Skip to content

Social Engineering Attacks: Considerations for SMBs

Jun 12, 2026

When most people think of someone hacking their business, they picture sophisticated cybercriminals infiltrating the network, breaking password protocols, and penetrating the firewall. Although that can happen, it’s very rare. Instead, social engineering is behind most cyberattacks, from high-profile data breaches at the largest corporations to ransomware and other attacks that many small and middle-market businesses (SMBs) fall victim to each year.

This kind of cyberattack doesn’t take a lot of money or sophisticated equipment to carry out, but the result can be quite costly for businesses. According to the IBM Cost of Data Breach Report 2026, phishing was the most common initial attack vector, at 17% of the breaches studied, resulting in an average breach of $5.3 million. For many attacks, phishing and other forms of social engineering are the start. When end users fall for social engineering attacks, they often divulge login credentials allowing bad actors to gain access to systems to steal sensitive information or deploy other attacks, such as ransomware.

Common Social Engineering Attack Vectors

Hackers can access a company’s sensitive information through a variety of social engineering techniques: faking the identity of an authorized user, guessing login credentials by mining social media profiles, or even boldly walking into the office and sitting down at an unsecured workstation. The three most common methods of trying a social engineering attack on an SMB are:

  1. Email — This indispensable business tool is valuable to would-be hackers, too. Many businesses are working harder to train staff to watch for potentially fraudulent emails, but it’s still an extremely successful attack vector — partly because it’s so easy to make an email appear to be coming from someone other than the true sender.
  2. Telephone — Phone calls are another common tactic. The caller pretends to have a legitimate request for access to systems or information, and if the recipient complies, cybercriminals can gain the data they seek.
  3. Physical access — In this tactic, hackers pretend to belong somewhere, such as a bank, an office, or a restricted-access area like a server room. If it works, they can get into the network using their own equipment or through an unattended workstation (even easier, since it’s probably already logged in). Once in, they’re free to steal, delete, or corrupt data as they like, or to install viruses and malware that infect the system.

These tactics are tried and true; however, bad actors continue to evolve their techniques. Just as organizations have adopted AI and automation to enhance their defenses, the hackers have adopted AI to enhance their social engineering strategies.

Take Arup, a British design and engineering firm, as an example. An employee in Arup’s finance division joined a virtual meeting with other staff members, including the chief financial officer, who ultimately authorized transactions totaling over $25 million. The catch: Everyone in that virtual meeting — except the finance worker — was a deepfake. The bad actors started their attack with a phishing email, inviting the employee to this virtual meeting, and then utilized AI to dupe the individual into sending fraudulent transactions.

This story reminds us we have to remain on our toes. We are in an age when many things may not be as they appear and traditional verification techniques may not work as they once did.

Why Does Social Engineering Work?

Psychology is key to a successful social engineering attack. People don’t want to get in trouble, and they are curious by nature. And in certain industries — such as nonprofit, healthcare, and financial services — organizational culture encourages employees to be helpful. By exploiting these basic human traits, hackers can bypass even the most sophisticated and carefully planned security systems.

For example, a bad actor posing as an IT auditor with an urgent request to test the safety of employee passwords is often successful; nobody wants to be the person who quibbles about protocol, holding up important work that makes the whole company safer. Similarly, an email attachment claiming to offer tantalizing information — the salaries of everyone at the company, perhaps — is nearly irresistible. If the document carries malicious content like a virus or ransomware, just one click can put the entire network at risk.

Prevention Starts with Training and Testing

Individual behavior is what allows hackers in or keeps them out, so when it comes to thwarting social engineering attacks, training and testing are the two most effective prevention strategies.

Social engineering training should focus on educating frontline workers on:

  • How to recognize when something is out of the ordinary
  • How (and when) to report it
  • How to respond

Every business should have a written policy detailing protocols for verifying the identity of callers, email senders, and in-person visitors. For example, if an email contains any red flags at all, recipients should know to contact the IT department using a familiar number or help desk email address — not via a number or link included in the email — to verify that it’s legit (and do this before clicking on links, downloading attachments, or responding to the email).

And don’t only focus on email. Organizations should have protocols for verifying and responding to requests via any medium. Phone-based scams continue to increase. Remember the attack on MGM Resorts back in 2023? That attack started with a phone call. Members of the hacking group Scattered Spider contacted the company’s help desk, impersonating an employee of MGM Resorts. Through the conversation, they were able to get the help desk personnel to provide access to the impersonated employee’s valid login credentials. From there, the hackers were able to further their attack.

It’s also critical that the training includes simulations and practice sessions. After all, it’s one thing to understand the policy in theory, and quite another to react appropriately when it’s happening. The goal is to impart a healthy skepticism in all members of the organization, so that they become comfortable and confident following established procedures in real-world scenarios.

Frequent social engineering testing is another imperative. This allows the company to identify vulnerabilities, whether that’s a particular attack vector (e.g., email requests or a sensitive location that needs more security) or specific individuals who need more training. Those who fail a test need to know that they failed and receive retraining and coaching, until it becomes automatic to follow established procedures before taking any action that could open the door for hackers.

In addition to training and testing, businesses can adopt technology to help stop social engineering attacks. Companies that run their own mail server should implement some type of third-party protection tool that can scan incoming mail for viruses and malware. Some businesses go so far as to forbid attachments completely unless they go through a secure method of transfer, such as a file share platform that ensures the validity of each attachment. And for physical threats, camera systems can send an alert to those responsible for information security when someone enters an area with servers or other sensitive equipment.

The First and Last Line of Cybersecurity Defense

Tools like these can reduce risk, but don’t make the mistake of thinking they’ll provide adequate protection or make up for human error. Cybersecurity experts like to say that in social engineering, your people are your first and last line of defense. Training and testing (and retraining, if necessary) really are the keys to preventing a successful social engineering attack.

Cybercrime isn’t going away, but you can mitigate the risks of social engineering with effective training, testing, and tools. Contact the cybersecurity professionals at CRI for help keeping your business safe.

Relevant insights

Join Our Conversation

Subscribe to our e-communications to receive the latest accounting and advisory news and updates impacting you and your business.

This field is for validation purposes and should be left unchanged.

By proceeding, you are agreeing to the terms and conditions in the Carr, Riggs and Ingram Privacy Policy. This form submission acts as your acknowledgment to receive occasional email updates, news and promotions from Carr, Riggs & Ingram.