Social engineering cyber security attacks don’t start with code, malware or system vulnerabilities. They start with people, routines and trust.
A fake customer sends a screenshot. A supplier shares a link. A colleague requests urgent approval for an invoice. The request feels familiar, so it often bypasses normal scrutiny.
This is what makes social engineering one of the fastest growing cyber security risks. Attackers are no longer relying on breaking systems. Instead, they are exploiting the way organisations communicate and make decisions under pressure.
As workflows become more digital and interconnected across platforms like Salesforce, SAP and collaboration tools, these attacks are becoming harder to detect and easier to scale. Even well-trained employees can be exposed when malicious content arrives through a trusted channel or expected process.
This shift means organisations need to think beyond awareness and training alone. The risk is not just whether someone can spot a scam, but whether systems can still protect the business when trust is successfully exploited.
A recent DigiCert incident shows exactly how this plays out in practice.
In 2026, DigiCert was reported to have suffered a targeted social engineering attack through its support channel, which was delivered by a Salesforce application.
According to security reporting on the incident, a threat actor posed as a customer and sent a malicious ZIP file disguised as a customer screenshot. Inside the archive was a Windows screensaver executable, commonly known as a .scr file, which carried a malicious payload.
This matters because DigiCert is a major Certificate Authority. Certificate Authorities issue digital certificates that help verify the identity of websites, software publishers and digital services. In simple terms, they are part of the trust infrastructure that helps users and systems decide whether something is legitimate.
A breach involving a brand like DigiCert is especially important because certificates are used to establish trust. If attackers can abuse certificate processes or obtain trusted code signing certificates, malicious software may appear more legitimate to users, operating systems and security tools.
1. An attacker posed as a customer
The request appeared to fit a normal support workflow
2. A malicious file was disguised as a screenshot
The file type helped exploit routine support behaviour.
3. The attack targeted internal support systems
Support teams regularly handle files from external users.
4. Certificate processes were reportedly abused
Trusted infrastructure can be used to make malicious activity look legitimate.
The key lesson is straightforward. Social engineering prevention needs more than training.
A support analyst can be well-trained and still be exposed to risky files as part of their normal job. The better question is: what controls are in place when a convincing, malicious file reaches an employee? For Salesforce, there’s nothing built in natively. If DigiCert had bowbridge Anti-Virus for Salesforce, this breach would never have been able to happen.
This isn’t the only major security breach of the year. Learn more about Salesforce security breaches and their costs.
Social engineering prevention requires a layered approach.
Training helps employees recognise risks, but technical controls are needed to stop malicious links, files and workflows before they cause damage.
Here’s a table of the core measures to take to help prevent social engineering . Learn more about security best practices from a Salesforce perspective.
| Prevention method | Why it matters |
| Security awareness training | Helps employees recognise suspicious behaviour and requests. |
| Multi-factor authentication | Reduces the risk of stolen passwords being enough to gain access. |
| Email and file scanning | Helps detect malicious attachments before they enter the workflow. |
| Access controls | Limits what attackers can reach if one account is compromised. |
| Verification processes | Helps stop fraudulent payment or data requests. |
| Incident reporting routes | Makes it easier for employees to flag concerns quickly. |
| Enterprise security solutions | Adds a failsafe when human judgement is not enough. |
The aim is not to make every employee a cybersecurity expert. The aim is to build a system where employees are supported by processes and technology that reduce the chance of one mistake becoming a serious breach.
One of the biggest risks in social engineering is the no-Multi-Factor-Authentication (MFA) vulnerability.
If an attacker tricks an employee into entering their password into a fake login page, the absence of a second factor can allow immediate account access. That can expose email accounts, customer records, business applications and connected systems.
Microsoft has reported that more than 99.9% of compromised accounts did not have MFA enabled. This makes MFA one of the most important baseline protections against phishing and credential theft.
MFA is not a complete answer. Attackers may still use vishing (voice phishing), MFA fatigue, adversary-in-the-middle phishing or social engineering to trick users into approving access. But without MFA, stolen credentials can become an immediate route into the organisation.
Even with training, MFA and strong security policies, businesses still need protection at the point where risky files, URLs and content enter the organisation.
This is especially important for teams that regularly receive documents, screenshots, ZIP files, customer uploads, supplier attachments or links inside application workflows.
bowbridge helps act as a protective layer between incoming content and business workflows, reducing the chance that malicious files and risky links reach employees in the first place.
Where people can be manipulated, bowbridge helps reduce exposure. By scanning and controlling files before they enter critical workflows, bowbridge gives organisations an additional layer of protection when human error, urgency or trust could otherwise be exploited.
