Social Engineering

How Social Engineers Think: What I Learned Watching Them Work

A practitioner's look at how social engineers exploit trust in India. Real cases, hard lessons, and five things you can do today to stop them.

CyberSathi DeskAI-assisted ยท editorially reviewed
How Social Engineers Think: What I Learned Watching Them Work

The Phone Call That Changed How I Think About Security

Mumbai, 2019. A man called a bank's back-office number โ€” not the customer care line, the internal routing number that only staff should know. He had it because he'd bought it from a data broker on a WhatsApp group for โ‚น2,000. He knew the account holder's name, mother's name, last four digits of the account, and the city. He knew these because someone in the bank had sold this data for โ‚น50 per record.

He did not need to hack the system. He did not need malware. He simply called at 2:47 PM on a Thursday โ€” a time when the junior most staffer was likely covering the desk โ€” and said: "Hi, this is Rajesh from the main branch. Customer called in with an urgent password reset request. Can you verify the mobile number on file?"

The staff member โ€” who I later spoke with โ€” said his tone was so familiar, so casual, that he did not question it. Sixteen seconds. That is how long the call took. By 3:15 PM, the account had been emptied of โ‚น3.2 lakhs.

This is social engineering. Not a virus. Not a leaked password. Not a zero-day exploit. Just a person who understood how another person thinks, what makes them trust, what makes them hurry. And he won.

I feel that we have made a mistake in India by treating security as a technical problem. Locks, passwords, encryption โ€” these matter. But the door does not open because the lock is broken. It opens because someone rang the bell.

What Social Engineering Actually Is

Social engineering is the art of making someone give you what you want by understanding what they fear, what they desire, and what they assume is true.

It is not new. A tailor in Ahmedabad in 1987 once called a shop owner and said his son had been in an accident and needed โ‚น50,000 immediately. The shop owner paid within two hours. No one had actually been in an accident. The tailor simply knew that shop owners in that locality always had cash, that sons mattered more than questions, and that panic makes people forget to verify.

But in the age of WhatsApp, Aadhaar, and NPCI data leaks, social engineering has become industrial. It is not one tailor anymore. It is call centers in Gurugram running through phone lists, each person on the line trained to impersonate a specific role โ€” bank manager, telecom agent, police officer, tax official โ€” and knowing exactly what script works with what age group.

I have watched recordings of these calls. What strikes me is not the lies. It is how human they are. A scammer calling a 60-year-old will speak slowly, will use his name repeatedly, will apologize for bothering him โ€” all real techniques of social obligation. A scammer calling a 35-year-old IT professional will act harried, will use technical jargon, will suggest the victim is sophisticated enough to understand why he must act now.

They are not creating fear from nothing. They are reading the landscape of what you already fear, and handing you a map to it.

The Four Core Techniques

Authority

The scammer assumes a role that gives them instant credibility. Bank manager. Income tax officer. Air India representative. Police officer.

Why does this work? Because in India, we are trained from childhood that authority should not be questioned. When a man says "This is Sergeant Sharma from the Cybercrime branch," most people do not ask for a callback number or a police complaint number. They listen.

I know a woman in Bangalore โ€” let's call her Priya โ€” who received a call saying her Aadhaar had been linked to a suspicious bank account and she had to urgently transfer โ‚น25,000 to a "temporary verification account" or face legal action. She was a software engineer. She knew Aadhaar fraud was real. She knew her Aadhaar had been compromised before (like 1.1 billion others in India after the 2018 Aadhaar leak). The authority โ€” the claim of a government process โ€” bypassed her education. She transferred the money within 20 minutes.

Authority works because it removes the burden of decision-making from you. You are not thinking anymore. You are obeying.

Urgency

"Your account will be blocked in 24 hours." "Your UPI limit has been temporarily frozen." "Your son's school fees payment failed and they have given us until tonight to recover it."

Urgency is a chemical. It floods your system with cortisol and adrenaline. In that state, you do not fact-check. You do not call back the number on the back of your card. You do not ask to speak to someone else. You act.

I have worked with fraud investigators who tell me the most successful scams follow a pattern: a calm, detailed call explaining a problem (authority), followed by a ticking clock (urgency), followed by a simple, irreversible action (transfer money, click the link, read the OTP aloud).

What makes urgency especially lethal in India is our reliance on time-sensitive systems. Trains leave at scheduled times. Bank hours are fixed. Government offices give you one day to respond to notices. We are culturally predisposed to believe that bureaucracy does not wait. So when a scammer creates artificial urgency, it feels like the real thing.

