Books, frameworks, research, and tools for understanding social engineering — both the human psychology side and the AI/LLM attack surface. These resources complement the social engineering training module.
Robert Cialdini's six (now seven) principles of influence — the psychological foundation behind most social engineering attacks
Wikipedia overview of voice phishing techniques, history, and countermeasures
Joint CISA/FBI advisory on Scattered Spider, whose signature move is phoning the IT help desk to obtain an MFA reset on a privileged account
Vishing campaign in which callers talked employees into authorizing a malicious connected app — access that never re-prompts for MFA
Vishing operation running a live adversary-in-the-middle relay during the call, then registering the attacker's own device
Telephone-Oriented Attack Delivery, where the email is deliberately clean so it survives filtering and the payload is the phone call itself
Record $20.9B in reported losses, including the first dedicated AI section (~$893M) covering voice cloning in fraud
FTC fraud data by contact method — the telephone carries the highest median loss per victim (about $1,500)
$3.5B lost to imposter scams in 2025 — the top reported fraud category for the fifth consecutive year
OWASP Top 10 for LLM applications — covers prompt injection, insecure output handling, and other AI-specific attack vectors
Simon Willison's comprehensive overview of prompt injection attacks and why they matter for AI agents
Wikipedia overview of pretexting — creating a fabricated scenario to extract information from a target
MITRE ATT&CK technique documentation for phishing and social engineering reconnaissance
Security awareness training platform with vishing simulations and deepfake training modules
Kevin Mitnick's classic book on how social engineering exploits human trust — essential reading for understanding the attacker mindset