A social engineering attack rarely starts with a line of code. It starts with a phone call from someone who sounds like your bank, a text that looks like it came from HMRC, or an email from a colleague asking for an urgent favour. These attacks target the person sitting in front of the screen rather than the software running on it, and in 2026, that approach is working better than ever. Generative AI now gives criminals the tools to write fluent UK English, clone a familiar voice from a few seconds of audio, and build a convincing fake video call in real time.
This guide explains what a social engineering attack actually is, the tactics UK and Irish criminals are using right now, and the psychological tricks that make even careful people fall for them. You will find a breakdown of the most common attack types, a look at how artificial intelligence has changed the threat landscape, practical steps for reporting an incident to the appropriate UK or Irish authority, and a prevention checklist you can put to use today.
Table of Contents
What Is a Social Engineering Attack?
A social engineering attack is any attempt to trick a person into handing over information, money or access by exploiting trust rather than a technical flaw. Instead of breaking through a firewall, the attacker persuades someone to open the door for them. This might mean posing as an IT technician who needs a password to “fix” a laptop, pretending to be a delivery firm that needs a card payment for a redelivery fee, or impersonating a manager who needs an invoice paid before the end of the day.
The defining feature of a social engineering attack is that it targets a person’s judgement, not a piece of software. Verizon’s 2025 Data Breach Investigations Report found that around 60% of confirmed data breaches involved a human action, such as a click, a phone call, or a misdirected email, with phishing responsible for 57% of social engineering incidents and pretexting for 30%. Those figures point to one conclusion: no amount of antivirus software or firewall configuration removes the need to think before you click, answer or pay.
Common goals of a social engineering attack include stealing login credentials, redirecting a payment, installing malware, or gaining physical access to a building or a restricted system. For a fuller breakdown of the terms used throughout this guide, see our guide to social engineering in the UK.
It helps to separate a social engineering attack from a purely technical one. A software exploit targets a gap in code that a patch can close. A social engineering attack targets a gap in judgement, which is much harder to patch, because it depends on training, culture and habit rather than a single update. That is why organisations with strong technical defences still suffer serious breaches: the attacker simply asks a person to do something the firewall was never built to stop.
The Psychology of Deception: Why the Human Brain Is Vulnerable
Every social engineering attack relies on the same raw material: human psychology. Criminals do not need to guess how people will react under pressure, because decades of behavioural research already tell them. The psychologist Robert Cialdini identified six principles of persuasion that show up in almost every scam, and knowing them is the first step towards spotting one.
Cognitive Biases Hackers Exploit
Authority is the most common lever. People are conditioned to comply with requests from a manager, a police officer or a government department, so an email that appears to come from “the CEO” or “HMRC” carries built-in credibility before a single word is read.
Urgency and scarcity work together to switch off careful thinking. A message warning that an account will be closed within the hour, or that a parcel will be returned unless a fee is paid immediately, gives the brain no time to pause and check.
Reciprocity plays a quieter role. An attacker who offers something small first, such as helpful advice or a free resource, creates a sense of obligation that makes the subsequent request harder to refuse. Social proof and liking round out the list: a scam claiming “thousands of customers have already claimed this refund” borrows the comfort of a crowd, while a friendly, familiar tone builds rapport before the ask arrives.
Workplace pressure adds another layer. Research into decision fatigue shows people are more likely to comply with a suspicious request at the end of a busy day, during a hectic financial year-end, or when juggling several tasks at once. A social engineering attack timed to land during a stressful afternoon has a far better chance of success than the same message sent on a quiet Tuesday morning.
The Core Types of a Social Engineering Attack
A social engineering attack can take several forms, and most UK organisations now face more than one at once. Phishing remains the most familiar, but voice and text-based scams have grown fast enough that the National Cyber Security Centre now treats them as a central part of the threat it tracks.
Vishing and Smishing on the Rise in the UK
Phishing uses email to imitate a bank, retailer or government service, usually with a link to a fake login page. Pretexting builds a false scenario, such as a fraudster posing as a new supplier who needs bank details updated “before the next invoice run”. Baiting dangles something tempting, like a free download or a USB drive left in an office car park, to get malware onto a device. Quid pro quo offers a trade, often fake technical support, in exchange for remote access to a computer. Tailgating is the physical version, where someone without a pass follows an employee through a secure door.
