English:Phishing and Social Engineering

Phishing and Social Engineering
Introduction
Phishing and social engineering are security threats that target human decisions as well as technical systems. Social engineering is the use of deception, persuasion, impersonation, or pressure to make someone reveal information, approve an action, transfer money, install software, or give access that should not be granted. Phishing is a common form of social engineering that uses messages or websites to imitate trusted people or organisations.
For apprentices, trainees, and vocational students, this topic is practical workplace knowledge. You may handle customer records, invoices, tools, production systems, company accounts, deliveries, shared devices, or internal communication. An attacker may therefore target you even if you do not work in an IT department.
By the end of this aiMOOC, you should be able to:
- Recognise phishing: Identify suspicious requests without relying on one single warning sign.
- Explain social engineering: Describe how attackers exploit trust, authority, urgency, fear, curiosity, and helpfulness.
- Protect information: Apply verification, password, authentication, and reporting practices in a workplace.
- Respond to incidents: Take appropriate first steps after a suspicious message, click, disclosure, or payment request.
- Transfer your learning: Apply the same security thinking to email, text messages, calls, QR codes, collaboration tools, and face-to-face situations.
Core Concepts
Phishing Is a Trust Attack
A phishing message tries to make a false situation feel normal, urgent, or important enough that you act before checking. The message might claim that your mailbox will be closed, an invoice has changed, a parcel is waiting, your manager needs a payment, or the IT department needs you to sign in. The goal can be credential theft, malware delivery, financial fraud, data theft, or access to a larger organisation.
A professional-looking message is not proof that it is genuine. Modern scams can use correct spelling, copied logos, familiar language, stolen account details, and information gathered from public websites or social media. Treat appearance as one clue, not as evidence of identity.

When you examine a suspicious message, ask: Was I expecting this? Is the request normal for my role? Does the sender identity match the real organisation? Is the action unusually urgent or secret? Would the organisation normally ask for this information or payment in this way?
Social Engineering Is Broader Than Email
Social engineering can happen through email, messaging apps, text messages, telephone calls, video meetings, social media, physical visits, and conversations. An attacker may pretend to be a colleague, supplier, supervisor, customer, technician, recruiter, bank employee, delivery driver, or authority figure.
The most important defence is not memorising a list of tricks. It is learning a repeatable habit: stop, check the context, verify independently, and report concerns through the approved channel.
Common Forms of Phishing and Social Engineering
Email Phishing and Spear Phishing
Email phishing may be sent to many people. Spear phishing is more targeted and may use details about your employer, project, role, supplier, or colleagues to sound convincing. A targeted message can be especially dangerous because it may match real workplace routines.
Typical warning signs include an unexpected login request, a change of bank details, a request to bypass normal procedures, an attachment you did not expect, a demand for secrecy, or a message that pushes you to act immediately. None of these signs alone proves fraud, but several together should increase your caution.
Smishing: Phishing by Text Message
Smishing uses SMS or other short-message channels. Common themes include delivery problems, account warnings, refunds, unpaid fees, and urgent verification. Because a phone screen shows less information than a desktop email client, it can be harder to inspect the sender or destination.

Do not follow a suspicious message link just to see where it goes. If the message claims to come from a service you use, open the official app, use a trusted bookmark, or type the known official address yourself.
Vishing: Voice Phishing
Vishing uses telephone or voice communication. The caller may create urgency, claim to be from IT support, ask you to read out a one-time code, request remote access, or pressure you to approve an authentication prompt. Caller ID can be manipulated, so the displayed number is not reliable proof of identity.

If a caller asks for a sensitive action, end the call and verify through a known official number or another approved workplace channel. Do not use a number supplied only by the suspicious caller.
QR Phishing and Collaboration-Tool Phishing
QR phishing, sometimes called quishing, uses QR codes to hide the destination until you scan them. A malicious QR code can appear in an email, poster, invoice, parking notice, or document. Treat an unexpected QR code that asks you to sign in or pay as you would treat an unexpected link.
Attackers also use collaboration platforms, direct messages, shared documents, calendar invitations, and fake support chats. The security question remains the same: Does this request fit the normal process, and can you verify the requester independently?
Pretexting, Impersonation, Baiting, and Physical Access
Pretexting means creating a believable story to justify a request. Impersonation means pretending to be another person or organisation. Baiting offers something attractive or useful in order to trigger unsafe action. A found USB drive, for example, should not be connected to a workplace device unless your organisation has an approved procedure for examining unknown media.

Physical social engineering can include attempts to enter restricted areas by following an authorised person through a controlled door, claiming to have forgotten a badge, or asking an employee to hold a secure door open. Follow your site rules for visitors, badges, contractors, and restricted areas.

