Threats, attacks & vulnerabilities
Social Engineering
Overview
Social engineering uses manipulation and social norms to gain access to information, a location, or a system that would normally be off-limits.
Key concepts
- Phishing family: phishing, spear phishing, whaling, smishing, vishing
- Deception & physical: pretexting, baiting, tailgating, shoulder surfing, impersonation
How it works
Phishing family (message-based)
| Type | How it targets |
|---|---|
| Phishing | Broad attack using fake emails, messages, or websites to trick many people at once. |
| Spear phishing | Targeted at a specific person, group, or organization — often lower-level roles, to gain trust and basic credentials. |
| Whaling | A spear-phishing attack aimed specifically at executives or other high-value individuals. |
| Smishing | Phishing delivered through text messages/SMS. |
| Vishing | Phishing performed through phone calls, voicemail, or voice messages. |
Deception & physical tactics
| Type | How it works |
|---|---|
| Pretexting | Creating a believable false story or identity to gain information or access. |
| Baiting | Offering something desirable (free software, a reward) to trick someone into an unsafe action. |
| Tailgating | An unauthorized person physically follows an authorized person into a restricted area. |
| Shoulder surfing | Looking at someone else's screen to gain confidential information. |
| Impersonation | Pretending to be a trusted person, employee, organization, or IT support worker. |
Protecting against social engineering
- Verify unexpected requests using a trusted, separate contact method.
- Check email addresses, links, attachments, and urgent language carefully.
- Never share passwords, MFA codes, or confidential information through unexpected communications.
- Report suspicious messages or calls, even if you're not sure.