Pretexting: The Attack That Starts With a Story

    Subscribe to our newsletter

    By submitting this form, you agree to the Allure Security privacy policy.

    Share Article

    Office desk phone showing a suspicious incoming IT helpdesk call, illustrating a pretexting social engineering attack.

    The $100 million MGM Resorts shutdown began with a phone call. No malware. No exploit. Just a convincing story told to the right person.

    On September 10, 2023, someone called the IT helpdesk at MGM Resorts International. The caller identified themselves as an employee, referenced details consistent with the employee’s profile on LinkedIn, and asked for help resetting their multi-factor authentication. The helpdesk agent, trained to assist and under pressure to resolve tickets efficiently, complied. Within hours, the group behind the call, a loosely organized collective of young English-speaking hackers known as Scattered Spider, had moved from that single MFA reset to the MGM domain administrator. Slot machines went dark. Hotel key cards stopped working. The website, mobile app, and online booking systems went offline. MGM’s CEO later confirmed the incident cost the company more than $100 million. The attackers had not exploited a software vulnerability, deployed a zero-day, or bypassed a firewall. They had told a story that the person on the other end of the phone had no reason to disbelieve.

    That story is a pretext: a fabricated scenario, identity, or reason for contact designed to manipulate someone into taking an action they would not otherwise take. Pretexting is the social engineering technique that sits underneath the attacks that dominate the threat landscape in 2026, from the vishing campaigns that CrowdStrike reported doubling in the first half of the year to the business email compromise schemes that the FBI attributed $3.046 billion in losses to in 2025. Where phishing is a delivery mechanism, pretexting is the manipulation itself. The email, the phone call, or the video conference is just the channel. The pretext is the reason the target believes what they are hearing.

    What makes pretexting different

    Most security tools are built to inspect technical artifacts: URLs, attachments, IP addresses, authentication tokens. Pretexting operates below that layer. It targets the judgment of the person receiving the communication rather than the security of the system delivering it. A pretexting attack against a helpdesk does not require a malicious link or a weaponized attachment. It requires the caller to know enough about the organization’s internal systems, terminology, and procedures to sound like someone who belongs.

    The investment required to build a convincing pretext has collapsed. IBM found that attackers can assemble a credible pretexting scenario from social media and public sources in roughly 100 minutes of research. LinkedIn provides organizational charts, reporting relationships, and recent job changes. Corporate websites publish leadership bios, press releases, and event calendars. Earnings calls, investor presentations, and conference recordings provide the speaking patterns and vocabulary that generative AI tools can replicate at scale. The Scattered Spider operators who targeted MGM built their pretext by studying publicly available employee information, the same information any recruiter or business contact would use to initiate a conversation.

    The technique takes several forms depending on the channel and the objective. Helpdesk pretexting, the variant that Scattered Spider scaled, impersonates an employee requesting a routine credential or MFA reset. Vendor pretexting impersonates a supplier to modify payment instructions within an existing business relationship. Authority pretexting impersonates a CEO, CFO, or legal counsel to instruct an employee to act with urgency on a fabricated directive. Technical support pretexting impersonates a bank, SaaS provider, or government agency to convince a customer that their account requires immediate attention. In every variant, the attacker borrows the identity and authority of an institution the target already trusts.

    The Scattered Spider playbook

    The MGM breach was not an isolated incident. It was one execution of a repeatable methodology that Scattered Spider applied across industries and continents.

    Three days before the MGM call, Scattered Spider used the same helpdesk pretexting technique against Caesars Entertainment. The group gained access to driver’s license numbers and Social Security numbers, demanded $30 million in ransom, and reportedly settled for $15 million. The two casino breaches, occurring within the same week and using identical initial access techniques, demonstrated that pretexting could be industrialized: the same script, the same social engineering approach, adapted to the target’s environment and executed by operators fluent enough in English to pass as American employees on a phone call.

    CISA updated its Scattered Spider advisory in July 2025 to document the group’s evolving techniques, noting “more sophisticated social engineering” as a core development. By April 2025, the same methodology had reached UK retail. Scattered Spider operators convinced Marks & Spencer’s IT helpdesk to reset employee credentials, leading to a DragonForce ransomware deployment that forced the suspension of online clothing and home orders. Harrods confirmed attempted unauthorized access the following week. The Co-op disclosed a similar incident days later. Three major UK retailers compromised in two weeks, all through variations of the same pretexting approach.

    The pattern extended to vishing-as-a-service operations documented in the CrowdStrike 2026 Threat Hunting Report, where groups like Cordial Spider and Snarky Spider run pretexting campaigns at scale against retail and hospitality targets. Their operators call employees impersonating IT support, reference specific internal systems and recent changes, and direct victims to credential harvesting pages or remote access tools. CrowdStrike documented one Cordial Spider intrusion that moved from initial vishing contact to data exfiltration in under five minutes. The pretext was constructed before the call began. The execution was automated.

