A phishing email and a sales pitch are structurally almost identical: urgency, scarcity, authority, a narrow window to act. One is called an attack. The other is called Tuesday. This episode looks at why social engineering works so reliably, and argues that the answer has less to do with sophisticated criminal innovation than with something much more familiar: the same psychological triggers that legitimate communication has been using on us, constantly, for years. Drawing on Cialdini’s principles of influence, this is a conversation about what we’ve been trained to do and who benefits from that training.
Podcast: Play in new window | Download (Duration: 12:13 — 30.9MB) | Embed
Subscribe: Apple Podcasts | Spotify | Amazon Music | Android | Deezer | Youtube Music | RSS | More
AI Generated Transcript:
Imagine two messages land in your inbox on the same morning. One says: “URGENT: Your account will be suspended in 24 hours unless you verify your details now.” The other says: “Only a few spots left — offer ends tonight.” One of these gets flagged by your spam filter, maybe reported, maybe used as an example in a cybersecurity training next quarter. The other gets… clicked. Forwarded. Sometimes even appreciated — “good marketing.” And if you put them side by side, strip away the branding, and just look at the structure of what each message is doing to your decision-making — they’re almost identical. Urgency. Scarcity. A narrow window to act. A cost to not acting right now. One of these is called an attack. The other is called a Tuesday.
I’m Andrei Barburas, and this is The Unlearning Project — a podcast from barburas.com, where every couple of weeks we take one assumption that usually goes unexamined and we crack it open. Today’s assumption is about social engineering — the idea that it’s a technical security problem, something that exists in a separate category from the persuasion techniques we encounter constantly, in completely legitimate contexts, every single day. It isn’t a separate category. Social engineering isn’t a sophisticated criminal innovation that exploits some unusual flaw in human psychology. It’s an application of psychological mechanisms that are already fully normalized, already trained into us, by everything else around us that wants our attention, our trust, or our money.
Let’s start with where this idea comes from, because it has a name and a fairly well-documented history: Robert Cialdini’s work on the principles of influence. Cialdini, a psychologist, spent years studying what actually moves people to say “yes” — not in laboratory abstractions, but in real-world sales, marketing, and persuasion contexts. And what he found was a relatively small set of psychological triggers that show up again and again, across wildly different situations, because they tap into decision-making shortcuts that are, for the most part, genuinely useful in everyday life.
Things like: scarcity — if something is rare or running out, it must be more valuable, so act now. Authority — if someone with relevant credentials or position says something, it’s probably reliable, so I don’t need to verify it myself. Social proof — if other people are doing this, it’s probably safe or correct, so I’ll follow along. Reciprocity — if someone does something for me, I feel an obligation to do something back. Commitment and consistency — once I’ve said yes to something small, I’m more likely to say yes to something bigger that follows from it, because backing out would feel inconsistent with who I just said I was.
None of these are flaws, exactly. They’re shortcuts — and shortcuts exist because, most of the time, they work. If something is scarce, it usually genuinely is more valuable. If someone has relevant authority, their judgment usually genuinely is more reliable than a stranger’s. These mechanisms evolved, or were learned, because in the vast majority of everyday situations, they produce reasonably good outcomes with minimal effort. The problem isn’t the shortcut. The problem is that the shortcut doesn’t actually check why a particular situation is triggering it. It just responds to the trigger.
And this is exactly what both marketing and social engineering exploit — the same triggers, often using nearly identical structures, for very different purposes. The phishing email that says “your account will be suspended” is using urgency and authority — it’s positioning itself as an official, time-bound message from an institution you trust, designed to short-circuit the part of your thinking that would normally pause and verify. The “only a few spots left” marketing email is using scarcity and urgency in exactly the same structural way — designed to short-circuit the part of your thinking that would normally pause and compare, research, or simply wait.
The difference between these two messages isn’t in the mechanism. It’s in the intent behind it, and — this is the part that I think is genuinely underappreciated — in how socially acceptable each one is considered to be. We’ve built an entire cultural and economic infrastructure around the second kind of message. It’s called advertising. It’s a multi-billion-dollar industry. People go to school to learn how to write messages like that more effectively. And the first kind of message is called a crime.