“However strong your training programme is, people will always be vulnerable to social engineering because these attacks are designed to exploit trust, pressure and routine behaviour. That is why organisations need an enterprise security solution that acts as a failsafe. With bowbridge, malicious files like these would not have had the same opportunity to enter the workflow, giving businesses an added layer of protection when human judgement is put under pressure.”
- Jorg Schnedider-Simon, CTO & Co-Founder at bowbridge
Protect yourself with bowbridge Anti-Virus for Salesforce
Social engineering is effective because it takes advantage of normal human behaviour.
People are trained to respond quickly to customers, support colleagues, follow instructions from senior staff and resolve problems without unnecessary delays. Attackers use that instinct against them.
According to the Verizon 2026 Data Breach Investigations Report, 62% of breaches involved the human element. That does not mean employees are careless. It means cybersecurity cannot rely on awareness alone. Businesses need controls that reduce the impact of human error.
| Human trigger | How attackers exploit it |
| Urgency | “This needs to be approved today.” |
| Authority | “The CEO has requested this transfer.” |
| Trust | “I’m from your IT provider.” |
| Curiosity | “Please see the attached screenshot.” |
| Fear | “Your account will be suspended.” |
| Routine | “Here is the updated invoice.” |
The problem is not that people fail to care about security. The problem is that attackers understand how people work, communicate and make decisions under pressure.
That is why social engineering prevention needs to include training, process and technical controls.
AI is making social engineering cyber security attacks more convincing, more personalised and easier to scale.
Attackers can use AI tools to write polished phishing emails, translate scams into different languages, imitate brand tone, summarise stolen information and create more believable pretexts. They can also generate documents, screenshots and support messages that look closer to real workplace communication.
AI can make social engineering scams more dangerous by helping attackers:
This does not change the fundamentals of social engineering. Attackers still rely on trust, pressure and routine. What AI changes is speed, scale and believability.
As scams become harder to spot, businesses need security systems that do not depend entirely on individual judgement.
There are several types of social engineering attacks, and many modern scams combine more than one tactic.
| Type of attack | What it means | Example |
| Phishing | Fraudulent emails designed to steal information or deliver malware | A fake Microsoft 365 login email |
| Spear Phishing | A highly targeted phishing message | An email tailored to a finance manager |
| Vishing | Voice-based social engineering | A fake IT support call asking for access |
| Smishing | SMS-based phishing | A fake delivery text with a malicious link |
| Baiting | Using curiosity or reward to make someone act | A file labelled as a customer screenshot |
| Pretexting | Creating a believable false scenario | Someone pretending to be a supplier or client |
| Business email compromise | Impersonating a trusted sender to trigger payment or data transfer | A fake invoice from a known vendor |
| MFA fatigue | Repeatedly sending MFA prompts until a user approves one | A login push notification attack |
| Malicious file delivery | Sending a harmful attachment disguised as a legitimate file | A ZIP file containing malware |
The most effective social engineering attacks are often the least dramatic. They look like ordinary work.
A support analyst receives a customer file. A finance team receives an invoice. A Salesforce user sees a link inside a case. A service agent opens a customer attachment. The workflow appears trusted, but the content inside it may not be safe.
Use this checklist to reduce the risk of social engineering scams affecting your business.
| Action | Priority |
| Enable MFA across all business accounts | High |
| Train employees on phishing, vishing, smishing and file-based attacks | High |
| Restrict risky file types where possible | High |
| Scan customer and supplier uploads before they reach staff | High |
| Use least-privilege access controls | High |
| Create a clear process for reporting suspicious requests | Medium |
| Review third-party and support workflow risks | Medium |
| Run regular security incident simulations | Medium |
| Keep software and endpoint protection updated | Medium |
| Use an enterprise application content security solution | Critical |
This checklist should not sit in isolation. Social engineering prevention works best when it is connected to everyday workflows.
If customers can upload files, those files need to be scanned. If teams use Salesforce cases, links and attachments, then they need to be checked where users encounter them. If support analysts open customer documents, then content controls should engage before the file reaches the user.
Security should support the way people work, not slow it down.
Social engineering scams continue to evolve because they target the one part of cyber security that will always involve uncertainty: people.
Attackers know how to create pressure, build trust and disguise malicious activity as everyday work. AI is making that easier to do at scale, but the core issue remains the same. Trusted workflows can still carry unsafe content.
The DigiCert screensaver incident is a useful reminder that even trusted brands and experienced teams can be targeted through ordinary support processes. A malicious file does not need to look unusual if it arrives in a context where files are expected.
To protect your organisation, you need a layered approach that combines awareness, MFA, secure processes and enterprise-level protection that can detect and control dangerous content before it reaches your people.
Protect your business from social engineering cyber security risks before attackers trick your people into giving attackers access to your business-critical systems and data.
Speak to bowbridge about enterprise application content security that helps keep harmful files, risky links and sensitive data exposure out of your workflows.