Social engineering is manipulating a person, rather than breaking a system, into doing something or revealing something that compromises security. It exploits human wiring like trust, authority, fear, urgency, and greed, and it is the common thread behind phishing, pretexting, and most scams.
What is social engineering, in plain English?
Social engineering is the craft of getting a person to act against their own interest by managing how they feel and what they believe in the moment. The attacker does not need a software exploit; they need the target to click, tell, pay, or approve. The tools are psychological: a sense of authority, a ticking clock, a fear of loss, a favor owed, or a reward dangled.
It is the root technique under a huge share of fraud. Phishing, spear phishing, voice phishing, pretexting, business email compromise, romance scams, and tech support scams are all social engineering wearing different clothes. Strip away the channel and the pattern is the same: build a believable story, apply pressure, and steer the target toward one specific action.
For a fraud or AML team, the important reframing is that the human is the attack surface. Controls that assume a request is genuine because it came from a real person, a real phone number, or a logged-in session are exactly what social engineering is built to defeat.
How a social engineering attack unfolds
Research — Learn the target. The attacker gathers names, roles, routines, and relationships from social media, leaks, and public records.
Pretext — Build a believable story. They craft a role and a reason to make contact: a manager, a vendor, a support agent, a regulator.
Pressure — Create urgency or fear. A deadline, a threat, or an authority is used so the target acts before pausing to verify.
Exploit — Extract the action. The target hands over a credential, a code, or a payment, or approves a change they should have questioned.
The levers attackers pull
Lever
How it is used
Authority
Posing as a boss, a bank, or a regulator so the target complies without pushing back.
Urgency
A deadline or a threat that removes time to think and verify through a second channel.
Fear
A warning of loss, fraud, or trouble that makes the target act to avoid the consequence.
Trust and liking
Building rapport or impersonating a known person so the request feels safe.
Greed
A prize, a job, or an investment that makes the target overlook the risk to chase the reward.
What it looks like in practice
In practice
An accounts payable clerk gets a call from someone claiming to be the company's bank, warning of a suspicious payment and asking the clerk to confirm a code to cancel it. The caller knows the clerk's name, the bank, and a recent invoice, so the story lands.
None of that detail proves who is calling; it was scraped and guessed. The code the clerk reads out is a one-time password that authorizes a new payee. The pressure was manufactured, the authority was faked, and the clerk did exactly what any careful person might do under a convincing threat.
Why it matters to operators
Because social engineering targets people, it slips past controls that only inspect systems. The login is real, the session is valid, the customer is the one clicking the button, which is why authorized payment fraud and takeovers that start with a scam are so hard to score on transaction data alone. The signal is often in the story, not the mechanics: a payment the customer was told to make, a change they were coached through.
The highest-leverage defense is layered: training and awareness so people recognize the pressure, strict verification and callback procedures that no urgency can waive, and system controls that assume any request could be engineered. When a control can be talked around, it is not really a control.
What to watch for
Pressure to skip steps. A customer or employee insisting a normal check be waived because of an emergency.
Coached behavior. Payments or changes where the customer is clearly following instructions from someone on another line.
Authority claims. Requests that lean on being the bank, the boss, a regulator, or support to shut down questions.
Second-channel avoidance. Resistance to a callback on a known number, or a reason why you cannot verify independently.
Out-of-pattern favors. First-time payees, urgent gift-card or crypto asks, and changes to payout or recovery details.
Quick questions
Is social engineering a type of fraud or a technique?
It is a technique. Most named scams, from phishing to business email compromise, are specific applications of social engineering across different channels and targets.
Why can't technology alone stop it?
The exploit is aimed at a person's judgment, not a system flaw. Technical controls help, but if a real user can be convinced to approve an action, the system sees a legitimate request.
What is the single most effective defense?
A verification procedure that cannot be waived by urgency, paired with awareness training. If people always verify sensitive requests through a known, separate channel, most social engineering fails.
How does it show up in authorized payment fraud?
The customer is manipulated into sending the money themselves, so the payment looks fully legitimate. The fraud lives in the story they were told, which is why context and intervention matter more than transaction rules.
Does AI make it worse?
Yes. Voice cloning, deepfakes, and generated text make pretexts more convincing and easier to produce at scale, so more attacks look and sound authentic.
How do you train for it without scaring people?
Focus on recognizing pressure and always verifying, not on spotting every trick. Simulated exercises and a blameless reporting culture work better than fear, which just drives mistakes underground.
---
title: Social engineeringとは?
source_page: https://www.sardine.ai/jp/fraud-aml-glossary/social-engineering
canonical: https://www.sardine.ai/jp/fraud-aml-glossary/social-engineering
format: text/markdown
description: Social engineering is manipulating people, rather than breaking technology, into actions or disclosures that compromise security, by exploiting trust, authority, fear, urgency, or greed. It is the common thread behind phishing, pretexting, voice phishing, impersonation, and most scams.