    Why technical controls keep missing it

    The challenge pretexting poses for security teams is structural. The attacker uses legitimate communication channels: a real phone call, a real email address, or a real messaging platform. They request actions that fall within the target’s normal responsibilities: resetting a password, updating payment details, processing a wire transfer, approving a document. The credentials they obtain through the interaction are genuine. The access they gain after the interaction is authenticated.

    Email security tools analyze message content for malicious indicators, but a pretexting email from a free Gmail account impersonating a CEO contains no malicious URL, no weaponized attachment, and no technical payload. Helpdesk ticketing systems log the interaction as a routine service request. Identity and access management platforms see a successful authentication event following an approved credential reset. The compromise is invisible to every tool in the stack because the attack never touches the stack. It operates entirely through human interaction, using the organization’s own processes as the attack surface.

    This is why the same pretexting technique continues to work against organizations of every size and sophistication level. MGM had a multi-billion dollar security infrastructure. Marks & Spencer had mature IT operations. The helpdesk agents at both organizations were doing their jobs as trained. The vulnerability was not a misconfiguration or an unpatched system. It was the gap between the urgency of a convincing request and the verification mechanisms available to the person receiving it.

    Why pretexting is a brand problem

    Every pretext borrows someone’s identity. When Scattered Spider called MGM’s helpdesk, they impersonated an MGM employee. When vishing operators call bank customers, they impersonate the bank’s fraud department. When BEC attackers redirect vendor payments, they impersonate the vendor. The pretext always requires a trusted institution whose authority the attacker can borrow, and that institution bears the reputational cost regardless of whether its own systems were compromised.

    For organizations whose brands are commonly used as pretexts, the exposure extends beyond any single incident. Customers who receive a convincing call from someone impersonating the bank’s helpdesk and subsequently lose money associate the experience with the bank, not with the anonymous attacker. Employees who fall for a vishing campaign impersonating their own IT department lose trust in legitimate internal communications. The cumulative effect of pretexting campaigns that borrow a brand’s authority is an erosion of the trust that the brand depends on for every legitimate interaction.

    The infrastructure that supports pretexting campaigns is often visible before the calls begin. Lookalike domains that impersonate the target organization’s email or SSO portals, credential harvesting pages that replicate internal login screens, and spoofed caller ID numbers that match the organization’s published phone numbers all represent detectable assets. The pretext itself is a story told over a phone line. The infrastructure that makes the story actionable, the pages where victims enter credentials, the domains that lend the pretext credibility, operates in digital space where monitoring can identify it.

    The Bottom Line

    Pretexting is the technique that makes the modern threat landscape’s most costly attacks possible. It turned a phone call into a $100 million shutdown at MGM. It enabled $25.6 million in deepfake-assisted wire fraud at Arup. It powered the vishing campaigns that CrowdStrike identified as the fastest-growing initial access vector in 2026. The technique works because it targets human judgment rather than technical infrastructure, and because the defenses designed to stop it, employee training and procedural verification, operate at human speed against attackers who have already rehearsed the conversation. For organizations whose brands are used as pretexts, the defense begins with monitoring the external infrastructure that makes pretexting campaigns operational: the spoofed domains, the harvesting pages, and the fabricated identities that give the story its credibility.

    Key Takeaways

    What is pretexting?

    Pretexting is a social engineering technique in which an attacker fabricates a scenario, identity, or reason for contact to manipulate a target into revealing information, granting access, or performing an action they would not otherwise take. Unlike phishing, which is a delivery mechanism, pretexting is the constructed narrative that makes the delivery persuasive.

    What is the most notable pretexting attack?

    The September 2023 MGM Resorts breach, in which Scattered Spider operators called the IT helpdesk impersonating an employee and convinced an agent to reset MFA credentials. The single phone call led to a complete operational shutdown, with slot machines, key cards, booking systems, and the company website all going offline. MGM confirmed losses exceeding $100 million.

    How does pretexting relate to vishing and BEC?

    Pretexting is the technique that enables both. Vishing campaigns use pretexting to construct the story told during the phone call. BEC schemes use pretexting to create the scenario that justifies the wire transfer request. The FBI attributed $3.046 billion in BEC losses in 2025, with pretexting as the underlying manipulation technique in the majority of cases.

    Why don't technical security tools stop pretexting?

    Pretexting operates through legitimate communication channels using requests that fall within normal business procedures. There is no malicious URL to scan, no malware to detect, and no network anomaly to flag. The credentials obtained through pretexting are genuine, and the access they enable is authenticated. The attack targets human judgment rather than technical infrastructure.

    How is pretexting a brand protection issue?

    Every pretext borrows the identity of a trusted institution. When attackers impersonate a bank’s fraud department, a company’s IT helpdesk, or a vendor’s billing team, the impersonated organization bears the reputational cost. Monitoring for the external infrastructure that supports pretexting campaigns, including spoofed domains, credential harvesting pages, and fabricated identities, detects the assets that make pretexting operational.

    Categories:

    See the threats targeting your brand right now

    Get a customized assessment showing active impersonation, phishing infrastructure, and exposed credentials specific to your organization. No commitment required.