Phishing & Social Engineering

Beginner ~6 min read
Here's a secret the pros know: attackers rarely 'hack' anything — they trick a person into opening the door for them. That person doesn't have to be you. Once you learn the playbook, the tricks start to feel obvious.

Phishing: The Most Common Attack Vector

Phishing is the #1 way attackers gain initial access to systems. It's simple, cheap, and devastatingly effective. Attackers craft convincing fake emails, websites, or messages to steal credentials or install malware.

Types of Phishing

Generic Phishing → Mass emails sent to thousands of random targets (fake PayPal, Netflix, Amazon alerts).

Spear Phishing → Targeted attacks on a specific person. The attacker researches you on LinkedIn, social media, etc. to craft a convincing, personalized message.

Vishing → Voice phishing via phone calls. Attackers impersonate your bank, IRS, or IT support.

Smishing → SMS phishing. Fake text messages with malicious links.

Pretexting

Pretexting means creating a fabricated scenario (a "pretext") to manipulate someone into giving up information. Example: an attacker calls your company's helpdesk pretending to be an IT technician needing access credentials.

Red Flags to Watch For

🚩 Mismatched sender address (support@paypa1.com instead of paypal.com)
🚩 Urgency language: "Act NOW or your account will be DELETED!"
🚩 Suspicious links — hover before you click
🚩 Generic greetings: "Dear Customer" instead of your name
🚩 Unexpected attachments
🚩 Requests for passwords or financial info via email
🚩 Too-good-to-be-true offers
🎯 Key Takeaway

If a message creates urgency, fear, or a too-good-to-be-true offer, slow down and verify through a channel you trust. Attackers rely on you reacting fast — so the fix is simply to pause.

// Knowledge Check