How Social Engineers Think: What I Learned from Years of Watching Them Work
Social engineers exploit trust, not passwords. An Indian practitioner's guide to understanding their methods—and why your skepticism is your only defense.

The Call That Taught Me Everything
Mumbai, February 2019. I was sitting in a coffee shop when my phone rang. The voice on the other end was calm, almost bored. "Sir, this is calling from ICICI Bank fraud prevention. We have detected some suspicious activity on your account. Can you confirm your last transaction?"
I hung up immediately. It was a scam. I knew it was a scam. And yet—for three seconds before I hung up—I felt the cold touch of uncertainty. That is the entire art of social engineering, compressed into a single moment.
The caller did not need my password. The caller did not need malware on my phone. The caller needed one thing only: my willingness to believe that I was in danger, and that the person on the phone could help.
That is what social engineering is. Not hacking. Not code. Just people. Lying.
What Social Engineering Actually Is
I will be direct: most of what we call cybersecurity is theater if we do not understand this one fact—the weakest security system in any organization is the human being who works there.
Social engineering is the art of manipulating that human being into giving away information or access that they should not give away. It is not a computer attack. It is a con. A very old con, dressed up in modern clothes.
The scammer does not break into your house through the window. The scammer knocks on your door, smiles at you, and you let them in yourself.
The Core Techniques: How They Actually Work
Pretexting—The Lie That Fits
Pretexting means creating a false scenario that makes you want to cooperate. The bank fraud line I received? That is pretexting. The scammer chose a story that made sense—because banks do call about fraud sometimes—and made me want to verify my information to protect myself.
I watched this happen to a friend in Bengaluru last year. A man called her saying he was from Amazon customer care. There had been a "suspicious purchase" on her account—a laptop worth ₹1,15,000. Was that her? Of course it was not. The immediate panic did the rest. She gave him access to her phone. He installed something. We do not know what it was because we never found out.
The reason pretexting works is simple: it tells a story your brain wants to believe. Banks do detect fraud. Amazon does have customer care. So when the caller says he is one of those people, your skepticism goes to sleep.
Phishing—The Email That Lies
Phishing is pretexting at scale. Instead of one caller, imagine 10,000 emails that all say the same thing: "Your ICICI account needs urgent verification. Click here."
Most people delete them. A few click. That is enough.
The email looks official. It has the bank logo (copied from the real website). It has urgent language: "Your account will be locked in 24 hours unless you verify your identity." It has a link. The link looks like icicibank-security.verify.co.in. Close. So close. But not quite.
I have received hundreds of these. They are getting better. Last month, I saw a phishing email for HDFC Bank that mimicked the exact layout of the real HDFC login page. The only tell? The footer link said www.hdfcbank-verification.com instead of www.hdfcbank.com. One character. That is all that separated ₹50,000 from being gone.
Baiting—The Thing You Want
Baiting is the oldest trick. You leave something tempting where someone might find it, and they take it.
In the old days, scammers left USB drives in parking lots labeled "Salary Reviews - Confidential." An employee finds it, plugs it into their laptop at work (because curiosity is human), and malware spreads through the network.
Now it is digital. "You have been selected for Amazon Prime membership for free." "Download your NEET exam results here." "Claim your free cryptocurrency wallet." Each one is bait. You download the file. The file installs something. The something sends back your passwords, your location, your bank details.
Why does this work? Because we want things to be true. We want the free membership. We want our exam results. We want the thing that someone is dangling in front of us.
Quid Pro Quo—The Trade That Hurts You
Quid pro quo is simple: "I will give you something valuable if you give me something valuable."
A scammer calls an office and says, "This is calling from the IT helpdesk. We need to update your system. Can you provide your employee ID and password so I can complete the update?"
The victim thinks: IT does ask for this sometimes. A system update is normal. So they give the password. The scammer logs in, copies data, installs backdoor access, and vanishes.
I have seen this happen in small offices in Gurugram where IT infrastructure is weak and everyone trusts everyone else. The victims were not stupid. They were just operating under the assumption that the person on the phone was who they said they were.
