Social Engineering

T1684

Technique with 2 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may use social engineering techniques to influence users to take actions that result in unauthorized access, approval of changes, disclosure of sensitive information, or execution of adversary-supplied instructions (i.e., introduction of malicious payloads or software), while minimizing technical indicators.

Adversaries may leverage trust-building methods across multiple channels (e.g., executive, vendor, or help desk scenarios, including AI-enabled voice interactions) to prompt user-authorized actions such as password resets, MFA changes, financial approvals, or the disclosure of sensitive information. Adversaries may also leverage common business communications and workflows such as email, collaboration platforms, voice communications, recruiting processes, help desk interactions, and SaaS consent mechanisms to make malicious requests appear routine and legitimate.

Additionally, adversaries have persuaded victims to take actions through references of current events, harnessing relevant themes to the work role or the organizations mission. For example, adversaries may use scare tactics (i.e., threaten repercussions for non-compliance) or otherwise incite victims’ emotions in order to generate a sense of urgency to take action.

This technique may include common social engineering patterns such as Phishing and Spearphishing Voice, often supported by convincing and targeted narratives.

Detection rules0

Rules on DetectionCode tagged with T1684 or one of its sub-techniques.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Sub-techniques2

IDNameExamples
T1684.001Impersonation21
T1684.002Email Spoofing0

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples1

Groups1

Used byProcedure example
GroupShinyHunters

ShinyHunters has used social engineering to demand payment from victims.

References6

  1. Fortinet Trends 25-26 Open source
    Fortinet. (n.d.). Recent Cyber Attacks & Emerging Cybersecurity Trends. Retrieved April 15, 2026.
  2. Proofpoint TA427 April 2024 Open source
    Lesnewich, G. et al. (2024, April 16). From Social Engineering to DMARC Abuse: TA427’s Art of Information Gathering. Retrieved May 3, 2024.
  3. SE - Hackers Target Workday Open source
    David Jones. (2025, August 19). Hackers target Workday in social engineering attack. Retrieved April 15, 2026.
  4. SE Proofpoint Open source
    Proofpoint. (n.d.). What Is Social Engineering?. Retrieved April 15, 2026.
  5. SE SentinelOne Open source
    SentinelOne. (2023, October 19). Social Engineering Attacks | How to Recognize and Resist The Bait. Retrieved April 15, 2026.
  6. SE SentinelOne 2 Open source
    SentinelOne. (2025, August 19). 15 Types of Social Engineering Attacks. Retrieved April 15, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.