Add Think Technology as a trusted source Social Engineering Attacks Explained | TTA

What are social engineering attacks and how do they work?

Illustration showing social engineering attacks targeting a business user via email and phone impersonation

A Queensland accounting firm receives an email from their regular supplier. The bank details have changed. The invoice looks identical to every previous one. A staff member updates the records and approves the payment. The money leaves the account and never comes back.

No malware was involved. No system was hacked. The attacker never needed a password cracker or a vulnerability scanner. They needed a convincing story, a spoofed email address, and a business busy enough not to stop and check.

That is social engineering. It targets people, not systems. And it is now the most common entry point for cyber attacks on Australian businesses. Understanding how these attacks work is the first step to stopping them.

What social engineering attacks actually are

Social engineering is a set of techniques attackers use to manipulate people into taking actions that benefit the attacker. Those actions include opening an attachment, handing over login credentials, approving a payment, or giving access to a system. The ACSC defines social engineering as directing individuals into performing specific actions such as visiting a website, revealing credentials, disclosing sensitive information, or transferring funds. Attackers go to significant lengths to make their communications look legitimate and trustworthy.

The defining characteristic of social engineering is that it bypasses technical controls entirely. Firewalls, antivirus, and spam filters are built to detect malicious code. A well-crafted social engineering message contains none. It is plain text asking a normal-sounding question from what appears to be a familiar sender. Technical defences have nothing to catch.

In ASD’s ACSC Annual Cyber Threat Report 2024-25, phishing (a form of social engineering) was recorded in 60% of incidents reported to the ACSC. Social engineering was the initial access technique in 38% of all reported incidents. Identity fraud was the top reported cybercrime type for the financial year. These are not edge cases. They are the norm.

The main types of social engineering attacks

Attackers have a consistent toolkit. Each technique exploits a different aspect of human behaviour, but they all rely on the same underlying principle: people act on trust and urgency before they stop to verify.

Phishing is the most common form. An attacker sends an email designed to look like it came from a trusted source, such as a bank, Microsoft, the ATO, or a known supplier. The goal is to get the recipient to click a link, open an attachment, or enter credentials into a fake site. Phishing can be sent in bulk (broad and generic) or targeted at a specific person (spear phishing), with personalised details drawn from LinkedIn, company websites, or prior email threads.

Business Email Compromise (BEC) is a targeted evolution of phishing. The attacker either compromises a real mailbox or registers a convincing lookalike domain and then impersonates an executive, supplier, or staff member to request a payment or credential change. In FY2023-24, Australians reported nearly $84 million lost to BEC across more than 1,400 confirmed incidents, averaging $55,000 per incident. BEC works because it blends into normal business processes. There is no suspicious link or attachment. Finance teams, executives, and anyone who approves payments are the primary targets.

Vishing is voice-based social engineering. The attacker calls and impersonates a helpdesk technician, bank representative, or government agency. In Australia, common pretexts include impersonating the ATO, Microsoft support, or a financial institution, with an urgent claim about a suspended account or compliance issue. The urgency is manufactured to stop the target thinking clearly. A well-known threat group, Scattered Spider, used vishing to access a major Australian airline’s call centre systems in 2025 by impersonating IT staff to steal credentials.

Pretexting is when an attacker builds a detailed cover story before making contact. This can precede a phishing email, a phone call, or even an in-person approach. The attacker researches the target organisation, learns the names of executives and suppliers, and constructs a plausible scenario. BEC attackers often spend weeks studying a business before acting, monitoring social media, scanning websites, and intercepting email threads to build context.

ClickFix is a newer technique the ACSC flagged as actively targeting Australian networks in 2025 and into 2026. Threat actors use fake browser alerts and fraudulent update prompts to trick users into running malicious code on their own devices. The social engineering element is simple: the user believes they are fixing a legitimate technical problem. Any request to run code or change system settings that arrives unexpectedly should be treated as suspicious.

Why social engineering keeps working on Australian businesses

Social engineering works because it exploits how people are wired, not gaps in software. Humans are built to respond to authority, urgency, and familiarity. Attackers design their lures to trigger exactly those responses. A message from the CEO asking for an urgent payment, a call from the ATO warning about a compliance issue, an invoice from a known supplier with updated bank details: each one is calibrated to make a busy person act before they think.

AI has made the problem worse. Generative AI tools allow attackers to produce highly personalised, grammatically correct phishing and BEC messages at scale. An attack that once took hours of manual research can now be prepared in minutes, with the target’s name, role, recent activity, and even invoice numbers incorporated. By mid-2024 an estimated 40% of BEC phishing emails were AI-generated, and that proportion has continued to grow.

