization question. If an action was already taken, record exactly what was disclosed or permitted and inform the responsible person. Revoking access and recovering funds require different responses.