Two variants have grown quickly across the UK: vishing (voice phishing) and smishing (SMS phishing). Vishing calls often impersonate a bank’s fraud team, HMRC, or a courier, using a false sense of urgency to get a one-time passcode read aloud over the phone. Smishing messages imitate parcel delivery notifications or council tax reminders, with a link to a convincing fake payment page. Reports of QR code phishing, known as quishing, rose from around 100 in 2019 to well over 1,300 in a single year, according to Action Fraud data reviewed by industry researchers, which shows how quickly a new format spreads once criminals find one that works.
Our data on phishing across social media platforms shows how these tactics have moved from email inboxes into Instagram messages, LinkedIn requests and fake marketplace listings, often as part of the same social engineering attack chain.
The AI Revolution: Social Engineering 2.0
Artificial intelligence has not invented new tricks so much as removed the friction that used to expose them. The clumsy grammar and generic greetings that once gave a scam email away have largely disappeared, and voice cloning has turned a thirty-second clip of someone talking into a working impersonation tool.
Deepfake Audio and Video: The New CEO Fraud
Large language models let a criminal based anywhere in the world produce fluent, error-free UK English on demand, removing the “poor spelling” red flag that security awareness training has relied on for years. The same tools can research a target’s job title, recent projects and colleagues from public LinkedIn posts in minutes, building a convincing pretext with almost no manual effort.
Voice cloning has made “CEO fraud” far more dangerous. A finance employee who receives a phone call in their manager’s actual voice, asking for an urgent payment, has far less reason to be suspicious than someone reading a text-based email. Mandiant’s 2026 M-Trends report documents a group known as Scattered Spider (tracked as UNC3944) that compromised several major UK retailers in 2025 by socially engineering IT help desk staff into resetting multi-factor authentication for privileged accounts, rather than exploiting any software vulnerabilities.
Video deepfakes are a newer but fast-growing risk, particularly for one-off video calls where a target has no earlier reference for how a colleague normally behaves on camera. Common technical tells still include unnatural blinking, a slight mismatch between lip movement and audio, and a flat, slightly robotic vocal cadence, though these gaps are closing as the underlying models improve.
Table: Traditional vs AI-Driven Social Engineering
| Tactic | Traditional method | AI-driven method | Risk level |
|---|---|---|---|
| Phishing email | Generic greeting, poor spelling, mass-sent | Personalised, fluent UK English, aimed at a specific role | High |
| Phone impersonation | Scripted caller reading from a script | Cloned voice of a real manager or relative | High |
| Video call fraud | Rare; required significant resources | Real-time deepfake video during a live call | Medium |
| Research on a target | Manual searching of public profiles | Automated scraping and summarising of social media | Medium |
The UK and Irish Context: Regulation and Reporting
UK reporting bodies exist to make it easy to flag an incident even when there is no financial loss yet. Action Fraud is the national reporting centre for England, Wales and Northern Ireland, and it is the right first stop for anything involving a financial loss or an attempted fraud. Police Scotland handles reports from Scotland directly. The National Cyber Security Centre runs a separate Suspicious Email Reporting Service, which had received tens of millions of reports by 2025 and led to hundreds of thousands of scam websites being removed, making it worth using even for a message that only seems mildly suspicious.
The UK Online Safety Act has added a further layer of responsibility for platforms hosting user-generated content, pushing social media and messaging services to remove fraudulent accounts and scam content more quickly. For UK Finance’s members, the picture is stark: authorised push payment fraud, where a victim is tricked into approving a payment themselves, cost £257.5 million in the first half of 2025 alone, a 12% rise on the previous year.
In Ireland, the Data Protection Commission oversees how organisations handle personal data breaches, while An Garda Síochána’s National Economic Crime Bureau investigates fraud reports. Any UK or Irish business that suffers a social engineering attack resulting in a data breach involving personal information has legal obligations under GDPR to assess, and in many cases report, the incident within 72 hours. The Financial Conduct Authority has separately warned UK firms that deepfake-enabled fraud is now a governance issue, not just an IT one, and expects boards to show they have considered the risk rather than leaving it entirely to a security team.
