In the digital age, cybersecurity is often associated with firewalls, encryption, and antivirus software. But one of the most emerging threats to organisations today doesn’t rely on technical exploits—it targets people. This is the realm of social engineering, a form of manipulation that preys on human psychology to gain access to sensitive information or systems.
So What Is Social Engineering exactly?
Social engineering is a deceptive tactic used by cybercriminals to manipulate individuals into divulging confidential information or performing actions that compromise security. Unlike technical attacks that exploit software vulnerabilities, social engineering exploits human vulnerabilities—trust, fear, urgency, and curiosity.
Common techniques can include:
- Phishing: Fraudulent emails or messages that appear to be from legitimate sources such as a bank or a government agency, usually containing malicious links
- Spear Phishing: Targeted phishing aimed at a specific individual, a highly targeted form of a phishing attack that uses personalised, convincing emails to trick a specific individual or organisation into revealing sensitive information or gaining unauthorised access to a system
- Vishing: where fraudsters use voice calls to trick people into revealing sensitive information, such as passwords, credit card numbers, or bank details – short for “voice phishing”
- Smishing: fraudulent text messages to trick individuals into revealing sensitive information or downloading malicious software. It is a combination of “SMS” and “phishing” and often impersonates trusted sources like banks, delivery services, or government agencies wanting the victim to click malicious links or provide personal data like passwords or financial information
- Pretexting: Fabricating a believable story or identity to manipulate a person into revealing sensitive information – where an attacker fabricates a scenario or false identity to manipulate a person into revealing confidential information or taking actions that compromise security. The attacker uses a “pretext,” or a made-up story, to gain the victim’s trust and appear legitimate, often posing as a trusted figure like a bank representative or IT support staff
- Baiting: Luring victims with a tempting offer, like a free download or a USB drive, to steal personal information or infect their system with malware, often involving malicious links and fake websites
Social Engineering vs. Technical Attacks
While technical attacks exploit flaws in software or hardware, social engineering attacks exploit human behavior. A technical attack might involve malware or brute-force password cracking, whereas a social engineering attack could involve impersonating an IT technician to trick an employee into revealing login credentials.
The key difference lies in the entry point:
- Technical attacks: Target system
- Social engineering attacks: Target people
Case Study: The Qantas Cyber Attack – July 2025
In July 2025, Qantas suffered a significant data breach affecting up to 6 million customers. The breach was traced to a third-party platform used by an offshore call centre. Cybercriminals reportedly used social engineering tactics to impersonate IT personnel and trick a call centre worker into revealing login credentials.
What Was Stolen:
- Names
- Email addresses
- Phone numbers
- Dates of birth
- Frequent flyer numbers
Although financial data and passwords were not compromised, the stolen information was enough to enable identity theft or other scams or fraudulent activity.
The attack was attributed to a cybercriminal group known for sophisticated social engineering techniques.
Qantas faced public scrutiny for its handling of the breach. Customers reported scam calls and suspicious activity linked to their personal data. The airline engaged cybersecurity experts and informed relevant Australian authorities including the Australian Federal Police.
How Organisations Can Protect Themselves
Regardless of industry, size, or location, every organisation is vulnerable to social engineering. Here are practical steps to reduce the risk:
- Educate staff regularly on social engineering tactics and how to spot suspicious behaviour
- Limit access to sensitive data based on role and necessity
- Establish clear protocols for verifying identity before sharing information
- Have policies and procedures in place (eg. for when a vendor wants to change bank account details, how to establish identity etc) and educate staff on them
- Monitor for unusual behavior using behavioral analytics and anomaly detection tools
- Secure third-party platforms and ensure vendors follow strict cybersecurity standards
- Use email filtering technologies to block malicious messages
- Implement phishing-resistant multi-factor authentication (MFA) across all systems
- Maintain offline backups and test them regularly to ensure data recovery capabilities
- Conduct simulated phishing exercises to test and improve employee awareness
- Your IT team should support your social engineering education program and protocols, and engaging a cyber security professional may also support your program through relevant expertise.
The Importance of Culture
- Your workplace culture will play an important role in preventing social engineering attacks. Your teams should feel safe and supported to adhere to company security protocols regardless of who they are dealing with. They may get a phone call purporting to be from a senior executive or manager, and your staff should feel empowered to stick to policy and procedure regardless of seniority or hierarchies! So ensure you encourage a culture of skepticism—employees should feel empowered, supported and educated to question unusual requests or situations where they are being placed under pressure to act quickly, or divulge information or take an action they would not normally do.
Conclusion
Social engineering is a growing threat that bypasses traditional cybersecurity defenses by targeting the human element. The Qantas breach is a stark reminder that even large, well-resourced organisations are vulnerable. By fostering awareness, implementing robust security protocols, and staying vigilant, organisations can significantly reduce their exposure to these manipulative attacks.
Where can you get further information?
In Australia the following agencies provide fantastic information and resources to support you and your teams with education and response to social engineering:
Commonwealth Fraud Prevention Centre
Australian Signals Directorate
Following are the references used in the development of this content:

