Social engineering attacks are successful because they exploit predictable aspects of human behaviour. One of the most important concepts behind these attacks is cognitive bias. Cognitive biases are patterns in the way people think and make decisions, particularly when under stress, pressure, or emotional influence.
Attackers take advantage of these biases in order to manipulate victims into making poor security decisions. Rather than hacking computer systems directly, social engineers often “hack” human behaviour by exploiting emotions such as fear, trust, urgency, and authority.
Understanding cognitive bias is important because it helps explain why even intelligent and security-aware individuals can still fall victim to phishing and manipulation-based attacks.