2. Common threats
Phishing and social engineering
Social engineering means manipulating a person, rather than a system, into doing something insecure. Phishing is the most common form: a message designed to look legitimate that tricks you into clicking a link, opening an attachment, or handing over credentials.
What makes phishing effective
Not clumsy spelling mistakes, modern phishing is often well produced. It works by creating urgency ("your account will be suspended"), authority ("message from the CEO"), or familiarity (a convincing copy of a real service's login page).
Variants worth knowing
- Spear phishing: a phishing message tailored to a specific person or organisation using real details about them, far more convincing than a generic blast.
- Vishing: phishing over a phone call, often impersonating IT support, a bank, or a delivery company.
- Smishing: phishing via text message.
- Business email compromise: an attacker impersonates a colleague or supplier, often after compromising a real account, to redirect a payment or request sensitive information.
The single most useful habit
Verify unusual or urgent requests through a second channel you already trust, not one provided in the suspicious message itself. If "your bank" emails you a phone number, don't call it, use the number on your card instead.
› Course contents
Foundations of cyber security
Common threats
Passwords and authentication
Staying safe day to day