Monday, June 22, 2026

Security Boulevard Logo

Security Boulevard

The Home of the Security Bloggers Network

Community Chats Webinars Library
  • Home
    • Cybersecurity News
    • Features
    • Industry Spotlight
    • News Releases
  • Security Creators Network
    • Latest Posts
    • Syndicate Your Blog
    • Write for Security Boulevard
  • Webinars
    • Upcoming Webinars
    • Calendar View
    • On-Demand Webinars
  • Events
    • Upcoming Events
    • On-Demand Events
  • Sponsored Content
  • Chat
    • Security Boulevard Chat
    • Marketing InSecurity Podcast
    • Techstrong.tv Podcast
    • TechstrongTV - Twitch
  • Library
  • Related Sites
    • Techstrong Group
    • Cloud Native Now
    • DevOps.com
    • Security Boulevard
    • Techstrong Research
    • Techstrong TV
    • Techstrong.tv Podcast
    • Techstrong.tv - Twitch
    • Devops Chat
    • DevOps Dozen
    • DevOps TV
  • Media Kit
  • About
    • Sponsor

  • Analytics
  • AppSec
  • CISO
  • Cloud
  • DevOps
  • GRC
  • Identity
  • Incident Response
  • IoT / ICS
  • Threats / Breaches
  • More
    • Blockchain / Digital Currencies
    • Careers
    • Cyberlaw
    • Mobile
    • Social Engineering
  • Humor
Security Bloggers Network Social Engineering 

Home » Cybersecurity » Social Engineering » Concession in Social Engineering

SBN

Concession in Social Engineering

by Social-Engineer on April 23, 2024

You’re sitting at home when you receive a call from a charity you’ve donated to in the past. They explain that they appreciate your previous donation and have been calling your neighbors who have been donating an average of $200. “Oh, I can’t afford that!” you respond. “We understand,” they say, “how about $20?” This, you think, you can do.

Unknowingly, you have just succumbed to a technique we in social engineering refer to as “concession.” What exactly is concession? How is it used? What are ways we can be more aware of concession being used against us? Let’s dive in.

What is Concession?

Concession, or “the act of conceding,” is defined as:

  1. The act or an instance of conceding (as by granting something as a right, accepting something as true, or acknowledging defeat).
  2. The admitting of a point claimed in argument.

How Concession Works

The basics of concession can be broken down into four steps. Once we understand these, we have a better probability of resisting this tactic. So, what are the basics of concession and reciprocity? Let’s look at them from the viewpoint of a malicious actor.

    1. Labeling the concessions. Malicious actors will make concessions to create feelings of indebtedness in their targets. In doing so, the target will have a very hard time, psychologically, ignoring the urge to reciprocate.
    2. Pressure to reciprocate. Now that the concession has been given by the attacker, there is a higher likelihood that the target will feel pressure to reciprocate with a similar act of giving.
    3. Make contingent concessions. These are “risk-free” concessions. These are used when trust is low or when the attacker needs to signal that they are ready to make other concessions.
    4. Make concessions in installments. The idea of reciprocity is deeply ingrained in our minds. Most people feel that if someone does them a favor, they should return that favor. Similarly, if someone is to make a concession, say in a negotiation or bargaining agreement, then the other party will instinctively feel obligated to “budge” a little bit too.

    Example of Concession Process

    As an example of this process, we can think about the famous con man Victor Lustig, he “sold” the Eiffel tower a number of times in his life.

  1. Concession in Social Engineering He used the following process:
    1. Labeling the concession. Once he had a target on the hook, he told them that he would tell them a secret, but they couldn’t share it with anyone else. It was of such high importance that he would concede to telling only them.
    2. Pressure to reciprocate. Once the target heard the secret news (the Eiffel tower was going to be scrapped and the cost of the metal was going to make someone very rich), they felt indebted to continue the discussion further and ask for more information. Many times, the targets would volunteer information like how wealthy they were or how much money they were able to invest.
    3. Make contingent requests. Victor would then make statements alluding to how he can only let a few people into the investment pool, and that he wasn’t sure if it could be them. By using concession aligned with scarcity, he really reeled in the target.
    4. Make concessions in installments. He would continually make concessions through meetings with his targets, until he successfully parted them from a very large sum of their money.

    Clearly a bad actor, but an effective use of concession.

    How Concession is Used

    In addition to the above examples, we see concession tactics used everywhere from telemarketers to car salesmen. They leverage the steps discussed above to entice you to feel like you’re getting a good deal or making a fiscally responsible decision. While good to be aware of, uses of concession are not necessarily malicious. However, concession can absolutely be used maliciously, as seen in the example of Victor Lustig.

    Professionally, vishers can use concession in many ways. For example, let’s say they are using the pretext of a virtual desktop infrastructure (VDI) upgrade. They may say something like “your VDI needs to be updated, but there are multiple ways we can go about this, so it is up to you. I can email you the instructions and you can run the upgrade yourself; it should take about 2 hours. Or I can do it for you.” By giving options, the other person feels like they are in control. Then, by giving one complicated option, and one simple option, they may concede to the simple option because it is so much easier. Now imagine how powerful this would be when leveraged maliciously by a professional social engineer! Clearly, concession tactics are worth learning about.

    Resisting Concession Tactics

    The first thing we need to do in order to resist concession tactics is to be aware of what they are. Reading this article is already the first step! Now that you understand just how concession works, you will be more likely to identify these techniques in real time. What if you can’t consciously identify these techniques, though? Remember to always trust your gut instincts. Often, once we know of something, we can subconsciously identify it even if we can’t quite name what is happening. This is true for social engineering tactics as well, including concession. Knowing this, we can trust ourselves when something feels off during a conversation. Do not be afraid to pause and give yourself a moment to process what is happening. Many times, this is the key to us protecting our information and ourselves from social engineering techniques.

