Understanding Phishing and Social Engineering

Understanding Phishing and Social Engineering

Learn how phishing and social engineering manipulate people into revealing information, transferring money or granting access. This practical guide explains common attack methods, warning signs, prevention habits and the right response when something goes wrong.

Cybersecurity is often presented as a technical problem involving firewalls, passwords and software updates. Those controls matter, but many successful attacks begin somewhere less technical: with a message, phone call or conversation designed to influence a person. Phishing and social engineering exploit trust, urgency, fear, curiosity or helpfulness to persuade someone to take an unsafe action.

Understanding these attacks is important for everyone who uses email, mobile money, social media, online banking, workplace systems or cloud services. An attacker does not always need to break through sophisticated security if they can persuade a person to disclose a one-time code, open a harmful file or approve a payment. The aim of this article is to show how these attacks work and how to respond without panic.

What Are Phishing and Social Engineering?

Social engineering is the use of psychological manipulation to influence someone into revealing information, changing a process or performing an action that benefits an attacker. It can happen through digital channels or in person. A caller pretending to be from a bank, a visitor trying to enter a restricted office and a message asking an employee to bypass a normal approval process may all be examples of social engineering.

Phishing is a common form of social engineering carried out through deceptive electronic communication. The attacker may use email, text messages, messaging applications, social media or a fake website. The message often imitates a trusted organisation or person and directs the recipient to click a link, open an attachment, enter login details, make a payment or share a verification code.

The distinction is useful: phishing is usually a specific digital delivery method, while social engineering is the broader manipulation strategy. Other social-engineering techniques include phone-based scams, known as vishing; text-message scams, known as smishing; and impersonation, pretexting or baiting.

Why These Attacks Work

Phishing is not successful merely because people are careless. Attackers design messages to take advantage of normal human behaviour and difficult working conditions. A person may be busy, distracted, worried about a financial problem or trying to respond quickly to a senior colleague. Under pressure, even a cautious user may not inspect a message carefully.

Common psychological triggers include:

  • Urgency: “Your account will be closed today” or “Approve this payment immediately.”
  • Authority: The sender claims to be a manager, bank official, government representative or technology provider.
  • Fear: The recipient is told that suspicious activity, a legal problem or a failed payment requires immediate action.
  • Reward: The message promises a job opportunity, refund, prize, investment return or special offer.
  • Curiosity: A file, photograph or confidential-looking document encourages the recipient to click.
  • Familiarity: The attacker copies a company logo, writing style or name from a known contact.

Attackers may also gather publicly available information before contacting a target. A business website, professional profile or social-media post can reveal job titles, suppliers, travel plans or reporting relationships. This information can make a fraudulent request appear more believable.

Common Types of Phishing

Email phishing

Email phishing is the familiar fake message claiming to come from a bank, delivery service, online platform, employer or colleague. It may contain a link to a counterfeit login page or an attachment containing malicious software. Some messages are sent widely, while others are carefully written for a particular organisation.

Spear phishing

Spear phishing targets a specific individual or organisation. The message may mention the recipient’s name, role, current project or a genuine supplier. Because it contains accurate details, it can be more convincing than a generic scam. Senior managers, finance staff, administrators and people with access to valuable information are common targets, although any employee may be approached.

Business email compromise

In a business email compromise, an attacker impersonates or gains access to a business account and attempts to redirect money, obtain sensitive information or alter payment details. For example, a fraudulent message may appear to come from a director requesting an urgent transfer, or from a supplier announcing a change to its bank account.

The key danger is not simply the message itself but the attempt to bypass normal controls. A legitimate-looking request should still follow the organisation’s approval and verification procedures.

Smishing and vishing

Smishing uses text messages or messaging applications, often claiming that a parcel, mobile account or payment needs attention. Vishing uses a phone call or voice message. The caller may ask for a password, personal identification number, one-time passcode or remote access to a device.

Caller identification is not proof of identity. Phone numbers and sender names can be manipulated, and a genuine organisation should not require customers to disclose confidential authentication information through an unsolicited call.

Fake websites and QR-code phishing

A fake website may closely resemble a real banking, email or social-media login page. The address may contain a misspelling, extra words or an unfamiliar domain. QR codes can also direct users to fraudulent pages, particularly when placed on posters, invoices or messages. A QR code should be treated like a link: inspect the destination and consider whether the request is expected before entering information.

Recognising the Warning Signs

No single warning sign proves that a message is fraudulent. However, several signs together should lead you to pause and verify through a trusted channel.

  • The message creates unusual pressure or threatens immediate consequences.
  • The sender requests a password, one-time code, payment, gift card or confidential document.
  • The email address, phone number or website address is slightly different from the genuine one.
  • The greeting, spelling, tone or formatting seems inconsistent with the supposed sender.
  • A link does not lead to the expected website when you inspect it carefully.
  • An attachment is unexpected, especially a document asking you to enable macros or change security settings.
  • The request changes established procedures, such as asking for a payment to a new account without independent confirmation.
  • The message asks you to keep the request secret or avoid contacting another person.
  • You are offered a benefit that seems unusually easy, valuable or time-sensitive.

