SardineCon SF/2026

Learn More

O que é Pretexting?

SUBSCRIBE

Pretexting is building a fake but believable scenario and identity, such as an auditor, IT support, a vendor, or a new executive, to persuade a target to hand over information or take an action. It is researched and interactive, building rapport across one or more contacts rather than blasting out a generic lure, which is what makes it so convincing.

What is pretexting, in plain English?

Pretexting is the storytelling engine of social engineering. Instead of a crude threat or a mass email, the attacker constructs a plausible backstory and a role that gives them a reason to ask for what they want. They might be the auditor who needs a report before a deadline, the IT technician resetting your access, the vendor confirming updated bank details, or the new executive who needs a quick favor. The pretext gives the request context and legitimacy.

What separates pretexting from ordinary phishing is research and interaction. The attacker studies the target, uses real names, projects, and jargon, and is prepared to hold a back-and-forth conversation. They build rapport, answer questions, and adjust the story in real time. That makes the ask feel like a normal part of a working relationship rather than a suspicious approach.

In the fraud stack, pretexting is a foundational technique that powers other attacks. It underpins voice phishing, business email compromise, and help-desk account takeover. Almost any social-engineering fraud that relies on a convincing role or scenario is, at its core, a pretext.

How a pretexting attack works

  1. Research — Study the target. The attacker gathers names, roles, projects, and processes from social media, leaks, and public sources.
  2. Build — Craft the pretext. They choose a credible identity and scenario that gives a natural reason for the request.
  3. Engage — Open the conversation. Contact is made by call, email, or chat, using real details to establish trust and rapport.
  4. Exploit — Make the ask. Once trust holds, they request the credential, data, payment, or access that was the goal all along.

Common pretexts and disguises

The disguise

The typical ask

IT or help desk

Reset a password, read out a code, or approve an access request for troubleshooting.

Auditor or compliance

Share sensitive records or process details before a supposed deadline.

Vendor or supplier

Update banking details on file or approve a changed remittance.

Executive or manager

Make an urgent payment or buy gift cards as a confidential favor.

Bank or agency

Confirm account details or move money to resolve a fabricated problem.

What it looks like in practice

In practice

A caller reaches the finance team introducing themselves as a technician from the company's payroll software provider, referencing a recent update the team really did receive. They are calm, know the product, and say they need to verify a login to finish a security patch before payroll runs.

Because the story fits and the details check out, an employee reads back a one-time code. That single confirmation lets the attacker into the payroll portal, where they redirect several salary payments. No malware, no obvious phishing link, just a well-researched role and a believable reason to ask.

Why it matters for operators

Pretexting defeats controls that assume fraud looks suspicious. A skilled pretext is polite, informed, and patient, so it slips past instinct and past staff trained only to spot obvious scams. The defense cannot be judgment alone; it has to be process. Strict identity-verification procedures and callback policies that no plausible story is allowed to bypass are what hold, because they do not depend on whether the caller sounds convincing.

For teams, the guiding rule is to verify through a trusted, independent channel before acting on any request for credentials, sensitive data, changed payment details, or urgent transfers. Call back on a known number, not one the caller provides. Confirm a vendor's new bank details through an established contact. The more convincing the caller, the more important it is that the process, not the person, decides.

What to watch for

  • Authority plus urgency. A caller invoking a senior role or a deadline to pressure quick action is the classic pretext combination.
  • Requests to bypass process. Any push to skip normal verification, callback, or approval steps is a warning regardless of how reasonable it sounds.
  • Changed payment details. A vendor or executive asking to update bank details or approve an off-cycle payment should trigger independent confirmation.
  • Credential or code requests. Legitimate IT and support will not ask a user to read out a password or one-time code.
  • Pressure against verifying. A caller who resists a callback or discourages checking with a colleague is protecting the pretext.

Quick questions

How is pretexting different from phishing?

Phishing is often a one-shot, generic lure. Pretexting is researched and interactive, using a tailored identity and scenario and a real conversation to build trust. Phishing can be a delivery method, while the pretext is the story that makes it work.

Is pretexting only done over the phone?

No. It works over email, chat, in person, and by phone. Voice pretexting is common because rapport builds quickly in conversation, but business email compromise is essentially a written pretext.

Why is it so effective?

It supplies context and legitimacy for the request, uses real details to pass a sniff test, and adapts in real time. Because it looks like a normal work interaction, it bypasses the instinct that catches cruder scams.

What is the single best defense?

Independent verification through a trusted channel, such as calling back a known number, before acting on any sensitive request. Process-based controls hold even when the story is convincing, which judgment alone cannot guarantee.

How does it relate to business email compromise?

Business email compromise is pretexting in written form: the attacker adopts the identity of an executive or vendor and uses a believable scenario to redirect a payment. The pretext is the core of the attack.

Can technology stop pretexting?

Technology helps at the edges, through email authentication, caller verification, and payment controls, but because pretexting targets people and process, the durable defense is enforced verification procedures rather than a single tool.

Go deeper

  • FTC Consumer Advice: Scams ↗ — US consumer guidance on current scams and fraud, and how to report them.
  • FBI IC3 ↗ — The FBI Internet Crime Complaint Center. Fraud reporting and annual trend reports.

O que saber junto com Pretexting