---
**Quick links:** [Human page](https://www.sardine.ai/jp/fraud-aml-glossary/social-engineering) · [Home](https://www.sardine.ai) · [Customers](https://www.sardine.ai/jp/customers) · [Blog](https://www.sardine.ai/jp/blog) · [Demo](https://www.sardine.ai/jp/demo)
---
# Social engineeringとは?
**Read time:** 4
Social engineering is manipulating people, rather than breaking technology, into actions or disclosures that compromise security, by exploiting trust, authority, fear, urgency, or greed. It is the common thread behind phishing, pretexting, voice phishing, impersonation, and most scams.
Social engineering is manipulating a person, rather than breaking a system, into doing something or revealing something that compromises security. It exploits human wiring like trust, authority, fear, urgency, and greed, and it is the common thread behind phishing, pretexting, and most scams.
What is social engineering, in plain English?
Social engineering is the craft of getting a person to act against their own interest by managing how they feel and what they believe in the moment. The attacker does not need a software exploit; they need the target to click, tell, pay, or approve. The tools are psychological: a sense of authority, a ticking clock, a fear of loss, a favor owed, or a reward dangled.
It is the root technique under a huge share of fraud. Phishing, spear phishing, voice phishing, pretexting, business email compromise, romance scams, and tech support scams are all social engineering wearing different clothes. Strip away the channel and the pattern is the same: build a believable story, apply pressure, and steer the target toward one specific action.
For a fraud or AML team, the important reframing is that the human is the attack surface. Controls that assume a request is genuine because it came from a real person, a real phone number, or a logged-in session are exactly what social engineering is built to defeat.
How a social engineering attack unfolds
Research — Learn the target. The attacker gathers names, roles, routines, and relationships from social media, leaks, and public records.
Pretext — Build a believable story. They craft a role and a reason to make contact: a manager, a vendor, a support agent, a regulator.
Pressure — Create urgency or fear. A deadline, a threat, or an authority is used so the target acts before pausing to verify.
Exploit — Extract the action. The target hands over a credential, a code, or a payment, or approves a change they should have questioned.
The levers attackers pull
What it looks like in practice
In practice
An accounts payable clerk gets a call from someone claiming to be the company's bank, warning of a suspicious payment and asking the clerk to confirm a code to cancel it. The caller knows the clerk's name, the bank, and a recent invoice, so the story lands.
None of that detail proves who is calling; it was scraped and guessed. The code the clerk reads out is a one-time password that authorizes a new payee. The pressure was manufactured, the authority was faked, and the clerk did exactly what any careful person might do under a convincing threat.
Why it matters to operators
Because social engineering targets people, it slips past controls that only inspect systems. The login is real, the session is valid, the customer is the one clicking the button, which is why authorized payment fraud and takeovers that start with a scam are so hard to score on transaction data alone. The signal is often in the story, not the mechanics: a payment the customer was told to make, a change they were coached through.
The highest-leverage defense is layered: training and awareness so people recognize the pressure, strict verification and callback procedures that no urgency can waive, and system controls that assume any request could be engineered. When a control can be talked around, it is not really a control.
What to watch for
Pressure to skip steps. A customer or employee insisting a normal check be waived because of an emergency.
Coached behavior. Payments or changes where the customer is clearly following instructions from someone on another line.
Authority claims. Requests that lean on being the bank, the boss, a regulator, or support to shut down questions.
Second-channel avoidance. Resistance to a callback on a known number, or a reason why you cannot verify independently.
Out-of-pattern favors. First-time payees, urgent gift-card or crypto asks, and changes to payout or recovery details.
Quick questions
### Is social engineering a type of fraud or a technique?
It is a technique. Most named scams, from phishing to business email compromise, are specific applications of social engineering across different channels and targets.
### Why can't technology alone stop it?
The exploit is aimed at a person's judgment, not a system flaw. Technical controls help, but if a real user can be convinced to approve an action, the system sees a legitimate request.
### What is the single most effective defense?
A verification procedure that cannot be waived by urgency, paired with awareness training. If people always verify sensitive requests through a known, separate channel, most social engineering fails.
### How does it show up in authorized payment fraud?
The customer is manipulated into sending the money themselves, so the payment looks fully legitimate. The fraud lives in the story they were told, which is why context and intervention matter more than transaction rules.
### Does AI make it worse?
Yes. Voice cloning, deepfakes, and generated text make pretexts more convincing and easier to produce at scale, so more attacks look and sound authentic.
### How do you train for it without scaring people?
Focus on recognizing pressure and always verifying, not on spotting every trick. Simulated exercises and a blameless reporting culture work better than fear, which just drives mistakes underground.
Go deeper
FTC Consumer Advice: Scams ↗ — US consumer guidance on current scams and fraud, and how to report them.
FBI IC3 ↗ — The FBI Internet Crime Complaint Center. Fraud reporting and annual trend reports.