All social engineering — whether targeting humans or AI — exploits predictable behavioral patterns. Understanding these patterns is the foundation of both attack and defense.
Against Humans
Classic social engineering adapted for call centers. Pretexting, authority exploitation, urgency creation, and emotional manipulation over the phone. Attackers build rapport, create a false sense of trust, and exploit the natural human desire to be helpful. These techniques have been used for decades — long before AI — and remain highly effective because they target fundamental psychological patterns that training alone can't fully eliminate.
Against AI Agents
Prompt injection via voice, jailbreaking through conversation, exploiting tool-calling, and manipulating AI decision boundaries. Unlike humans, AI agents don't get suspicious or feel uncomfortable — they process every input literally. Attackers exploit this by crafting inputs that look like normal conversation but contain hidden instructions, gradually shifting context to override guardrails, or abusing the agent's tools by providing attacker-controlled parameters through natural speech.
Robert Cialdini's six principles of influence are the foundation of persuasion psychology — and they map directly to social engineering tactics. What makes them powerful in a call center context is that the same principles work against both human agents and AI agents, just with different delivery. Toggle between the two to see how each principle is weaponized differently depending on the target.
Beyond Cialdini's principles, social engineers exploit specific cognitive biases — mental shortcuts our brains take that can be weaponized. Recognizing these biases is the first step to defending against them.
Anchoring
The first piece of information we receive dominates our judgment — even if it's irrelevant or fabricated. A social engineer opens with a believable premise ("I'm from IT, we detected a breach at 3:42 AM") and everything that follows is interpreted through that anchor. Even if the target gets suspicious later, the initial framing has already shaped their thinking.
Confirmation Bias
People readily accept information that confirms what they already believe and dismiss what contradicts it. A social engineer who knows the target's company just had layoffs might say "I'm calling about the restructuring" — the target fills in the gaps themselves because it fits their existing narrative, doing much of the attacker's work for them.
Halo Effect
A positive impression in one area spreads to unrelated areas. If someone sounds professional, confident, and uses the right jargon, we unconsciously assume they're also trustworthy and authorized. Social engineers invest heavily in sounding credible — the right tone, vocabulary, and cadence can override logical verification steps.
Automation Bias
Humans over-trust automated systems and computer-generated information. "The system flagged your account" or "Our monitoring tool detected an anomaly" carries more weight than "I think something might be wrong." Social engineers invoke systems and tools to add false authority to their requests.
Curse of Knowledge
Experts assume others share their knowledge, so when someone uses the right technical jargon, we assume they must be legitimate. A social engineer who learns a few internal terms (ticket numbers, system names, department codes) can pass as an insider because real employees can't imagine an outsider knowing those details.
Normalcy Bias
People assume things will continue to work as they always have — that unusual requests must have a normal explanation. When a social engineer asks for something slightly outside procedure, the target's brain defaults to "there must be a good reason" rather than "this is suspicious." This bias is why attacks disguised as routine processes are so effective.