GCSE · Computer Science · AQA · Spec 8525

Blagging (pretexting)

You've got a brilliant password. Then the phone rings: “IT support here. It's urgent, I need your password.” Do you hand it over? Let's walk that call.

Computer Science · Social engineering

Take the call: where does it end?

Start at the call, then pick a branch at each fork to see where this call ends.

Identity check → Disclosure policy → Access

  • A trusted role and a bit of pressure, all invented. What happens next depends on what you and your organisation have in place.

4 possible endings to the call.

On The call: “Hi, IT support here. Your account's been flagged and I need your password right now.”. 2 branches to choose from.

You're the employee who picks up the phone. At each fork, choose what happens and watch the route change.

Exam line: Same story, different endings. The protections your organisation puts in place decide which one you get.

Pin the definition

So what actually is blagging?

A friend hears the word “blagging” in your lesson and says: “Oh, that's just hacking into computers, isn't it?”

Which idea is closest to what you think blagging is?
How sure are you?

Take the story apart

What is each line doing?

Someone phones claiming to be from your bank. For each line, pick the job it is doing in the blag.

Still to sort

Posing as someone trusted or obeyed (0)

Who the caller says they are

Where the line is: This is the claimed role itself. A line that leans on someone else's approval to shut down your checking belongs under pressure.

Background detail (0)

Facts gathered earlier so the story sounds genuine

Where the line is: A detail only does this job if it makes the caller sound genuine. It doesn't ask for anything yet.

Urgency or authority (0)

Pushes the victim not to stop and check

Where the line is: Look for time running out, or someone senior supposedly already approving it.

The request itself (0)

What the attacker actually wants

Where the line is: Every other line exists to make this one feel safe to answer.

6 of 6 still to sort.

Here's one invented call, cut into lines. Decide what job each line does for the attacker.

Why it works

?

Reason it through

Why can a blag get past a strong password?

Link 1 of 4

First link · your turn

What does the pretext borrow before the caller asks for anything?

2
Locked — reveal the link above first
3
Locked — reveal the link above first
4
Locked — reveal the link above first

Your turn to write

Protect the organisation

Explain how an organisation can protect itself against blagging, and why each measure helps. [4 marks]

0 words · your answer stays on this page and is not sent anywhere.

WHAT YOU'VE LEARNED

A quick recap of today's lesson.

How a made-up story gets past a strong password, and the checks that stop it

What you need to know

  • Social engineering means tricking people, not machines, into giving up confidential information or access.
  • Blagging, also called pretexting, is social engineering using a believable invented story: the pretext.
  • Have a goYour mate says: “Blagging is basically hacking, just with a phone.” They sound very sure. What have they missed?

    Blagging targets a person with an invented story. It doesn't break the computer's defences.

    Social engineering manipulates people rather than breaking technical defences, so the person is the target, not the technology.

  • The blagger usually pretends to be someone you'd trust or obey, like a colleague, manager, tech support or a bank employee.
  • Blaggers often gather background details first, then add urgency or authority so the victim doesn't stop to check.
  • It works because people want to help and trust a legitimate-looking request, so it can bypass technical security.
  • Have a goA company has an excellent password system. Can a blagger still get past it? Answer in one line.

    Yes. They persuade a person to reveal the password, so the system is never attacked.

    Blagging targets the person, so a strong password is useless if someone is talked into giving it away.

  • A successful blag can lead to data disclosure, unauthorised access, identity theft and financial loss.
  • Defence one: verify who's asking through a separate trusted channel, such as calling back on a known number.
  • Have a goA caller says: “Don't bother ringing back, there's no time!” What should that make you more or less likely to do?

    More likely to check, using a number you already know.

    Urgency is often added so the victim doesn't stop to check, and a callback on a known number tests the story.

  • Defence two: a policy that staff never disclose passwords or sensitive data on request.
  • Training helps people recognise pretexts and pressure tactics.
  • Limiting what each person can access means one deceived person reveals less.

The big picture

Blagging (pretexting) is social engineering: the attacker invents a believable story to talk a person into handing over information or access, so technical security can be bypassed. Checking identity through a separate trusted channel, no-disclosure policies, staff training and limited access stop a blag or limit the damage.

Key points

1Blagging (pretexting) is a form of social engineering: an invented, believable scenario used to persuade a person to hand over information or carry out an action.
2It attacks the person, not the technology, so a strong password is useless if a person is talked into revealing it.
3A pretext usually borrows a trusted or obeyed identity, often uses gathered background details, and frequently adds urgency or authority.
4Protections: verify identity through a separate trusted channel, no-disclosure policies, staff training and limited access.
5A successful blag can lead to disclosure of personal or confidential data, unauthorised access, identity theft and financial loss.

Worked example

Problem

Someone in a hi-vis jacket tells a school receptionist: “IT support, I'm already late for my next site. Just let me into the server cupboard, it'll take two minutes.” The school has no routine for checking visitors. What should the receptionist do, and why?

⚠ Watch out

Treating a callback as optional because the caller sounds convincing or in a hurry. Pressure not to check is exactly what a pretext often adds, so the check matters most then.

🧠

Memory hook

A blagger doesn't pick the lock. They talk someone into opening the door.

✓

Check yourself

Cover the page. A caller says they're from IT support, it's urgent, and they need your password. Say what makes this a blag, and name one thing that would stop it.

Flashcards

(11)
What is social engineering?
Using deception to manipulate people, rather than to break technical defences, so they give away confidential information or grant access.
What is blagging, and what is the 'pretext'?
Blagging (pretexting) is social engineering where the attacker invents a believable scenario, the pretext, to persuade the victim to hand over information or carry out an action.
Who does a blagger usually pretend to be?
Someone the victim would trust or obey, for example a colleague, a manager, technical support staff or a bank employee.
Why do blaggers often gather background details and add urgency or authority?
Details make the story sound genuine. Urgency or authority makes the victim less likely to stop and check.
Which human traits does blagging exploit?
Trust, helpfulness and fear, including people's willingness to help with an apparently legitimate request.
Why can a blag beat a strong password?
A person is talked into revealing it, so the attacker never has to break it.
Name some possible consequences of a successful blag.
Disclosure of personal or confidential data, unauthorised access to accounts or systems, identity theft and financial loss.
A caller you can't verify says there's no time to ring back. Where should the check happen?
Through a separate trusted channel, for example calling back on a number you already know.
What should a no-disclosure policy say?
That staff never disclose passwords or sensitive data on request, and that the organisation will never ask for them.
How does staff training help against blagging?
It teaches people to recognise pretexts and pressure tactics.
What does limiting each person's access achieve?
If one person is deceived, they can reveal less.

Tap any card to flip it, or use Study as deck to go through them one at a time. In the full lesson these run as a spaced-repetition deck — you rate each card Hard, Good or Easy and the tricky ones keep coming back until they stick.

Learning with Lightbulb is opening soon

You can use this lesson now. Join the waitlist and we'll let you know when the full Lightbulb experience is ready.

Keep me posted

More AQA GCSE Computer Science topics

See the full AQA Computer Science curriculum →

How this lesson was checked. This AQA GCSE Computer Science (specification 8525)lesson was published through Lightbulb Learning's human-designed editorial process — the educational standards, accuracy rules and publication checks it must pass were authored and approved by Philip Halpin. It passed subject-specific assessment, automated educational checks and technical publication verification before going live (publication checks completed 9 October 2026). Published pages are monitored, human spot-checking is ongoing across the lesson library, and anything found wrong is corrected or withdrawn. How our lessons are made and checked. Spotted a mistake? Email hello@lightbulblearning.co and we'll review it.