Social engineering is the art of manipulating people into taking actions that benefit an attacker. In 2026 the toolkit has expanded dramatically. Phishing emails remain the most common entry point, but the tactics layered on top — AI-generated voice, real-time deepfake video, multi-channel pressure sequences, and long-game relationship building — have made the attacks harder to detect and the consequences larger.
This post covers the social engineering tactics appearing in NZ incidents, what makes them work psychologically, and the training approaches that build genuine resilience rather than checkbox awareness.
---
The Tactics Appearing in NZ Incidents
Multi-channel pressure sequences. The classic phishing email is now often accompanied by a confirming phone call, a WhatsApp message, or a LinkedIn connection request from the same "person." Each channel adds legitimacy — if the email, the call, and the LinkedIn all say the same thing, it must be real. The attacker builds a consistent false identity across platforms before making the request.
AI-generated voice impersonation. Cloned executive voices in voicemails and live calls are now operationally accessible to mid-tier ransomware and fraud groups. A two-minute sample from a recorded meeting, a podcast, or a social media video is enough. The call sounds exactly like the CEO. The detail on this attack and the controls that stop it are in deepfake CEO fraud.
Help desk and IT support impersonation. The attacker calls an employee pretending to be IT support, creates urgency around a security alert, and walks the employee through "fixing" it — which involves installing remote access software or resetting their MFA. CERT NZ has seen this pattern against NZ businesses, and it bypasses almost all technical controls because it is the user who takes the action.
Relationship-based attacks (long game). An attacker builds a relationship with a target over weeks or months — a LinkedIn connection, shared industry interest, helpful interactions — before making the request. By the time the request arrives, the target has a relationship and a reason to comply. These attacks are rare but high-value, and they target senior people with access to significant assets.
Pretexting via data harvesting. Attackers harvest personal information from data breaches, social media, and public records before making contact. The call or email references real details — the target's manager's name, their last project, their start date — creating false familiarity that triggers trust.
Why Social Engineering Works — The Psychology
Understanding the psychological mechanisms makes the training land better. Social engineering exploits predictable human responses:
Authority. Requests from authority figures — the CEO, the IT department, the regulator — are harder to challenge. Attackers impersonate authority consistently because it works. Training needs to make it safe and normal to verify authority regardless of how the request is framed.
Urgency. Time pressure closes the verification window. "Transfer this today or the deal falls through." "Your account will be locked in 30 minutes." Training needs to reframe urgency as a red flag, not a reason to act.
Social proof. "Everyone else has already done this." "This has been approved by your manager." Fabricated consensus reduces the individual's sense that questioning is appropriate.
Scarcity and fear. "This is your only chance." "Legal will be involved if this is not resolved today." Fear responses bypass rational evaluation. Training that acknowledges this mechanism gives people a frame to step back when they feel it happening.
Reciprocity. An attacker who provides help, shares useful information, or builds a relationship creates a sense of obligation. Long-game attacks exploit this.
Training That Builds Real Resilience
The training approaches that actually change how staff respond to social engineering:
Name the mechanisms. Telling people that phishing exists is less useful than teaching them to recognise urgency, authority, and reciprocity as manipulation levers. When a staff member can name what is happening — "this is creating artificial urgency" — they can step back from the automatic response.
Practice the verification step. The single most valuable behaviour to train is: when something creates pressure or urgency, pause and verify through a separate channel. Practice this in scenario exercises until it becomes automatic. The verify step is the control that stops most social engineering attacks regardless of how sophisticated the pretext is.
Make questioning safe. Staff who fear looking foolish or challenging authority will not use the verify step when they need it most. Training needs to include explicit permission — from managers, from executives — to question and verify. A CEO who publicly says "call my mobile if anyone ever asks you to do something in my name" removes the social obstacle to verification.
Include non-email scenarios. Training that only covers email phishing leaves staff unprepared for phone calls, WhatsApp messages, LinkedIn approaches, and in-person requests. Scenario training should include voice and multi-channel scenarios alongside email.
Use local context. NZ-specific scenarios — IRD impersonation, NZ Police contact, a call from a known bank's fraud team — are more effective than US or UK scenarios because they feel plausible. The phishing training guide covers the principles that apply across all social engineering formats.
The Reporting Culture
The most valuable security outcome from social engineering training is not that staff never click or never respond. Sophisticated attacks will get through. The outcome that matters is that staff report when something feels wrong — before or after they acted on it.
A reporting culture means:
- Staff know who to report to and how to do it without friction
- Reports of suspected social engineering are acknowledged and investigated
- Staff who were deceived are supported, not blamed
- Near-misses are shared with the team so everyone learns
The report rate is the lagging indicator of a healthy security culture. An organisation where staff report suspicious contacts has detection capability. An organisation where suspicious contacts go unreported is flying blind.
Practical Takeaway
- Update awareness training to include voice, multi-channel, and relationship-based attack scenarios
- Teach staff to name the psychological mechanisms — urgency, authority, reciprocity
- Train the verify step as a specific behaviour — separate channel, known contact details
- Make verification culturally safe from the top down — executive endorsement matters
- Include an explicit "if you are ever asked to do anything in my name, call me directly" message from leadership
- Measure report rate alongside click rate — it is the more important metric
- Refresh training every six months — the tactics evolve faster than annual cycles catch
Start your free SecureAZ trial to build social engineering awareness into your training programme with NZ-localised scenarios, phishing simulations, and the human layer that technical controls cannot replace.
External references:
- CERT NZ — Social engineering
- NCSC NZ — ncsc.govt.nz
- Verizon DBIR 2025
- ACSC — Business email compromise and social engineering