Threats 8 min read

Social Engineering: How Attackers Trick Your Team (Beyond Email)

Everyone talks about phishing emails. But some of the most damaging attacks on small businesses start with a phone call, a visitor at the front desk, or a fake invoice that arrives in the actual mail. Here are the social engineering tactics your team needs to know about.

A client of mine β€” a small manufacturing company with about 25 employees β€” got hit last year. Not through a phishing email. Not through ransomware. Someone called their front desk claiming to be from "the phone company," said they were doing a routine line test, and asked the receptionist to read back the verification code that had just been texted to her phone.

That code was a two-factor authentication reset for the company's domain registrar account. By the time anyone realized what had happened, the attacker had transferred their domain to a different registrar and pointed their website to a fake page. It took three days and several thousand dollars to get the domain back. All because one phone call worked.

This is social engineering β€” the art of manipulating people instead of hacking systems. And while phishing emails get most of the attention, attackers have a whole toolbox of non-email tricks that work just as well. Here are the ones that actually hit small businesses, and what to do about them.

Phone Impersonation (Vishing)

Voice phishing β€” "vishing" β€” is when someone calls your business impersonating a trusted person or organization. The most common variants I have seen:

The IT Support Call

"Hi, this is Mark from Microsoft support. We are seeing unusual activity from your computer and need to run a diagnostic. Can you go to this website and download the remote support tool?"

Microsoft does not make unsolicited support calls. Nobody legitimate calls you to tell you your computer has a virus. The tool they want you to install gives them full remote control of your machine.

The Bank Call

"This is Chase fraud prevention. We have detected a suspicious wire transfer of $4,200 from your account. I need to verify your identity β€” can you confirm your account number and the security code I am about to text you?"

The caller is triggering a real password reset or login attempt, which causes your bank to text you a legitimate 2FA code. Once you read it back to them, they own your account. Banks never call and ask for authentication codes.

The Boss Call

"Hey, it is [Owner's Name]. I am stuck in a meeting with a client and need you to do me a quick favor. Can you log into the bank and send a wire to this account? I will explain later β€” I am about to walk back in."

The caller knows the owner's name, probably found it on LinkedIn. They might even have researched who reports to whom. AI voice cloning is making these calls increasingly convincing.

The defense:

  • Every employee who might receive an external call needs to know: never give out codes, passwords, or account information over the phone to someone who called you. Hang up. Call back using a number you look up independently β€” not one the caller gives you.
  • For internal "boss" calls β€” verify through a different channel. Text them. Slack them. Walk over to their office. A real boss who genuinely needs a wire transfer will not mind you taking 30 seconds to confirm.
  • Create a simple verification phrase or process for financial requests. Something like: "Before I process any wire transfer, I will call you on your cell phone to confirm. Every time. No exceptions."

Pretexting: The Fake Invoice and the Fake Survey

Pretexting is when an attacker creates a fabricated scenario to get information or money from you. Unlike a simple impersonation call, pretexting involves a whole backstory. Two versions hit small businesses constantly:

The Fake Invoice

Your accounts payable person receives an invoice for $850 β€” toner cartridges, office supplies, "domain renewal," SEO services, or a listing in some business directory. It looks legitimate. It has your company name, a realistic invoice number, and a payment address. The amounts are usually small enough that nobody questions them. If you pay it, they send another one next month.

A landscaping client of mine paid a fake "annual domain listing fee" for two years before someone noticed. The total loss was only about $400, but the fact that nobody caught it for two years was the real wake-up call.

The Tech Support Renewal Scam

"Hi, this is [Company] calling about your copier/printer/security system service contract. Your annual renewal was due last month and we need to update your payment information. Can you confirm your billing details?"

They know you have a copier because every office has a copier. They know the brand because they looked up your business on Google Maps and called to ask. The call sounds routine, and it lands on someone who handles routine administrative tasks.

