Hi Agent... The reason why they call it social engineering is because they don't always have to tell any lies. All they have to do is pretend they need help accessing some system. Many people tend to assume things and are willing to help even a total stranger who turns up at the office and says he needs access to one of the system and thus needs a password.
He's in the office so he's either an unknown collegue or some outside advisor and not everyone tends to question them why they need access. There's a job that needs to be done and they don't want to waste time on "formalities"...
"Hi, I am new here and need to access system X. Do you happen to know the password?" is a short and very true statement for such a person. It's not a lie, but he knows the other will assume he's a collegue or some hired help.
Do you know how many laptops get stolen from offices? Some stranger just walks inside with the other employees trying to avoid any security checks. They just look around for an abandoned laptop and once they find one, they take it and walk outside again, with the laptop. And it might take days before someone realises that the laptop isn't stored in some safe place but actually got stolen. Maybe even longer.
Kevin Poulsen? :)