Now, I’m not making an argument that marketing and phishing are morally equivalent — they’re clearly not, and the harms involved are different in kind and severity. But I think there’s something important in noticing that the training we receive — the years of exposure to messages that use urgency, scarcity, authority, social proof, all deployed skillfully and constantly, in completely normalized contexts — doesn’t just fail to protect us from social engineering. It actively primes us for it. Every time one of these triggers works on us in a low-stakes context — and we don’t even necessarily notice it working, because the outcome is just “I bought something I probably would have bought anyway” — it reinforces the underlying pattern: this trigger, followed by this kind of action, is normal.
So when a much higher-stakes version of the exact same trigger shows up — a message from “IT support” saying there’s been unusual activity on your account and you need to verify your credentials immediately — the pattern that gets activated isn’t a new one. It’s the same pattern, the one that’s been exercised, repeatedly, in low-stakes contexts, thousands of times. The brain isn’t encountering an unfamiliar manipulation. It’s encountering a very familiar structure, just with higher stakes and a different sender.
This is part of why security training that focuses purely on “spot the red flags” — bad grammar, suspicious links, mismatched sender addresses — while useful, often misses something deeper. Because the most effective social engineering doesn’t actually rely on those obvious red flags at all. It relies on the same psychological mechanisms that legitimate communications use constantly, which means the “red flag,” structurally, isn’t really a flag at all — it’s a feature that’s been normalized everywhere else.
Let’s get more specific about why this matters in workplace contexts, because this is where the stakes tend to be highest, and where the dynamics get most interesting.
Think about how authority operates inside organizations. There’s an entire, completely legitimate communication culture built around messages that say, in effect, “this is from someone above you, this needs to happen quickly, and questioning it would be inappropriate or costly.” A request from a senior leader, marked urgent, asking for something to be expedited — this happens constantly, and in the vast majority of cases, it’s exactly what it appears to be. The organizational culture trains people to respond to this pattern quickly, without much friction, because friction in response to legitimate urgent requests from legitimate authority has its own costs — looking obstructive, looking like you don’t understand priorities, slowing things down unnecessarily.
Now overlay a social engineering attack onto that exact same pattern — an email that appears to come from a senior leader, marked urgent, requesting a wire transfer or sensitive information, with language that subtly implies questioning it would be inappropriate. This is sometimes called “CEO fraud,” and it remains remarkably effective, not because the emails are technically sophisticated, but because they’re tapping into a pattern of deference and urgency that the organization itself has spent years training into its employees, for entirely legitimate reasons. The attack doesn’t need to teach anyone anything new. It just needs to borrow a pattern that’s already there, fully operational, reinforced daily.
This is where I think the framing of “human error” — which gets used a lot in cybersecurity discussions, often as a kind of explanation for why a breach happened — becomes a bit misleading. It’s not that people are making errors in the sense of failing to apply something they know. It’s that the same psychological mechanisms that make organizations function smoothly — quick deference to authority, response to urgency, trust in social proof, reciprocity — are exactly the mechanisms that, when borrowed by someone with bad intent, produce exactly the outcomes those mechanisms were designed to produce. The system worked. It just worked for the wrong person.
So what does this mean practically — beyond the standard advice to “be careful” and “verify the sender,” which, while true, doesn’t really address the deeper pattern?
I think it means recognizing that the relevant skill isn’t really about spotting attacks. It’s about noticing when one of these triggers — urgency, authority, scarcity, social proof — is doing the deciding for you, regardless of whether the message is legitimate or not. The question worth asking isn’t “does this look like a scam?” The question is “am I about to act quickly because I’ve actually thought this through, or because something about this message is creating a feeling of needing to act quickly?” That distinction holds up regardless of whether the message turns out to be real or fake — because even legitimate urgent requests benefit from a moment of genuine evaluation, rather than an automatic response trained by years of exposure to messages designed to bypass exactly that evaluation.
There’s also something here for anyone thinking about organizational culture more broadly — because a culture that’s built almost entirely around speed, deference, and minimal friction in response to authority and urgency isn’t just operationally efficient. It’s also, structurally, a culture that’s already optimized for social engineering to succeed, the moment someone with bad intent figures out how to speak in the right voice.
Here’s the question I want to leave you with. Think about the last time you acted quickly on something — a message, a request, a deal — because it felt urgent, or because it came from someone whose authority you didn’t question, or because everyone else seemed to be doing it too. Set aside, for a moment, whether that situation turned out fine. And ask instead: what was actually doing the deciding, in that moment — you, or the trigger?
That’s it for this episode of The Unlearning Project. We’ll be back in two weeks with another one. Until then, notice the next time something feels urgent — and ask why.



