Most phishing emails ask for something once and hope for a click. Pretexting is patient. It builds a relationship, a role, a plausible reason to be trusted, before it ever asks for anything at all. That patience is exactly why the 2026 Verizon Data Breach Investigations Report, the most widely cited annual breach analysis in the industry, gave pretexting its own dedicated category for the first time this year, separate from ordinary phishing.
This guide explains what pretexting actually is, how it technically differs from phishing, why it has become a documented precursor to ransomware attacks, and what organizations can do about it.
In Short: Pretexting is a social engineering technique where an attacker fabricates a believable scenario, often over a phone call or in a real-time conversation, to build trust with a target before making a request. Unlike a typical phishing email, pretexting usually happens in real time, which is exactly what makes it harder to catch and increasingly common as a first step toward ransomware.
What Is Pretexting?
Pretexting is a social engineering technique in which an attacker builds trust through a fabricated scenario, delivered by phone, email, text, or in person, to persuade a target into divulging sensitive information or taking a harmful action. The defining feature is the story itself: a plausible role, relationship, or reason that gives the interaction credibility before any request is made.
A pretexting attempt might involve someone posing as an IT help desk technician resolving a login issue, a vendor confirming updated payment details, or a new colleague asking for a quick favor while they get set up. What makes it effective is not urgency or fear, the emotional levers most phishing relies on, but the opposite: patience, plausibility, and the slow construction of trust.
Pretexting Just Became Its Own Attack Vector
For years, pretexting was treated as a supporting tactic inside broader phishing or social engineering statistics. That changed with the 2026 Verizon Data Breach Investigations Report. According to Help Net Security’s coverage of the report’s findings, pretexting has become a more common initial access vector specifically for ransomware and extortion attacks, prompting Verizon to track it as its own distinct category for the first time in the report’s 19-year history.
This is a meaningful shift. Verizon’s report, based on analysis of more than 31,000 real-world security incidents and over 22,000 confirmed breaches across 145 countries, found the human element present in 62 percent of breaches overall, with social engineering as the third most common breach pattern. Pretexting’s promotion to its own tracked vector, now accounting for roughly 6 percent of breaches on its own, reflects a documented pattern: attackers increasingly use it as the opening move in campaigns that end in ransomware, not just as a way to extract a single piece of information.
Pretexting vs Phishing: The Real Difference
The two terms get used almost interchangeably, but there is a precise technical distinction worth understanding. Phishing is generally asynchronous: an attacker sends a message and waits to see who responds. Pretexting is generally synchronous: it happens in a real-time interaction, where the attacker adapts the conversation as it unfolds.
This distinction has a practical consequence that surprises many people: a phone call using a fabricated identity, including many vishing attempts, is technically classified as pretexting in the industry-standard VERIS incident taxonomy Verizon’s report uses, not as phishing, even though most people would casually call it phishing. The label matters less than the underlying implication: real-time, adaptive social engineering behaves differently than a static email template, and defenses built only around spotting a suspicious email will not necessarily catch a live, adaptive conversation.

How AI Is Changing Pretexting
Generative AI has changed what a pretexting attempt requires to succeed. According to Proofpoint threat researcher Sarah Sabotka, quoted in Dark Reading’s coverage of the DBIR’s healthcare findings, generative AI now enables threat actors to construct more precise pretexting scenarios and higher-quality lures than were previously practical at scale. In healthcare specifically, pretexting reportedly jumped to the second most common social engineering tactic in the 2026 data, directly behind phishing, after not appearing among top techniques in the two prior years of the report.
The core skill pretexting has always required, constructing a believable backstory, used to limit how many attackers could execute it convincingly and how many targets a single attacker could realistically pursue. AI tooling reduces both constraints, generating plausible scenarios faster and helping attackers adapt them in real time during a live conversation.
What a Pretexting Attempt Actually Requires
Unlike a mass phishing email blast, pretexting campaigns require real preparation before a target is ever contacted: research into the organization, a constructed persona, and a plausible narrative that will hold up under a real-time conversation. This preparation phase overlaps significantly with the reconnaissance process covered in our guide on how attackers research targets before a spear phishing campaign, since the same publicly available information used to personalize a spear phishing email is often what makes a pretexting scenario believable in the first place.
