Social engineering is manipulating a person into taking an action or revealing information, rather than defeating a technical control. For employers it is the mechanism behind nearly every fraud that reaches HR and payroll, because those functions can be asked to do things that no system would permit an outsider to do directly.
An attacker cannot change an employee's bank account from outside. But they can ask someone who can.
The techniques are consistent and worth naming, because recognizing the lever is easier than evaluating each message.
Authority. A request appearing to come from an executive. The recipient weighs the cost of being wrong about a fraud against the cost of appearing to distrust the CFO, and the second feels more immediate.
Urgency. A deadline that removes time to think or verify. Almost every successful scheme includes one, because verification is what defeats them.
Helpfulness. The most underestimated. HR teams are measured on being responsive to employees. "I switched banks and need this updated before Friday" is exactly the request a good HR professional wants to resolve quickly.
Familiarity. References to real projects, real colleagues, real invoices — gathered from a compromised mailbox or public sources. This is what makes modern attempts feel legitimate.
Fear. A threatened consequence: an account closing, a payment failing, a compliance problem.
Attacking people is cheaper and more reliable than attacking systems. It requires no technical skill, leaves little for security tools to detect, and scales — the same pretext works across hundreds of employers with minor edits.
It also targets the least-defended surface. Employers invest in endpoint protection and firewalls, then leave the process for changing an employee's bank details as an email to a single person with no verification step.
That last one is worth flagging. A call asking innocuous organizational questions is often reconnaissance for a later attempt, and employees have no reason to treat it as suspicious.
Training raises the bar and is worth doing. But social engineering is engineered against reasonable people, and the best version — a request from a genuinely compromised colleague's account, referencing real context — is not reliably detectable by anyone.
Treating awareness as the whole defense puts the entire burden on an employee's judgment in a moment designed to compromise it. The organization needs controls that work when judgment fails.
Each of these works regardless of whether the employee recognized anything.
The most effective non-technical measure is leadership stating explicitly that verification is expected, applies to requests appearing to come from them, and carries no consequence for the employee who checks.
Authority-based manipulation only works while employees believe pushing back is career-risky. Saying otherwise, publicly and more than once, closes the most damaging variant at no cost.
The same applies to reporting. An employee who realizes they were manipulated needs to be able to say so within minutes, without fear. Organizations that treat these as personal failures learn about incidents last.
Employer's Guardian helps employers train staff against the specific pretexts aimed at HR and payroll, and document that training, through workforce training.
This article provides general educational information, not legal, tax, or insurance advice. Requirements vary by location, industry, and the data your organization handles.