Good judgement is more reliable than visual appearance. Logos, signatures and professional formatting can be copied. Treat the action being requested as more important than how polished the message looks.

How to Verify a Suspicious Request

Verification should be independent. Do not use the link, phone number or reply address provided in the suspicious message, because these may be controlled by the attacker.

  1. Pause. Resist the pressure to act immediately. Urgency is often part of the attack.
  2. Identify the request. Is the person asking for a password, money, access, personal data or an unusual change to a process?
  3. Inspect the source. Check the complete email address, telephone number, web address and context. Do not rely only on the displayed name.
  4. Use a trusted route. Contact the organisation through its official website, a known telephone number, a previously verified contact or an established internal directory.
  5. Confirm sensitive actions verbally or through an approved second channel. For a payment change, contact the supplier using details already on file rather than those in the new message.
  6. Report the attempt. Send it to the organisation’s security or information-technology team, bank or relevant platform, following its reporting procedure.

For individuals using mobile money or online banking, never share a personal identification number or one-time passcode with someone who contacts you unexpectedly. If a caller claims there is a problem, end the call and contact the provider using an official channel.

Reducing Risk in Everyday Work

Security habits should make safe behaviour easier, not depend on perfect memory. Use a unique, strong password for every important account and store passwords in a reputable password manager where appropriate. Enable multi-factor authentication, preferably using a method that is resistant to common forms of interception. Multi-factor authentication reduces risk, but it does not make phishing harmless: attackers may still try to trick users into approving a fraudulent sign-in.

Keep operating systems, browsers, applications and security tools updated. Updates often fix weaknesses that attackers could otherwise exploit. Back up important business and personal files, and ensure that backups cannot be easily altered or deleted from the same account as the original files.

For organisations, technical controls should be supported by clear processes. Payment changes should require independent verification, sensitive data should be shared only with authorised recipients, and access should be limited according to a person’s actual role. Staff should know how to report a suspicious message without being embarrassed or punished for raising a concern. A quick report may help protect colleagues who receive the same attack.

Small enterprises in Kenya and elsewhere may not have a dedicated security department. They can still create practical safeguards: maintain a current list of trusted supplier contacts, require two people to approve significant payments, separate payment preparation from payment authorisation, and review account activity regularly. These controls address the business process attackers are trying to manipulate.

What to Do If You Have Responded

If you clicked a suspicious link but did not enter information or open a file, close the page and report the event. If you entered a password, change it immediately from a trusted device and change it anywhere else that password was reused. Enable multi-factor authentication if it is not already active.

If you shared a one-time code, approved a sign-in, transferred money or disclosed financial information, act quickly. Contact the bank, mobile-money provider, employer or affected service through an official channel. Ask what protective steps are available, such as freezing an account, cancelling a transaction or reviewing recent activity. Inform your organisation’s security contact and preserve the suspicious message, web address, call details and transaction records.

If malware may have been installed, disconnect the device from networks where practical and contact a qualified technical support or security team. Do not delete evidence before it has been reviewed if the device is part of a workplace investigation. Be alert for follow-up calls: an attacker may pretend to help you recover the account and use the first incident to gather more information.

Prompt reporting matters because it can limit losses and warn others. Shame and silence usually benefit the attacker. A responsible response focuses on containment, evidence and recovery rather than blame.

Applying This in Practice

Consider this example: a small Nairobi-based business receives an email apparently from a regular supplier. It says the supplier has changed banks and asks the business to use new account details for an invoice due that day. The sender’s name looks correct, and the invoice includes genuine business information.

A safe process would be to pause the payment, compare the sender’s full address with previous correspondence and contact the supplier using the telephone number already stored in the business records. The employee should ask a colleague or manager to review the change and document the verification. If the supplier confirms that no change was requested, the email should be reported and the account details should not be used.

Now consider a personal example: a text message claims that a mobile-money account will be suspended unless the recipient confirms a code through a link. The recipient should not open the link or share the code. They should use the provider’s official application, website or customer-service number to check the account. The message can then be reported and deleted.

These examples demonstrate a general rule: when a request involves money, access or sensitive information, slow down and verify it using a separate trusted route. That brief pause is often more valuable than trying to identify every technical detail of the scam.

Key Takeaways

  • Phishing is a digital form of social engineering that uses deceptive messages to influence unsafe actions.
  • Urgency, authority, fear, rewards and secrecy are common manipulation techniques.
  • Inspect the complete sender address and web address, but do not rely on appearance alone.
  • Verify unusual requests through a trusted channel that was not provided in the suspicious message.
  • Never disclose passwords, personal identification numbers or one-time codes to unsolicited callers or messages.
  • Use unique passwords, multi-factor authentication, updates, backups and clear payment-approval procedures.
  • If an incident occurs, report it quickly, protect affected accounts and preserve useful evidence.

Comments

Learner discussion on this EduHub resource.

No comments yet.