Table: Where to Report an Attack (UK and Ireland)
| Country | Body | Best for | Contact |
|---|---|---|---|
| England, Wales, NI | Action Fraud | Financial loss or fraud | reportfraud.police.uk / 0300 123 2040 |
| Scotland | Police Scotland | Financial loss or fraud | 101 |
| UK-wide | NCSC | Suspicious emails, texts, calls, websites | report@phishing.gov.uk |
| Ireland | An Garda Síochána | Financial loss or fraud | garda.ie |
| Ireland | Data Protection Commission | Personal data breaches | dataprotection.ie |
Building a Human Firewall: Prevention Strategy
Software alone will not stop a social engineering attack, because the target is a person’s judgement rather than a device. The strongest defence combines a few technical safeguards with a simple habit that anyone can learn in a few minutes.
A single training session rarely changes behaviour on its own. Short, regular reminders, such as a simulated phishing test followed by a quick, blame-free debrief, tend to stick far better than an annual slideshow, because they keep the pattern-recognition skill fresh rather than letting it fade over the following months.
The Social Engineering Attack Prevention Checklist
A short mental framework helps under pressure. Read the message properly before reacting. Evaluate who is really asking and why, and whether the request aligns with how that person or organisation typically behaves. Then either delete it or report it if something still feels wrong. Alongside that habit, a few practical steps make a measurable difference:
- Verify unusual requests through a second channel, such as calling a colleague back on a number you already have, rather than one provided in the message.
- Turn on multifactor authentication everywhere it is offered. Microsoft’s own research suggests it blocks more than 99% of automated account takeover attempts, though it will not stop every social engineering attack on its own.
- Slow down urgent requests, particularly ones involving payments, password resets or gift cards, since urgency is the single most common pressure tactic in use.
- Confirm a caller’s identity independently if a voice sounds right but the request feels wrong, especially for anything involving money.
- Report near-misses as well as successful attacks. A colleague who reports a suspicious call helps the whole organisation recognise the same attempt next time.
- Review privacy settings on social media, since public posts about a job title, holiday dates or family details are often the raw material for a convincing pretext.
Our internet glossary explains many of the related terms used across this guide, from multifactor authentication to data breach, in plain English.
Staying Vigilant Against a Social Engineering Attack
Technology keeps changing the shape of a social engineering attack, but the underlying trick stays the same: borrow trust, create pressure, and get a person to act before they have had time to check. Recognising the pattern is the most reliable defence there is, whether the attack arrives as a phishing email, a text about a missed delivery, or a phone call in a voice that sounds exactly like your manager’s.
Keep the habits in this guide close at hand. Read carefully, verify through a second channel, and report anything that feels off, even if nothing was lost. If you have experienced a social engineering attack or spotted one that others should know about, we would like to hear from you in the comments below. Sharing real examples helps everyone else recognise the same attempt sooner next time.
Frequently Asked Questions
What is the most common social engineering attack right now?
Phishing still leads by volume, but AI-generated spear phishing aimed at a specific person’s role has overtaken generic mass email as the more damaging variant, since it is harder to spot and often targets finance or HR staff directly.
How can I tell if a voice or video call is a deepfake?
Listen for a flat or slightly robotic tone, unnatural pauses, or blinking that does not quite match natural speech in a video call. None of these signs is guaranteed, so the safest approach is to verify anything involving money or credentials through a separate channel.
Does antivirus software protect against a social engineering attack?
Not directly. Antivirus software can catch malware delivered through a malicious attachment or link, but it cannot stop someone from being persuaded to hand over a password or approve a payment voluntarily. That is a human problem that needs a human-focused response.
Who is most likely to be targeted?
Anyone can be targeted, but finance staff, HR teams and senior executives face disproportionate attention because they can approve payments or access sensitive systems. Smaller businesses are increasingly targeted too, often as a way into a larger supply chain partner.
What should I do if I have clicked a suspicious link?
Disconnect the device from the network, change any passwords that may have been exposed, and tell your IT team or bank straight away. If personal data was shared, report it to Action Fraud or Police Scotland and keep a record of what happened.
Are small businesses really at risk from social engineering attacks?
Yes. Criminals often see a smaller business as an easier route into a larger organisation’s supply chain, and a successful social engineering attack on a small team can be just as costly, relative to size, as one on a large corporation.