Skip to content

alphaPlan · Cybersecurity · Cheat-sheet 04

Social Engineering & the Human Factor

Social engineering targets the person, not the machine, and one habit beats it: slow down and verify anything unexpected through a separate, trusted channel.

Ideas to remember

  1. 01It is easier to ask a person for the key than to pick the lock, and trust, habit and pressure do most of the damage.
  2. 02Attackers pull four levers on purpose, authority, urgency, helpfulness and fear, so feelings answer before thinking does.
  3. 03Phishing, smishing and vishing are one trick through three doorways: email, text message and phone call.
  4. 04Business email compromise (BEC) is a patient, well written request to change payment details, and it targets a gap in your process.
  5. 05Physical tactics work too: tailgating, bin raiding, sticky note passwords and dropped USB sticks.
  6. 06A password manager stays silent on a fake page, and MFA still holds after your password has been talked out of you.

Words

Social engineering
Talking someone into handing over information or doing something they should not.
Phishing
A fake message, usually an email, built to look trustworthy so you click, open or type your password.
Smishing
The same trick by SMS or a messaging app.
Vishing
The same trick by phone call, now easy to fake with voice cloning.
BEC
Business email compromise: a real-looking invoice or note that redirects a real payment to the attacker.
Tailgating
Slipping through a secure door behind an authorised person.

Do this

  • When a request comes with a countdown or a threat, pause, breathe, and verify on a separate, trusted channel.
  • Confirm any change of bank details by phoning a number you already have on file, never one in the message.
  • Make 'we always call to confirm a change of bank details' a written rule, not a personal favour.
  • Let people badge in themselves, shred sensitive paper, and hand any found USB stick to IT unopened.
  • Turn on MFA everywhere, starting with email, and deny any prompt you did not start.

Watch out

  • The tell is rarely the logo; it is the request, since a real bank does not email you a link and ask you to log in urgently.
  • Strong urgency is itself a red flag: a genuine request survives a five minute delay, a scam usually does not.
  • If your password manager does not autofill, you may be on a look-alike page; that silence is a warning.

From the lessons: Hacking the human, Weaponised bias, Phishing, smishing, and vishing, Business email compromise, Physical tactics, Password managers and MFA. codeforalbania.com/en/learn/cybersecurity/04-social-engineering

shënim: ky material u krijua në kuadër të projektit 'U.S. Cybersecurity Leadership in AI for Albania', financuar nga departamenti i shtetit i shteteve të bashkuara. mendimet, gjetjet dhe përfundimet e paraqitura këtu janë të autorit(ëve) dhe nuk pasqyrojnë domosdoshmërisht ato të departamentit të shtetit të shteteve të bashkuara.

Disclaimer: This material was created on behalf of the 'U.S. Cybersecurity Leadership in AI for Albania' project, funded by the United States Department of State. The opinions, findings, and conclusions stated herein are those of the author(s) and do not necessarily reflect those of the United States Department of State.

Disclaimer

Found something unclear, outdated or improvable? Suggest an improvement