Phishing is a delivery channel: a deceptive message. Pretexting is the fabricated scenario that makes a request believable. Most phishing contains a pretext, but pretexting needs no email at all and frequently runs by phone or in person.
Treating them as alternatives is the common mistake. They sit at different layers. Phishing answers how the message arrived; pretexting answers why the target believed it. A pretext can be delivered by email, phone, video call or a person at a reception desk.
Pretexting also tends to be built before any request is made. The attacker establishes a plausible identity and reason first, so that when the ask comes it fits a story the target has already accepted.
Documented cases
- The Hewlett-Packard boardroom scandal of 2006 cost $14.5M and involved investigators impersonating board members and journalists to phone companies in order to obtain private call records. No phishing email was involved at any point.
- Kevin Mitnick posing as a Novell employee in 1994 obtained NetWare source code entirely by telephone, using an invented internal identity.
- The Clorox and Cognizant breach at $380M is pretexting delivered by phone: the caller was a fabricated employee, and the pretext was a routine lockout.
- This library records 28 pretexting cases against 62 phishing cases, so the pretext layer is present in roughly a sixth of everything documented here as the primary mechanism.
The control that breaks it
- Verify identity through a channel the requester did not choose.
- A pretext survives only as long as the target stays inside the conversation the attacker set up, so any independent check breaks it.
- For help desks and reception, that means an identity-proofing step that does not rely on facts an attacker can research from public sources.
Related