Cyber Security Phishing and Social Engineering

Social engineering attacks manipulate people rather than machines, and phishing, spear-phishing, pretexting, and baiting are its four most common forms.

What Is Social Engineering?

Social engineering is the practice of manipulating people — rather than exploiting software flaws — into taking an action that helps an attacker, such as revealing a password, approving a payment, or installing malware. It works because it targets normal human tendencies: trust in authority, willingness to help, curiosity, and urgency. Phishing, spear-phishing, pretexting, and baiting are four of the most common techniques, and they differ mainly in how targeted they are and what 'hook' they use.

Phishing

Phishing is a broad, usually untargeted attack sent to large numbers of people at once, most often by email or text message, impersonating a trustworthy sender such as a bank, delivery company, or well-known software provider. The message typically creates urgency — 'your account will be suspended' — and pushes the recipient toward a fake login page or a malicious attachment. Because it's sent widely rather than tailored to one person, a phishing message often contains generic greetings and details that don't quite match the recipient's real situation.

Spear Phishing

Spear phishing is a targeted version of phishing aimed at one specific person or organization. The attacker researches the target beforehand — using information from social media, a company website, or a previous data breach — and uses that detail to make the message far more convincing, such as referencing a real colleague's name, an actual project, or a recent event. Because it's personalized, spear phishing has a much higher success rate than generic phishing and is frequently used against employees with access to sensitive systems or approval authority.

Pretexting

Pretexting relies on a fabricated scenario — a 'pretext' — rather than a message pushing a link. The attacker impersonates someone the victim would reasonably trust, such as an IT technician, a new employee, an auditor, or a vendor, and uses that invented identity and situation to request information or access directly, often over the phone or in person. Where phishing usually asks the victim to click something, pretexting is built entirely around a convincing story and often unfolds over a real conversation.

Baiting

Baiting dangles something enticing to lure the victim into compromising themselves, without necessarily impersonating anyone. Classic examples include a USB drive labeled 'Confidential Salaries' left in a company parking lot, or a website offering a free download of paid software or a movie. When the victim takes the bait — plugging in the drive or running the download — it delivers malware or harvests credentials.

TechniqueTarget ScopeTypical DeliveryDistinguishing Feature
PhishingBroad, untargetedMass email or textGeneric message sent to many people at once
Spear PhishingOne specific person or orgPersonalized email or messageUses researched details about the target
PretextingOne specific person or orgPhone call, in-person, or messageBuilt around a fabricated identity or story
BaitingAnyone who takes the baitPhysical media or 'free' downloadRelies on curiosity or greed rather than urgency
  • Unexpected urgency or threats ('act now or your account is closed')
  • Requests for credentials, payment, or gift cards that bypass normal process
  • Sender address or phone number that looks almost, but not quite, right
  • Links that don't match the company's real domain when you hover over them
  • Any request to plug in an unknown USB device or bypass a security step 'just this once'