Common pretexting scenarios organizations should be aware of include:
Help desk impersonation, where an attacker poses as IT support to convince an employee to reset a password, approve an MFA request, or install remote access software.
Vendor impersonation, where an attacker builds a relationship over time, often across multiple interactions, before requesting a change to payment or banking details.
New employee or new vendor pretexts, exploiting the reasonable uncertainty employees have about unfamiliar colleagues or business relationships during onboarding periods.
Authority impersonation, where an attacker poses as an executive or senior figure, closely related to the whaling attacks and why executives need different phishing training.
Why Organizations Should Take This Seriously
Pretexting’s promotion to a dedicated, tracked attack vector in the industry’s most cited breach report is a signal, not just a statistical curiosity. It reflects real, documented cases where a patient, well-researched, real-time social engineering attempt served as the opening move in a ransomware or extortion incident, not a standalone information-gathering exercise.
A few practical implications follow:
Real-time interactions need the same scrutiny as suspicious emails. A phone call, a video meeting, or an in-person interaction can carry the same risk as a phishing email, even though it feels categorically different to the person experiencing it.
Verification needs to work in synchronous situations, not just asynchronous ones. A policy of “verify before clicking a link” does not automatically translate into “verify before trusting a caller,” and training needs to explicitly cover both.
Preparation happens before contact, which means detection can too. Since pretexting requires research and infrastructure ahead of time, organizations that monitor for early signals, such as unusual reconnaissance activity, have a window that purely reactive, post-contact defenses do not.
Testing and Training Against Pretexting
Because pretexting succeeds through patient, adaptive, real-time interaction rather than a static email template, testing for it benefits from scenarios that go beyond a standard phishing email. Running realistic pretexting scenarios, including phone-based and help-desk-style pretexts, through a phishing test for employees shows whether your team applies the same verification instinct to a live conversation that they would to a suspicious email. Tracking this alongside other social engineering channels feeds into a more complete employee phishing risk score, since an employee who is cautious with email but readily trusts a well-constructed phone call represents a real, measurable gap that email-only testing would miss.
Final Thoughts
Pretexting earned its own line in the industry’s most cited breach report because attackers have found something training programs built around suspicious emails were never designed to catch: a patient, believable, real-time conversation. As generative AI continues lowering the skill and time required to construct a convincing pretext, organizations that only train employees to inspect emails are defending against an increasingly smaller share of how these attacks actually begin.
FAQ
What is pretexting in cybersecurity?
Pretexting is a social engineering technique where an attacker fabricates a believable scenario, often delivered through a real-time phone call or conversation, to build trust with a target before making a request for sensitive information or access.
How is pretexting different from phishing?
Phishing is generally asynchronous, an attacker sends a message and waits for a response. Pretexting is generally synchronous, happening in a real-time interaction the attacker can adapt as it unfolds. Many phone-based social engineering attempts are technically classified as pretexting rather than phishing in the industry-standard VERIS taxonomy.
Why did Verizon add pretexting as its own attack vector in 2026?
The 2026 Verizon Data Breach Investigations Report found pretexting had become a common initial access vector specifically for ransomware and extortion attacks, warranting its own tracked category for the first time in the report’s history.
How has AI changed pretexting attacks?
Generative AI allows attackers to construct more precise, believable pretexting scenarios and adapt them faster during real-time conversations, reducing the skill and time previously required to execute a convincing pretext at scale.
Can organizations test employees against pretexting attacks?
Yes. Effective testing includes realistic, real-time scenarios such as phone-based or help-desk-style pretexts, not just email-based phishing templates, since pretexting exploits a different kind of trust than a static message does.
Final CTA
Pretexting succeeds in real time, which means training needs to prepare employees for real conversations, not just suspicious emails. See how realistic phishing simulation covers this with a free PhishCare demo account, no credit card required.
Content Reviewed By

Nawaz is a practising security analyst specializing in phishing simulation campaigns, employee awareness assessments, red team exercises, and ethical hacking.
He leads phishing simulation deployments at PhishCare, a product developed by CyberSapiens, with hands-on experience evaluating and deploying phishing simulation tools across organizations in multiple industries and regions globally.
View LinkedIn Profile







