Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-407 — Pretexting
CAPEC-407

Pretexting

TLP:CLEAR

Description

Typical severity: Low. Likelihood of attack: Medium. An adversary engages in pretexting behavior to solicit information from target persons, or manipulate the target into performing some action that serves the adversary's interests. During a pretexting attack, the adversary creates an invented scenario, assuming an identity or role to persuade a targeted victim to release information or perform some action. It is more than just creating a lie; in some cases it can be creating a whole new identity and then using that identity to manipulate the receipt of information.

Mitigation

An organization should provide regular, robust cybersecurity training to its employees to prevent successful social engineering attacks.

Details

Platforms
Social-engineering
Social-engineering
Software
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.