Social Engineering

Social Engineering: Definition & Defense

Social engineering is the manipulation of people, rather than systems, into revealing information or taking actions that benefit an attacker. Instead of breaking through technical defenses, the bad actor exploits trust, urgency, authority, and confusion. Phishing emails, fraudulent support calls, and impersonation scams are all social engineering.

Common Social Engineering Techniques

The channels vary, the psychology doesn’t. Phishing works through email, smishing through text messages, and vishing through phone calls, with spear phishing tailoring the lure to a specific person. Other forms include pretexting (inventing a scenario, like posing as IT support), baiting, and impersonating executives or vendors to redirect payments. Visa’s Spring 2026 threats report found that as network security strengthens, criminals are accelerating their shift to AI-enabled social engineering, identifying nearly $1 billion in scam activity in the second half of 2025 and naming scams the single largest category of consumer payment fraud.

Why It Matters for Commerce Brands

Social engineering hits stores from three directions. Shoppers get phished, and their stolen credentials come back as account takeover and payment fraud. Support teams get manipulated, pressured into refunds, credits, and policy exceptions by scripted claims and manufactured urgency. And employees get targeted directly for access to systems and data. The support channel deserves special attention: refund abuse rings openly coach members on what to say to agents to trigger payouts.

How to Defend Against Social Engineering

Training helps, but process beats vigilance: verification steps that don’t depend on the judgment of one person under pressure, callback procedures for sensitive changes, limits on what support agents can grant without secondary checks, and monitoring for the account changes that follow a successful scam, such as new devices, changed addresses, and drained stored value. Give agents risk context at the moment of the conversation, not after.

How Wyllo Helps

The support conversation is where social engineering gets monetized, and it’s where Wyllo puts intelligence. Wyllo CX Support embeds risk scores and next best actions inside the CX tools agents already use, so a scripted refund claim meets an agent who can see the claim history behind it. Wyllo Claim and Policy Abuse Prevention catches the abuse pattern upstream, before the escalation.

Frequently Asked Questions

What is the most common form of social engineering?

Phishing remains the highest volume vector, but AI has narrowed the quality gap across channels: voice cloning for vishing, flawless copy for email, and convincing fake profiles for impersonation are all cheaply available to bad actors.

How do fraudsters socially engineer support teams?

With scripts. Common plays include claiming an item never arrived, manufacturing urgency around a “gift,” escalating politely but persistently until a goodwill credit appears, and splitting one scheme across several agents so no single conversation looks abnormal.

Can technology stop social engineering?

Not the persuasion itself, but its outcomes. Risk signals catch the account behavior that follows a successful scam, and agent-facing intelligence removes the information asymmetry the scammer relies on.

Related Glossary Categories

Install Wyllo

Select your ecommerce platform to start your free two-week trial.​

See Wyllo in Action

Contact the Wyllo team and we’ll be in touch within one business day to schedule your personalized demo. 

Let's find those
bad actors.

Contact the Wyllo team and we’ll review your system together to identify the bad actors.