The OAIC recorded 115 social engineering or impersonation breaches in the second half of 2024 alone, out of 595 total breach notifications. Many of those involved credential theft followed by account access. One successful lure often becomes the entry point for a broader compromise: stolen credentials reused across systems, email threads monitored for months, or a single compromised account used to launch attacks on the victim’s clients.

How social engineering attacks play out in Queensland SMEs

At TTA, we see a consistent pattern across Brisbane and South-East Queensland businesses, particularly in professional services, construction, and healthcare. The initial contact is almost always via email. It either impersonates someone the target already knows, or it arrives from a genuinely compromised account belonging to a supplier or business contact.

The request is time-sensitive. Payment needs to go out today. Bank details have changed effective immediately. A staff login needs to be reset urgently before a meeting. The pressure reduces scrutiny. Staff who would normally pause and verify instead act to avoid causing a problem.

What makes these incidents recoverable is early detection. Businesses with clear out-of-band verification steps, such as calling a supplier on a known number before changing payment details, catch the attempt before money leaves the account. Businesses without that habit often find out too late. The AFP has noted that in many BEC cases, victims do not realise they have been defrauded until funds have already moved through multiple accounts, making recovery difficult.

Technical controls matter, but they are the second line of defence here, not the first. Multi-factor authentication (MFA) makes it harder for attackers to use stolen credentials. Email security controls including SPF, DKIM, and DMARC reduce the success rate of domain spoofing. DNS filtering blocks connections to known malicious domains. Managed detection tools can flag unusual login behaviour, such as an account accessing systems from an unexpected location at an unusual hour. But none of these replace the human habit of pausing to verify before acting.

What a practical defence looks like for a small business

Defending against social engineering attacks does not require a large budget. It requires consistent habits and a small set of well-configured controls. For most Queensland SMEs, the starting point is:

  • Enable MFA on every account, especially email and any system that handles financial data or client records.
  • Set a standing rule: any change to payment details must be verified by phone, using a number already on file, not the number in the email.
  • Configure email authentication (SPF, DKIM, DMARC) to make domain spoofing harder.
  • Run short, regular security awareness sessions focused on real examples, not annual checkbox training.
  • Establish a clear, blame-free process for staff to report suspicious messages without delay.

The ACSC’s Small Business Cyber Security Guide covers these foundations in plain language. The Essential Eight framework from the ACSC also addresses several controls directly relevant to social engineering, including MFA requirements, application hardening, and patching. For professional services firms, IT support built around your industry can help put those controls in place without disrupting day-to-day operations.

If you have experienced a suspected social engineering attempt, the ACSC guidance is clear: do not engage further, do not delete the communication, and report it to your IT team immediately. Preserving the message supports any later investigation.

Frequently asked questions about social engineering attacks

What is a social engineering attack in simple terms?

A social engineering attack is when a criminal manipulates a person into doing something that helps the attacker, such as handing over a password, approving a fraudulent payment, or clicking a malicious link. The attack targets human behaviour rather than software vulnerabilities. The attacker typically uses urgency, authority, or familiarity to make the target act before they stop to verify.

Is phishing the same as social engineering?

Phishing is one type of social engineering. Social engineering is the broader category, covering all techniques that manipulate people rather than systems. It includes phishing (email-based lures), vishing (voice calls), smishing (SMS), pretexting (fabricated backstories), and business email compromise. Phishing is the most reported form in Australia, appearing in 60% of incidents reported to the ACSC in FY2024-25.

Who is most at risk from social engineering attacks in Australia?

Any business can be targeted, but attackers prioritise people with access to money, credentials, or sensitive data. Finance staff, executives, and anyone who approves payments or manages IT access are common targets. The ACSC notes that attackers also cast wide nets, contacting as many staff as possible in the hope that at least one attempt succeeds. Small businesses in professional services, construction, and healthcare are frequently targeted.

Can multi-factor authentication stop social engineering?

MFA significantly raises the cost of an attack by making stolen passwords less useful on their own. However, it does not stop all social engineering. Attackers can use real-time phishing kits to intercept MFA codes, or use vishing to convince a target to approve an MFA prompt themselves. MFA is an essential control, but it works best when combined with staff awareness and verified payment processes.

What should a business do immediately after a suspected social engineering attack?

Stop the interaction, do not delete the communication, and contact your IT team straight away. If a payment may have been redirected, contact your bank immediately as a fast response can sometimes recover funds before they are moved further. Report the incident to the ACSC via ReportCyber. If personal information was accessed, assess whether the incident triggers notification obligations under the Privacy Act’s Notifiable Data Breaches scheme.

Where do we go from here?

Social engineering attacks are preventable with the right mix of habits, training, and technical controls. If you want to know where your business stands, our team can walk you through a practical assessment. Get in touch with TTA to start the conversation.

Get tech tips

Stay up-to-date with the latest in tech for small and medium business.
Subscribe to our newsletter and get tips and monthly updates.