Cybersecurity glossary

What is Pretexting?

Learn what pretexting is, how attackers invent a role and a story to justify sensitive requests, how it underpins BEC and vishing, and how verification processes defeat a polished persona.

Social engineering and user threatsUpdated August 13, 2026
Also known asPretext social engineeringInvented-identity attackScenario-based impersonation

Definition

Pretexting is a social-engineering technique in which the attacker invents a convincing identity, scenario, and reason for contact—the pretext—so the target feels obligated or helpful enough to disclose information, grant access, or complete a transaction they would refuse from a stranger.

Why the story is the exploit

Malware needs a vulnerability. Pretexting needs a reason you would help. The attacker constructs a character (IT, auditor, new hire, counsel, stranded executive) and a situation that makes the target’s normal caution look unhelpful or disobedient. Once that frame is accepted, asking for a password reset, a door badge, or a changed IBAN feels like doing the job—not breaking it.

The technique is older than email. It still thrives because organizations run on exceptions: someone always has a dying laptop before a demo, a vendor always needs a portal account today, a leader always wants discretion. Pretexting borrows those real exception paths and occupies them.

A strong pretext is internally consistent, slightly urgent, and flattering to the helper. It does not have to be perfect. It has to be better than the target’s appetite for conflict in that moment.

How a pretext is assembled

1

Choose the helpful target

Reception, help desk, finance ops, and executive assistants are trained to solve problems quickly for other people.

2

Invent a role they already serve

Pick an identity the target is supposed to assist: employee, auditor, courier, customer, or senior stakeholder.

3

Load the story with checkable fragments

Mix public org details, leaked data, and guessed ticket language so a quick sanity check appears to pass.

4

Add a clock and a cost of refusal

Payroll will miss the window, the audit finding will escalate, the executive will be embarrassed—if the target slows down.

5

Ask for a small, job-shaped action

A reset, a transfer, a badge reprint, a file, a ‘temporary’ forwarding rule—each feels like a normal ticket.

6

Keep the persona until the action completes

Stay in character on the call, in the thread, or at the desk so second thoughts do not get a silent moment.

Places pretexting shows up

Service desk identity proof

A caller who knows a manager’s name and a laptop model requests an MFA reset ‘because the phone was stolen on travel.’

Finance exception handling

Confidential M&A, a supplier ‘system migration,’ or a CEO stuck in a meeting becomes the reason to skip dual control.

Physical and reception desks

A visor, a clipboard, and a work-order story can produce badges, Wi-Fi, or a walk into a restricted floor.

Vendor and customer support

Attackers pose as a client in an outage so support shares logs, credentials, or a remote session they would not give a stranger.

Pretexting versus the channels that carry it

IdeaWhat it isWithout a pretext
PretextingThe invented identity and justificationThe request looks like a random stranger asking
PhishingDeceptive message plus hostile destinationThe link has no believable work reason
VishingLive voice deliveryA cold call with nothing to say after hello
BECPayment or data diversion via business mailA wire request with no executive or vendor story

Making the story insufficient

You cannot train people to enjoy saying no to a panicked colleague. You can make the colleague’s panic irrelevant to the control.

  • Define which actions are never authorized by the requester’s narrative: MFA resets, payee changes, badge issuance, production access.
  • Require a callback or ticket on a channel the organization already operates, using contact data not supplied in the request.
  • Give help-desk and reception scripts that are polite and absolute: ‘I will open a ticket and reach you on the number we have on file.’
  • Limit how much internal detail is public; every org chart, tool name, and office photo is pretext raw material.
  • Log failed identity proofs. Repeated near-miss stories against finance or IT are a campaign, not awkward customers.
  • Separate helpfulness metrics from security-sensitive tickets so staff are not punished for slowing a ‘CEO’ request.
  • For executives, publish an internal rule: no payment or access instruction is valid by voice or chat alone.
  • Practice tabletop scenes, not only phishing clicks: a courier at 5 p.m., a payroll emergency on Friday, a vendor outage during a launch.

The tell is rarely a typo

People look for spelling mistakes. Pretexting crews look like competent coworkers. The reliable tell is the combination of identity plus irreversible action plus time pressure plus a reason you must not use the normal path. Any three of those together should force a channel switch, even when the story is emotionally perfect.

The practical takeaway

Pretexting is the craft of becoming someone the target is supposed to help. Channels change; the need for a justification does not.

Do not debate the story on the attacker’s channel. Verify the person through a contact method you already trusted, and keep high-impact actions bound to that verification. A real emergency can wait for a callback. A fabricated one cannot.

Related security terms

Frequently asked questions

What is pretexting in simple terms?

Pretexting is making up a believable role and situation so someone helps you. The attacker is not ‘a random stranger asking for a password’; they are ‘payroll fixing a direct-deposit error before tomorrow’s run.’

Is pretexting the same as phishing?

No. Phishing is a delivery method, usually a deceptive message plus a destination. Pretexting is the story and identity. Phishing often uses a pretext; vishing and in-person scams can pretext without any phishing page.

Where does pretexting show up besides email?

Help-desk calls, fake audits, courier impersonation at reception, vendor onboarding chats, dating-app romance setups, and support tickets that look like a real customer emergency.

Why do pretexts include true details?

A few accurate facts—manager name, invoice number, office location—make the false request feel internally consistent. People treat mixed-true stories as fully true.

Can training spot every pretext?

Training helps people notice pressure and odd channels. Process is stronger: no identity, payment, or access change proceeds on the requester’s story alone.

Is pretexting illegal?

Using a false identity to obtain financial data, access systems, or commit fraud is illegal in many jurisdictions. This glossary explains the technique so teams can defend against it, not so anyone can practice it.

What is the best on-the-spot defense?

Slow the request. Switch to a contact method you already had, and verify the person’s identity and ticket through that channel. A legitimate pretext survives a callback; a fabricated one usually collapses.

References

Explore authoritative guidance and frameworks related to pretexting.

Explore every security definition

Return to the glossary to search by term, alias, starting letter, or security category.

Browse glossary