At a glance
Social engineering is when cybercriminals trick you into sharing personal or sensitive information. This can lead to hacked accounts, devices, or systems. Social engineering can target anyone, but often focuses on high-value people.
Learn how to check for warning signs like unexpected links, urgent requests or unusual instructions. Always check that a request is real before you act.
What is social engineering
Social engineering is a serious threat to people and organisations by targeting people rather than computer systems. The aim is to trick people into giving away access to accounts, devices, systems, or important information.
Malicious actors use social engineering because it is a simple, low cost, and an effective way to trick you into doing things like:
- opening attachments
- clicking malicious links
- sharing password details
- visiting fake websites
- giving away personal or sensitive information
- transferring money.
Social engineering attacks can happen through email, text messages, social media or phone calls. These messages and calls often seem authentic and trustworthy. Malicious actors use emotions like fear, trust or urgency to make you act quickly. Messages and calls may seem like they come from someone you know, such as a friend, family, co-worker or a trusted organisation.
Targets of social engineering
Anyone can be targeted by social engineering. Malicious actors often focus on people who have access to valuable information, accounts, systems or money, or who can approve payments or access requests.
They may also target people who often communicate with customers, service providers or people outside their usual networks.
Common targets can include:
- people with valuable personal, financial or account information
- high-profile individuals
- senior managers and their staff
- information technology (IT) staff and system administrators
- workers in human resources, sales, marketing, finance and legal teams.
Malicious actors may contact many people, hoping that one person will fall for the attack.
Social engineering can be hard to identify. Advances in artificial intelligence (AI) have made social engineering attacks more effective and convincing. Learning to spot the warning signs can help keep you and your organisation secure.
Warning signs of social engineering
There are several ways to tell whether a message or phone call may be real or fake.
Unusual attachments or website links
Be cautious of unexpected attachments or website links. Don’t click on any links or visit websites sent to you from an unexpected or unfamiliar source. If you do click on a link, never share your personal or sensitive information.
This includes links sent within:
- calendar invitations
- instant messaging applications
- customer engagement portals
- personal and work emails.
If you receive a message from an organisation you know, you should still avoid clicking any links. Instead, visit the official website or application and login to your account using a trusted method.
If you receive an unexpected attachment, you should contact the sender through a secure, trusted method. For example, through a phone number listed on an official website.
Requests to run code or skip security controls and procedures
Malicious actors may try to persuade you to change system settings, run code or take other actions that compromise security. For example, if Microsoft Office macros are disabled, a malicious actor may provide detailed instructions to enable them. This can allow malicious code to automatically run when a user opens a document.
They may also use social media or online gaming platforms to offer deals that seem too good to be true. This could include free software or giveaways in exchange for running code on a device. These tactics often exploit people’s fear of missing out by creating a sense of urgency.
To make their attempt seem more credible, malicious actors may also exploit current news stories and events. For example, they may claim to provide a fix for a high-profile technical issue. By sharing code and encouraging users to run it on their devices, they can expose those devices to further exploitation and compromise.
Treat any request to change system settings, run code or alter security settings as highly suspicious. Always verify the request independently.
Chief executive officer (CEO) fraud
Malicious actors may pretend to be someone you trust or in a position of authority and urgently request a high-value payment or large money transfer.
In a workplace, they may pretend to be a senior executive, like a CEO. These requests often occur when the executive is unavailable or hard to contact, increasing pressure on staff to comply without proper checks.
Requests for sensitive or unnecessary information
Malicious actors often use simple social engineering techniques to exploit people’s natural desire to be helpful. Their requests may seem reasonable at first.
For example, they might pretend to be a colleague, friend or other trusted person asking you to send information or documents.
They may also pose as someone who could reasonably need access to the information they’re asking for. This could be a service provider, new IT service desk staff member or a colleague working on a shared project from a different office.
Be mindful of what you share online. Malicious actors can use these details to impersonate you or make their approach more convincing. To help protect your privacy, review your settings and follow our security tips for social media and messaging services.
Malicious actors may also use phone calls to apply pressure. They often create a false sense of urgency or authority to trick you into sharing information.
They may try to access your end-to-end encrypted accounts by adding an unauthorised device or re-registering your account. Do not share registration PINs or verification codes for social media or messaging apps, especially if the request appears to come from a 'support' account. Always review new device register notifications.
Never share your current password as part of a reset or account recovery process. Organisations should ensure their processes never require staff to disclose their current passwords. Reinforce this through security awareness training.
Be cautious of requests for sensitive information from people you don’t interact with regularly. Even if you know the person, consider whether they really need access to that information. Malicious insiders may exploit their contacts to gain information or access they should not have.
Poorly written or unusual communication
Malicious actors can make mistakes. Sometimes they’ll use poor grammar, spelling or have an unusual tone. Sometimes they won’t sound like the person they’re pretending to be. They may also use general greetings instead of your name (such as ‘sir’, ‘madam’ or ‘to payee’).
AI tools can now create messages with perfect spelling and grammar. It’s becoming harder to identify these mistakes as a sign of a scam.
If you feel like someone is messaging or talking to you strangely, you should always contact the person (or organisation) directly through a trusted method. For example, calling their number from your contact list.
What you can do about social engineering
If you suspect a social engineering attempt:
- don’t respond to the message
- don’t delete or forward the message
- report it to your organisation’s IT or cyber security team if it relates to work
- keep the message for investigation and response
- report the scam to the National Anti-Scam Centre’s Scamwatch.
Remember, when in doubt:
- avoid sharing personal or sensitive information over a call, email or message
- contact someone through a trusted method if you believe someone else is pretending to be them.
If you manage cyber security for an organisation, learn how to detect socially engineered messages.
Further information
For more ways to protect yourself or your organisation, you can also use:
Never miss a threat
Sign up to receive the latest cyber security alerts, along with information on emerging threats and how to stay secure online.