Tailgating—The Physical Breach
Tailagating means following someone into a secure area without authorization. You walk into an office building behind someone who has a security badge. The door opens. You are in.
Once you are inside, you can:
- Sit at an unattended desk and access their computer
- Plug in a USB device that captures network traffic
- Walk to the server room and photograph hard drives
- Ask questions about systems and people until you understand the network well enough to attack it remotely later
Tailgating is not high-tech. It is just audacity and the fact that most people assume you belong there if you act like you belong there.
The Hard Truth About Why This Works
Social engineering works because trust is necessary. You cannot live a functional life if you assume everyone is lying to you. You have to trust that the person on the phone from the bank is actually from the bank. You have to trust that the email from your CEO is actually from your CEO. You have to trust that the person walking into your office with a clipboard is supposed to be there.
Scammers exploit the system that keeps society running: assuming people are who they say they are.
Yes, the bank has verification procedures. Yes, your email should have sender authentication. Yes, your office should have security protocols. But all of those are only as strong as the human being enforcing them. And humans get tired. Humans get distracted. Humans want to be helpful.
That is the vulnerability.
What Makes Someone a Target
After years of watching this, I can tell you that scammers do not target random people. They target:
People who are helpful by nature. If you are the kind of person who answers questions and helps when asked, you are vulnerable. Social engineers know this. They will call and say, "I need help understanding this error on my account," and your helpfulness becomes your weakness.
People who are in a hurry. Skepticism takes time. If you are rushing to get somewhere, you are more likely to take shortcuts. You will type the OTP without checking where you entered it. You will click the link without reading the URL. You will answer the security question without thinking about who you are talking to.
People who are afraid. "Your account will be locked." "Your Aadhaar is being misused." "Suspicious activity detected." Fear makes people act without thinking. The scammer counts on that.
People who are lonely. Romance scams work because the victim is lonely, and someone is finally paying attention to them. They are not stupid. They are just in need of human connection.
The Philosophy That Actually Helps
Here is what I have learned: security is not about being paranoid. Security is about being deliberately, methodically skeptical. Not of people in general. Just of claims that require immediate action, information sharing, or access to your accounts.
The most dangerous claim is the one that combines urgency with authority. "Your account will be locked in 24 hours" + "I am from the bank" = most people do what they are told.
Break that chain. Always.
What You Can Actually Do
-
Verify before you trust. If someone calls claiming to be from your bank, hang up and call the bank's official number (the one on your card, not the one the caller gives you) and ask if they called you. Most of the time, they did not.
-
Check the sender, not just the message. Phishing emails often mimic official ones, but the sender's actual email address is wrong. Hover over the sender name. Look at the full email address. Would your bank send you an email from
info@icicibank-security.co.uk? No. -
Slow down when someone asks for information. Your password. Your OTP. Your employee ID. Your Aadhaar number. None of these should be shared in response to an unsolicited call or email. Period. If you need to do something urgent, take the time to verify the person asking. Urgency is the scammer's best tool.
-
Do not click links in unsolicited messages. Type the website address into your browser yourself. Use the phone number on your official documents, not the one someone gave you. This takes 30 seconds and costs you nothing.
-
Talk to someone else before you act. If you get a call or email that makes you anxious, tell a friend or family member what happened. Read it to them. Often, they will hear the scam before you do. We are all blind to our own vulnerabilities.
-
Report it, even if nothing was stolen. Call the bank's fraud line. Forward the email to the official fraud reporting address. Tell CERT-In at
incidents@cert-in.org.inif the scam involved phishing. Data on scam attempts helps institutions identify patterns and protect others. -
Remember: you are not stupid if you almost fell for it. The best scammers in the world are good at what they do because they understand human psychology. You are not weak for having been targeted. But you can be smart by understanding how the attack works and refusing to cooperate with it.
The person who stops a scam is not the person who is most paranoid. It is the person who is calm enough to check.