Why Social Engineering Works
Attackers often combine several psychological pressures. Understanding these pressures helps you notice when a request is trying to override normal judgement.
Authority uses status or rank: “The director needs this now.” Urgency reduces the time available to check. Fear creates anxiety about penalties, account closure, or job consequences. Scarcity makes an opportunity seem limited. Curiosity encourages you to open an unexpected file or message. Helpfulness exploits the normal desire to assist a colleague, customer, or visitor. Familiarity uses names, routines, suppliers, or workplace language to make a request feel safe.
These techniques are not proof that a message is malicious. Legitimate work can also be urgent or important. The correct response is therefore not automatic rejection; it is verification through a trusted process.
A Workplace Verification Routine
Use this routine whenever a request involves credentials, money, confidential information, unusual software, changes to payment details, or access to restricted systems.
- Pause: Do not let urgency force an immediate click, reply, payment, login, or approval.
- Check the context: Compare the request with your role, current tasks, normal procedures, and expected communication.
- Verify independently: Contact the person or organisation using a known number, official app, trusted directory, or established internal channel.
- Follow procedure: Use approval rules for payments, supplier changes, password resets, remote access, and visitor access.
- Report quickly: Use the approved reporting button, service desk, supervisor, or security contact so others can be protected.
For a bank-account change or urgent payment request, independent confirmation is essential. A reply to the same email thread is not independent verification because an attacker may control the mailbox or may have imitated the sender. Use a known contact method and follow dual-approval rules where your organisation requires them.
Technical Clues Without Overconfidence
You do not need to be a network specialist to check basic clues. Compare the full sender address with the expected domain. Be alert to look-alike domains, unusual reply-to addresses, unexpected cloud-sharing invitations, and login pages reached from unsolicited messages. Check whether an attachment makes sense for the task. Be cautious if a document asks you to enable macros, install software, or change device security settings.
A padlock icon or HTTPS connection only tells you that the connection to a site is encrypted. It does not prove that the site belongs to the organisation you intended to visit. A convincing logo also does not prove identity.
Never use a live suspicious link as a classroom experiment on a normal device. Training should use screenshots, instructor-provided simulations, reserved example domains, or other controlled materials.
Authentication and Account Protection
A password is only one layer. Use a unique password for each account and a reputable password manager where your organisation permits it. Turn on multi-factor authentication when available.
Not all MFA methods provide the same protection. Codes that you manually type can still be captured by a convincing fake site. Phishing-resistant authentication methods such as FIDO or WebAuthn security keys and passkeys are designed to prevent an authentication secret from being given to an impostor site.

