Pretexting
A social engineering technique where an attacker fabricates a believable scenario or identity to manipulate a victim into revealing information or granting access.
Pretexting is a form of social engineering where the attacker creates a fabricated scenario (the “pretext”) to engage the victim and extract information or access. Unlike phishing (which casts a wide net), pretexting is typically targeted and involves building a relationship or impersonating a trusted figure.
Examples include an attacker posing as IT support requesting login credentials, a vendor asking for system access, or a “new employee” requesting help accessing shared accounts. The pretext provides a plausible reason for the request, lowering the victim’s defenses.
Defenses include security awareness training, verification procedures for sensitive requests (calling back on a known number), and using a password manager that eliminates the need to verbally share credentials: if credentials are shared through the vault, pretexting attacks targeting passwords become ineffective.
Stop sharing passwords in spreadsheets
TeamPassword stores, shares and rotates your team credentials, encrypted end to end.
Trusted by 900+ agencies and small teams worldwide