Social Engineering Attacks in Banking
Social engineering skips the firewall by working on the person who already has access.
Social engineering is getting a person to do the attacker's work: open the door, read out the code, approve the payment. It skips the bank's firewalls entirely because the person being manipulated already has legitimate access. A caller who persuades a branch officer to "urgently" update a customer's registered mobile number has defeated every OTP control on that account without touching a computer.
That is why the syllabus lists it as a modus operandi of its own. Technology controls assume the person at the keyboard is acting freely. Social engineering breaks that assumption.
You save ₹300
- Full 120-question mocks
- Cyber law coverage
- Module-wise practice
One payment, no subscription · Valid for 2 months
The Levers Attackers Pull
Almost every script uses two or three of these at once.
- Authority
- "This is the zonal office" or "This is the cyber police". People comply with rank, especially in hierarchical organisations like banks.
- Urgency
- "Your account will be frozen in 30 minutes." Time pressure stops the victim from checking.
- Fear
- Threats of legal action, account blocking or arrest. The basis of so-called digital arrest scams.
- Greed or reward
- Lottery wins, cashback, a refund that needs "one approval", high-return investment tips.
- Helpfulness
- Staff want to solve a customer's problem. Attackers pose as distressed customers or colleagues locked out of a system.
- Familiarity
- Using real names, branch codes or recent transaction details (often from leaked data) to sound like an insider.
Techniques Beyond the Phishing Message
Pretexting
How it works
A made-up scenario that justifies an unusual request
Banking example
Caller claiming to be from the IT vendor asks a branch user to install a "patch" through remote access
Baiting
How it works
Leaving something tempting that carries malware
Banking example
A USB drive labelled "Salary revision 2026" left in a branch canteen
Quid pro quo
How it works
Offering a service in exchange for access or information
Banking example
Fake "technical support" offering to fix a slow terminal if the user shares login details
Tailgating (piggybacking)
How it works
Following an authorised person through a secured door
Banking example
A visitor walks into the currency chest or server room behind an officer
Shoulder surfing
How it works
Watching someone enter a PIN or password
Banking example
A "helper" at an off-site ATM who watches the PIN being typed
Impersonation of staff
How it works
Posing as a colleague, auditor or vendor in person
Banking example
Someone in a courier's uniform asking to collect cheque books
| Technique | How it works | Banking example |
|---|---|---|
| Pretexting | A made-up scenario that justifies an unusual request | Caller claiming to be from the IT vendor asks a branch user to install a "patch" through remote access |
| Baiting | Leaving something tempting that carries malware | A USB drive labelled "Salary revision 2026" left in a branch canteen |
| Quid pro quo | Offering a service in exchange for access or information | Fake "technical support" offering to fix a slow terminal if the user shares login details |
| Tailgating (piggybacking) | Following an authorised person through a secured door | A visitor walks into the currency chest or server room behind an officer |
| Shoulder surfing | Watching someone enter a PIN or password | A "helper" at an off-site ATM who watches the PIN being typed |
| Impersonation of staff | Posing as a colleague, auditor or vendor in person | Someone in a courier's uniform asking to collect cheque books |
Defences That Work in a Branch
- checkCall back on a number from the bank's own directory before acting on any phoned instruction, however senior the caller sounds
- checkNever change a registered mobile number or email on a phone request; follow the documented in-person or authenticated process
- checkNever plug unknown USB drives into bank systems
- checkBadge access to restricted areas, with staff trained to stop tailgaters politely
- checkShield the keypad when entering PINs, and tell customers to do the same
- checkReport every suspicious approach to the information security team, even when nothing was given away; one report often reveals a campaign
Quick practice on banking operations. No signup.
Where It Sits in Law
Social engineering is a method, not an offence. The charge depends on what it achieved: cheating (BNS section 318) or cheating by personation (BNS section 319, and IT Act section 66D where a phone or computer was used); identity theft (IT Act section 66C) where a password or OTP was misused; or a computer related offence under IT Act section 66 where it led to unauthorised access. A staff member who knowingly helps an outsider get in can face liability under section 43(g) of the IT Act, which covers providing assistance to access a computer system in contravention of the Act.
How the IIBF Exam Tests This
Two kinds of MCQ. First, naming the technique from a scenario: baiting (a planted device), pretexting (a story), tailgating (physical entry). Second, choosing the best control: the answer to social engineering is usually awareness training and verification procedures, not a stronger firewall or encryption. The trap is treating social engineering and phishing as the same thing. Phishing is one form of social engineering; social engineering is the wider category.
FAQs
What is social engineering in cyber security?expand_more
Manipulating people into revealing information or granting access, rather than attacking the technology. It works through authority, urgency, fear or reward.
What is the difference between phishing and social engineering?expand_more
Phishing is one type of social engineering, delivered by email, call or SMS. Social engineering also covers in-person and physical techniques such as pretexting, baiting and tailgating.
What is tailgating in cyber security?expand_more
Following an authorised person into a restricted area, such as a server room, without using your own access. It defeats physical access controls through politeness.
What is the best defence against social engineering?expand_more
Trained, alert staff and firm verification procedures: call back on known numbers, never bypass the documented process for changing customer details, and report every suspicious approach.
Next steps
Take a full IIBF Cyber Crimes mock test120 questions, 2 hours, scored instantly.