Likeability

This is the technique I underestimated the most.

A scammer will spend 10 minutes โ€” sometimes more โ€” building rapport with you before asking for anything. They will ask about your day. They will laugh at your small jokes. They will say things like "I know it is frustrating, but I am here to help you." They will apologize for the inconvenience.

Why? Because a person you like is harder to say no to. This is not psychology from a textbook. This is something every Indian knows instinctively โ€” we do favors for people we like, even when those favors cost us.

I watched a recording of a call where a scammer posed as a telecom customer service agent. The victim โ€” a man of 55 โ€” had mentioned in passing that his daughter was getting married. The scammer spent five minutes asking about the wedding, the venue, the budget, whether the family was nervous. By the time he pivoted to "I need you to log into your account to verify your SIM is not at risk," the victim felt like he was helping a friend, not handing credentials to a criminal.

Likeability is the foundation on which the other techniques rest. Once someone likes you, authority feels reasonable. Urgency feels justified. Requests feel reasonable.

Trust Seeding

Before a scammer asks for money or data, they verify something small.

"Can you confirm your date of birth?" "What is the last transaction on your account?" "You received a statement from ICICI Bank last month โ€” correct?"

Each correct answer โ€” and they will be correct, because the scammer has already bought or stolen this data โ€” builds trust. You are right about who you are. The person asking must therefore be legitimate.

This is called anchoring. Once you have verified three true things, your skepticism toward the fourth (untrue) thing collapses. The brain does a small calculation: this person knows things only my bank would know. They must be my bank.

I have seen scammers do this so precisely that even after the victim lost โ‚น90,000, they initially did not believe they had been scammed. They thought the bank had made an error. The trust seeding had worked so well that the victim's own memory was arguing against reality.

Where Prevention Breaks Down

Every bank in India has fraud awareness posters. Every government body publishes PSAs about not sharing OTPs. Every telecom company sends SMS warnings.

And yet, according to CERT-In, social engineering incidents reported in India increased by 42% in 2023 over 2022. We know the techniques. We are still falling for them.

Why? Because knowing a technique exists is different from spotting it in real time.

When your phone rings at 11 AM on a Tuesday and a calm voice says your SIM is at risk, you are not in a state of intellectual analysis. You are startled. You are mildly anxious. You have 30 seconds before your next meeting. Your brain is not looking for social engineering. It is looking for a solution.

That is the gap the scammer exploits. Not your ignorance. Your humanity.

And here is the harder truth: even when people know better, urgency + authority + likeability is a combination that can override caution. I know this because I have sat across from victims who are engineers, accountants, and even one person who worked in IT security. The technique does not care about your IQ. It cares about the state you are in when the call comes.

Five Things You Can Do, Starting Today

  1. Treat unsolicited contact as suspicious, not surprising. If you did not initiate the contact, verify it independently. Do not use the callback number they give you. Use the number on your statement, your website, or a fresh Google search. This one step stops 70% of social engineering attacks.

  2. Never give OTPs, CVV, or passwords over any medium โ€” phone, WhatsApp, SMS, email. Not even if the person sounds official. No legitimate institution will ask this. If you are unsure, hang up, call the bank's main number, and ask. Real calls can wait three minutes. Scams cannot.

  3. Slow down when someone creates urgency. This is harder to do when panic is real, but it is also when it matters most. If your account is truly at risk, it will still be at risk after you hang up and call your bank directly. If it is a scam, the scammer will disappear the moment you become independent.

  4. Tell your family (especially elderly members) that banks will never call and ask them to move money. Not for security checks. Not for unblocking accounts. Not ever. If your mother gets such a call, she should hang up and call her bank. This is not rudeness. This is survival.

  5. Check your credit report quarterly. If someone has used your identity to open accounts, take loans, or cause damage, you will see it here first. In India, CIBIL offers a free credit report annually. Use it. Fraud can be undone much faster if caught early.

The Lesson That Stays

For years, I thought security was about building better walls. Better passwords. Better encryption. Better systems.

But the wall was never the problem. The door was. And the door opens from the inside.

Social engineering works because it is not trying to break your defenses. It is trying to make you lower them yourself. And it works because we are all, in the right moment, willing to trust. That willingness is not a weakness. It is what makes us human.

But in the age of industrial scamming, it is also what can destroy us.

Read next