The defense:

  • Anyone who handles invoices or payments needs to know: verify new vendors before paying. Check that you actually ordered from them. Google the company name. If the invoice is for under $500 and from an unknown vendor, that is exactly the pattern to watch for.
  • Keep a list of actual vendors and service contracts. If a "renewal" call comes in and the company is not on your list, it is a scam until proven otherwise.

Tailgating and Physical Intrusion

Tailgating is when someone follows an authorized person through a secured door. It is the physical equivalent of phishing β€” instead of tricking a computer, you trick a human holding a door.

The classic scenario: someone in a delivery uniform, arms full of boxes, approaches your office door right behind an employee who just badged in. The employee, not wanting to be rude, holds the door. The "delivery person" thanks them, walks inside, and now has physical access to your office.

For most small businesses without badge readers or security guards, physical security comes down to one thing: do not hold the door for people you do not recognize. If someone says they have a meeting with so-and-so, walk them to the front desk or call the person they claim to be visiting. If they are legitimate, they will appreciate the security. If they are not, they will leave.

This is uncomfortable. Nobody wants to be rude. But the alternative β€” letting a stranger walk unchallenged into your office β€” is worse. Make it an explicit policy so employees feel supported: "We do not hold doors for people we do not know. This is a company rule, not a personal choice, and nobody will get in trouble for enforcing it."

USB Drops and Baiting

This sounds like something out of a spy movie, but it happens. Someone drops a few USB drives in your parking lot, near the entrance, or in a common area. Each one has a label: "Confidential β€” Payroll Data," "Employee Bonuses 2026," or "Layoff List." Curiosity gets the better of someone. They plug it in to see what is on it.

The USB drive is not a storage device β€” it registers as a keyboard and types commands at lightning speed, downloading malware or opening a remote access tunnel. Or it simply contains a file that, when opened, runs ransomware. Either way, plugging in an unknown USB drive is like handing your computer to a stranger.

The defense: tell your team explicitly: never plug in a USB drive you found. If you find one, bring it to whoever handles IT. Let them examine it on an isolated machine. In 99% of cases it is just someone's lost homework β€” but that 1% can destroy your business.

Why Small Businesses Are Targeted

Attackers go after small businesses for the same reason burglars target houses without alarm systems: it is easier. A large corporation has mandatory security training, badge readers at every entrance, a dedicated accounts payable team with verification procedures, and an IT department that has seen every scam in the book.

A 15-person business has none of that. The receptionist handles calls, invoices, visitors, and deliveries β€” often all at once. The owner is the person who approves wire transfers, and nobody questions their "urgent" requests. Everyone is too busy to be suspicious. That is exactly the environment social engineers exploit.

The 10-Minute Team Discussion That Prevents Most of This

You do not need a formal training program. At your next team meeting, take 10 minutes and cover these four rules:

  1. "If someone calls you asking for information, do not give it to them. Hang up and call back on a number you find yourself." β€” This one rule stops every phone impersonation attack. It works for banks, IT support, vendors, and "the boss."
  2. "If someone you do not know wants to come inside, walk them to the front desk. Do not hold the door." β€” Make this a stated policy so people feel supported when they enforce it.
  3. "Never pay an invoice from a vendor you do not recognize without verifying it." β€” If the amount is under $500, from an unknown company, and nobody remembers ordering anything β€” that is the pattern. Pick up the phone and call them.
  4. "Never plug in a USB drive you found. Bring it to me." β€” Simple, clear, memorable.

Print these four rules on a single page. Post them in the break room. Put them in your employee handbook. The goal is not to create a culture of paranoia β€” it is to create a culture of verification. Checking is cheap. Getting tricked is expensive.

The Difference Between Paranoia and Verification

A paranoid person never answers the phone. A prepared person answers the phone, listens, and says: "Let me call you back on the number I have on file." The caller's reaction tells you everything. A legitimate person says "of course." A social engineer gets pushy, creates urgency, or hangs up. The verification itself is the test.