Cyber Academy
Recognising social engineering
Attacks aimed at people rather than software, and the structural signals that give them away regardless of how polished they look.
Social engineering is the practice of getting a person to take an action, rather than getting software to misbehave. It is consistently more effective than technical exploitation because it does not need a vulnerability to exist.
The common shapes
- Authority: a message that appears to come from a manager, a bank, or a government department.
- Scarcity and urgency: a limited window that discourages verification.
- Familiarity: a compromised account belonging to someone you know, used to make an unusual request seem normal.
- Helpfulness: a request for a small favour that escalates once you have engaged.
Defence is procedural, not intuitive
You cannot reliably detect a good attack by feel, because a good attack is designed to feel fine. What works is a rule you follow regardless: any request involving money, credentials, or access gets verified through a channel you chose, using contact details you already had.
In an organisation, make that rule explicit and make it socially acceptable to use. People fall for urgent requests partly because verifying feels like distrust.
Practice task
Work through the Scam Education scenarios. Each one presents a realistic message and asks for your decision before revealing the outcome and the signal you may have missed.