Pretexting is the construction of a fabricated but plausible scenario and identity — a “pretext” — that gives a target a reason to trust the attacker and hand over information, access, or action they would otherwise withhold. It is the foundational human-vector technique: the story inside which almost every other social-engineering move runs, supplying motive (“why this person is contacting me”), authority or affinity (“who they are”), and a frictionless next step (“what I’m being asked to do”). Done well, it never feels like an attack; it feels like a Tuesday.
The technique rests on an asymmetry: most trust decisions are made from surface cues — a confident tone, a plausible name, a known-sounding department, a detail only an insider “should” know — rather than from verification. The pretexter assembles just enough of those cues to clear your threshold, then spends the trust immediately. The corroborating details are frequently harvested from public sources, prior breaches, or an earlier, smaller pretext, each success buying credibility for the next.
Because the deception lives in the scenario rather than in any single suspicious artifact, pretexting is unusually hard to catch by looking for technical red flags — which is why defense here leans on out-of-band verification and process, not on spotting a bad link. It underlies most modern financial-crime patterns: the “supplier” changing bank details, the “executive” demanding an urgent wire, the “bank fraud department” walking a victim through draining their own account.