Guides

Social Engineering: What to Look Out For

Social engineering is the psychological manipulation of people into performing actions or divulging confidential information. Here is a brief breakdown of the most common attack types and how to recognize them.

G
GEL LLC
3 min read
Social Engineering: What to Look Out For

In the context of information security, social engineering is the psychological manipulation of people into performing actions or divulging confidential information. This differs from social engineering within the social sciences, which does not concern the divulging of confidential information.

A type of confidence trick for the purpose of information gathering, fraud, or system access, it differs from a traditional "con" in that it is often one of many steps in a more complex fraud scheme. At its core, it is "any act that influences a person to take an action that may or may not be in their best interests."

Types of Social Engineering

Smishing

Attackers use mobile phone text messages to deliver the "bait." Smishing attacks typically invite the user to click a link, call a phone number, or contact an email address provided by the attacker via SMS message. The victim is then invited to provide their private data — often, credentials to other websites or services.

Furthermore, due to the nature of mobile browsers, URLs may not be fully displayed, which can make it more difficult to identify an illegitimate login page.

Phishing

Phishing is where an attacker sends a fraudulent ("spoofed") message — usually via email — designed to trick a human victim into revealing sensitive information or to deploy malicious software on the victim's infrastructure, such as ransomware.

Vishing

Vishing is the use of telephony to conduct phishing attacks. Attackers dial a large quantity of telephone numbers and play automated recordings — often made using text-to-speech synthesizers — that make false claims of fraudulent activity on the victim's bank accounts or credit cards. The calling phone number is spoofed to show the real number of the bank or institution being impersonated.

The victim is then directed to call a number controlled by the attackers, which will either automatically prompt them to enter sensitive information to "resolve" the supposed fraud, or connect them to a live person who will attempt to use social engineering to obtain information.

Voice phishing capitalizes on the lower public awareness of techniques such as caller ID spoofing and automated dialing — compared to the equivalents for email phishing — and the inherent trust that many people place in voice telephony.


Awareness is your first line of defense. If something feels off — an unexpected text, a suspicious email, or an unsolicited call asking for credentials — trust your instincts and verify through official channels before taking any action.

Explore Topics

#social engineering#phishing#smishing#vishing#cybersecurity#InfoSec#awareness#fraud
G

Written by

GEL LLC

Content creator and writer sharing insights and stories.