GCSE · Computer Science · AQA · Spec 8525
Blagging (pretexting)
You've got a brilliant password. Then the phone rings: “IT support here. It's urgent, I need your password.” Do you hand it over? Let's walk that call.
Computer Science · Social engineering
Take the call: where does it end?
Start at the call, then pick a branch at each fork to see where this call ends.
Identity check → Disclosure policy → Access
A trusted role and a bit of pressure, all invented. What happens next depends on what you and your organisation have in place.
4 possible endings to the call.
You're the employee who picks up the phone. At each fork, choose what happens and watch the route change.
Take the story apart
What is each line doing?
Someone phones claiming to be from your bank. For each line, pick the job it is doing in the blag.
Still to sort
Posing as someone trusted or obeyed (0)
Who the caller says they are
Where the line is: This is the claimed role itself. A line that leans on someone else's approval to shut down your checking belongs under pressure.
Background detail (0)
Facts gathered earlier so the story sounds genuine
Where the line is: A detail only does this job if it makes the caller sound genuine. It doesn't ask for anything yet.
Urgency or authority (0)
Pushes the victim not to stop and check
Where the line is: Look for time running out, or someone senior supposedly already approving it.
The request itself (0)
What the attacker actually wants
Where the line is: Every other line exists to make this one feel safe to answer.
Here's one invented call, cut into lines. Decide what job each line does for the attacker.
Why it works
Reason it through
Why can a blag get past a strong password?
First link · your turn
What does the pretext borrow before the caller asks for anything?
WHAT YOU'VE LEARNED
A quick recap of today's lesson.
How a made-up story gets past a strong password, and the checks that stop it
What you need to know
- Social engineering means tricking people, not machines, into giving up confidential information or access.
- Blagging, also called pretexting, is social engineering using a believable invented story: the pretext.
Have a goYour mate says: “Blagging is basically hacking, just with a phone.” They sound very sure. What have they missed?
Blagging targets a person with an invented story. It doesn't break the computer's defences.
Social engineering manipulates people rather than breaking technical defences, so the person is the target, not the technology.
- The blagger usually pretends to be someone you'd trust or obey, like a colleague, manager, tech support or a bank employee.
- Blaggers often gather background details first, then add urgency or authority so the victim doesn't stop to check.
- It works because people want to help and trust a legitimate-looking request, so it can bypass technical security.
Have a goA company has an excellent password system. Can a blagger still get past it? Answer in one line.
Yes. They persuade a person to reveal the password, so the system is never attacked.
Blagging targets the person, so a strong password is useless if someone is talked into giving it away.
- A successful blag can lead to data disclosure, unauthorised access, identity theft and financial loss.
- Defence one: verify who's asking through a separate trusted channel, such as calling back on a known number.
Have a goA caller says: “Don't bother ringing back, there's no time!” What should that make you more or less likely to do?
More likely to check, using a number you already know.
Urgency is often added so the victim doesn't stop to check, and a callback on a known number tests the story.
- Defence two: a policy that staff never disclose passwords or sensitive data on request.
- Training helps people recognise pretexts and pressure tactics.
- Limiting what each person can access means one deceived person reveals less.
The big picture
Blagging (pretexting) is social engineering: the attacker invents a believable story to talk a person into handing over information or access, so technical security can be bypassed. Checking identity through a separate trusted channel, no-disclosure policies, staff training and limited access stop a blag or limit the damage.
Key points
Worked example
Problem
Someone in a hi-vis jacket tells a school receptionist: “IT support, I'm already late for my next site. Just let me into the server cupboard, it'll take two minutes.” The school has no routine for checking visitors. What should the receptionist do, and why?
⚠ Watch out
Treating a callback as optional because the caller sounds convincing or in a hurry. Pressure not to check is exactly what a pretext often adds, so the check matters most then.
Memory hook
A blagger doesn't pick the lock. They talk someone into opening the door.
Check yourself
Cover the page. A caller says they're from IT support, it's urgent, and they need your password. Say what makes this a blag, and name one thing that would stop it.
Flashcards
(11)What is social engineering?
What is blagging, and what is the 'pretext'?
Who does a blagger usually pretend to be?
Why do blaggers often gather background details and add urgency or authority?
Which human traits does blagging exploit?
Why can a blag beat a strong password?
Name some possible consequences of a successful blag.
A caller you can't verify says there's no time to ring back. Where should the check happen?
What should a no-disclosure policy say?
How does staff training help against blagging?
What does limiting each person's access achieve?
Tap any card to flip it, or use Study as deck to go through them one at a time. In the full lesson these run as a spaced-repetition deck — you rate each card Hard, Good or Easy and the tricky ones keep coming back until they stick.
Learning with Lightbulb is opening soon
You can use this lesson now. Join the waitlist and we'll let you know when the full Lightbulb experience is ready.
Keep me postedMore AQA GCSE Computer Science topics
How this lesson was checked. This AQA GCSE Computer Science (specification 8525)lesson was published through Lightbulb Learning's human-designed editorial process — the educational standards, accuracy rules and publication checks it must pass were authored and approved by Philip Halpin. It passed subject-specific assessment, automated educational checks and technical publication verification before going live (publication checks completed 9 October 2026). Published pages are monitored, human spot-checking is ongoing across the lesson library, and anything found wrong is corrected or withdrawn. How our lessons are made and checked. Spotted a mistake? Email hello@lightbulblearning.co and we'll review it.