    Stay Secure

    Awareness is the first step in any security program. It is imperative to know and understand the tactics the threat actors will use to social engineer us. Remember to trust your gut instincts and always give yourself a moment to gather your thoughts and check in with your feelings. Being aware of the concession tactic and checking in with yourself will help you to keep you and your information secure.

    Written by Shelby Dacko
    Human Risk Analyst at Social-Engineer, LLC

*** This is a Security Bloggers Network syndicated blog from Security Through Education authored by Social-Engineer. Read the original post at: https://www.social-engineer.org/social-engineering/concession-in-social-engineering/

April 23, 2024April 23, 2024 Social-Engineer General Social Engineer Blog, social engineering
  • ← NVD delays highlight vulnerability management woes: Put malware first
  • Constella Intelligence Enhances Identity Protection in Email Sector Through New Market Focus →

Techstrong TV

Click full-screen to enable volume control
Watch latest episodes and shows

Tech Field Day Events

Upcoming Webinars

True Agentic SecOps at Lakehouse Scale
Agentic Software Delivery in 2026: How To Bridge The Gap Between AI Ambition and Delivery Confidence
Untangling the EU Cyber Resilience Act
The Software Supply Chain Just Got Harder to See
Building a Resilient Security Culture in the AI Era with AWS & Datadog

Podcast

Listen to all of our podcasts

Secure by Design

3 weeks ago | Jack Poller

Senator Sanders Wants to Own AI Companies — and Hand America’s Adversaries the Keys

4 weeks ago | Jack Poller

NIST’s Nine: The PQC Signature Race Moves to Round Three

4 weeks ago | Jack Poller

The Quantum Arms Race: Why Washington Just Wrote a $2 Billion Check to Nine Companies

1 month ago | Jack Poller

Beyond Moore’s Law: The Hyper-Acceleration of Autonomous AI Cyber Capabilities

1 month ago | Jack Poller

The Exception Economy: When Security Teams Stop Protecting and Start Negotiating

Press Releases

GoPlus's Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

GoPlus’s Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

Subscribe to our Newsletters

Most Read on the Boulevard

MSG Breach: Knicks Take the NBA Championship, ShinyHunters Takes the Data 
France to Stop Certifying Products Without Quantum-Safe Encryption in 2027
Google DeepMind Treats Advanced AI as ‘Insider Threats’ in New Cybersecurity Roadmap
NYC Sewers Crawling With Rats and Potential Bad Actors 
Job Seekers Make for Vulnerable Targets
FortiBleed Leak Exposes VPN Credentials for Nearly 74,000 Fortinet Devices
GitHub Locks Down npm: What the New Install Defaults Mean for Your Supply Chain
973 MCP Packages, 71% Single-Maintainer: A Practitioner’s Guide to AI Developer Security
Oracle June 2026 Critical Security Patch Update Addresses 243 CVEs (CVE-2026-35273)
What NIST should know when updating the SSDF for AI

Industry Spotlight

NYC Sewers Crawling With Rats and Potential Bad Actors 
Cybersecurity Featured Industry Spotlight Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threats & Breaches 

NYC Sewers Crawling With Rats and Potential Bad Actors 

June 18, 2026 Teri Robinson | 4 days ago 0
Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks
Cloud Security Cybersecurity Data Privacy Data Security Featured Incident Response Industry Spotlight Malware Mobile Security Network Security News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threats & Breaches Vulnerabilities 

Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks

April 12, 2026 Jeffrey Burt | Apr 12 Comments Off on Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks
The Day the Security Music Died
AI and Machine Learning in Security Cybersecurity Featured Industry Spotlight Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

The Day the Security Music Died

April 8, 2026 Alan Shimel | Apr 08 Comments Off on The Day the Security Music Died

Top Stories

Job Seekers Make for Vulnerable Targets
Cybersecurity Data Privacy Data Security Featured News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

Job Seekers Make for Vulnerable Targets

June 19, 2026 Teri Robinson | 3 days ago 0
MSG Breach: Knicks Take the NBA Championship, ShinyHunters Takes the Data 
Cybersecurity Data Security Featured News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

MSG Breach: Knicks Take the NBA Championship, ShinyHunters Takes the Data 

June 18, 2026 Teri Robinson | 4 days ago 0
Trying to Control AI is Like Holding Sand
AI and Machine Learning in Security Cybersecurity Featured News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

Trying to Control AI is Like Holding Sand

June 17, 2026 Alan Shimel | Jun 17 0

Security Humor

Fortinet® Follies

Fortinet® Follies

Download Free eBook

[su_panel border="0px solid #ddd" radius="0" text_align="center" padding-top="0px" padding-bottom="0px"]
The State of Cloud Native Security 2020
[/su_panel]

Security Boulevard Logo White

DMCA

Join the Community

  • Add your blog to Security Creators Network
  • Write for Security Boulevard
  • Bloggers Meetup and Awards
  • Ask a Question
  • Email: [email protected]

Useful Links

  • About
  • Media Kit
  • Sponsor Info
  • Copyright
  • TOS
  • DMCA Compliance Statement
  • Privacy Policy

Related Sites

  • Techstrong Group
  • Cloud Native Now
  • DevOps.com
  • Digital CxO
  • Techstrong Research
  • Techstrong TV
  • Techstrong.tv Podcast
  • DevOps Chat
  • DevOps Dozen
  • DevOps TV
Powered by Techstrong Group
Copyright © 2026 Techstrong Group Inc. All rights reserved.
×

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.