Never approve an unexpected sign-in prompt. If you receive repeated prompts that you did not initiate, deny them and report the event. An attacker may be trying to create “MFA fatigue” so that you eventually approve one.
Organisational Defences
Good security does not depend on perfect human detection. Organisations should use multiple layers so that one mistake does not become a major incident.
Useful controls include email filtering, malware protection, software updates, restricted administrative rights, least privilege, secure backups, strong authentication, payment approval procedures, and clear reporting channels. Email-domain controls such as SPF, DKIM, and DMARC can reduce some forms of sender spoofing. They do not make every incoming message trustworthy, so process and user awareness still matter.
Training should make reporting easy and should avoid a blame culture. People who fear punishment may delay reporting a mistake. Fast reporting gives technical teams more time to block messages, reset accounts, protect other employees, and investigate what happened.
What to Do After a Mistake or Suspicious Event
If you clicked a suspicious link, entered credentials, approved an unexpected login, opened an attachment, installed software, disclosed confidential information, or transferred money, report it immediately according to your workplace procedure. Speed matters more than embarrassment.
Do not hide the event and do not delete evidence that your IT or security team may need. Follow organisational instructions for the device. You may be asked to disconnect it from the network, run an approved security scan, reset credentials from a known-clean device, revoke sessions, or preserve messages for investigation.
If credentials were entered on a suspicious site, change the affected password through the official service and change any reused password elsewhere. If financial information or a transfer is involved, contact the responsible finance team or financial institution through a known official channel. If personal data may have been exposed, follow your organisation's data-protection and incident-reporting obligations.
AI, Deepfakes, and Modern Impersonation
Generative AI can help attackers produce polished language, translate messages, personalise content, or imitate voices and images. A realistic voice or video is therefore not sufficient proof of identity for a sensitive request.
For high-risk actions, use a process that does not depend only on what you see or hear. Verify through a second, independent channel, use pre-agreed approval procedures, and confirm unusual changes before releasing money, credentials, confidential information, or access.
Professional Ethics and Safe Training
Cybersecurity learning must remain legal, authorised, and safe. Do not send deceptive messages to real colleagues, customers, suppliers, or public targets without explicit organisational authorisation and a controlled training plan. Do not collect real passwords or payment data in an exercise.
Use clearly fictional examples, screenshots, tabletop scenarios, and training accounts. The goal is to improve judgement, reporting, and resilient processes, not to trick people for entertainment or embarrassment.
Reliable Sources and Further Reading
- CISA Secure Our World: Practical guidance on phishing, strong passwords, MFA, and software updates.
- UK National Cyber Security Centre: Multi-layered organisational guidance for phishing defence.
- NIST Digital Identity Guidelines: Technical guidance on authenticators and phishing resistance.
- U.S. Federal Trade Commission: Consumer guidance on recognising, avoiding, and reporting phishing.
Interactive Tasks
Quiz: Test Your Knowledge
Which action is the safest first response to an unexpected request to change a supplier bank account? (Verify the change through a known independent contact method) (!Reply to the same email and ask whether it is genuine) (!Make the payment quickly and check later) (!Forward the email to a personal account)
What is social engineering in cybersecurity? (Manipulating people into unsafe actions or disclosures) (!Repairing social media software) (!Designing office communication systems) (!Encrypting every message on a network)
What is spear phishing? (Targeted phishing that uses information about a person or organisation) (!A phishing attack that only uses telephone calls) (!A security scan of an email server) (!A method for creating strong passwords)
Why is correct spelling not enough to prove that a message is genuine? (Modern scams can be polished and professionally written) (!Every genuine message contains spelling mistakes) (!Only automated messages use correct spelling) (!Secure email systems remove all spelling errors)
What should you do with an unexpected MFA prompt that you did not initiate? (Deny it and report the suspicious activity) (!Approve it so the prompts stop) (!Share the prompt with a stranger) (!Disable every security setting)
What is smishing? (Phishing delivered through text messages) (!Phishing delivered only through printed letters) (!A method of encrypting mobile devices) (!A type of secure video call)
Why can caller ID not prove who is calling? (The displayed number can be manipulated) (!Telephone networks never show a number) (!Only banks can use caller ID) (!All business calls are anonymous)
Which authentication approach is designed to resist impostor login sites? (Phishing resistant authentication such as FIDO or WebAuthn) (!Reusing one password for every account) (!Approving every push notification) (!Sending passwords by email)
What should workplace phishing training encourage? (Fast reporting through a clear trusted channel) (!Punishment for every mistaken click) (!Keeping incidents secret from the IT team) (!Testing staff with real stolen passwords)
What does a padlock icon in a browser mainly indicate? (The connection to the site is encrypted) (!The site owner is definitely trustworthy) (!The website cannot contain a scam) (!The message that linked to the site is genuine)
Memory Game
| Spear phishing | Targeted deceptive messaging that uses information about a specific person or organisation |
| Smishing | Phishing delivered through text messages |
| Vishing | Phishing carried out through voice communication |
| Pretexting | A fabricated story used to justify a sensitive request |
| Verification | Independent checking of identity or a request through a trusted method |
| Baiting | An attractive offer or object used to encourage unsafe action |
Drag and Drop
| Match the correct terms. | Topic |
|---|---|
| Urgency | Pressure to act before checking |
| Authority | Pressure based on status or rank |
| Independent verification | Confirmation through a trusted separate channel |
| Least privilege | Giving users only the access needed for their work |
| Incident reporting | Quickly informing the approved workplace contact about a suspected event |
...
Crossword Puzzle
| Phishing | What attack uses deceptive messages or sites to steal information or trigger unsafe actions? |
| Pretexting | What technique creates a believable false story to justify a request? |
| Smishing | What is phishing through text messages called? |
| Vishing | What is phishing through voice calls called? |
| Impersonation | What technique involves pretending to be another person or organisation? |
| Verification | What process independently checks whether a request or identity is genuine? |
LearningApps
Cloze Text
Open-Ended Tasks
Easy
- Phishing red-flag poster: Create a one-page poster showing at least six warning signs and three safe responses for a vocational workplace.
- Verification script: Write a short, polite script you could use to verify an unusual payment, password-reset, or access request without accusing the requester.
- Message comparison: Compare two instructor-provided screenshots and explain which details you would verify before taking action.
- Security interview: Interview a trainer, supervisor, or IT contact about how suspicious messages should be reported in your workplace or training centre, without asking for confidential technical details.
Standard
- Smishing awareness image: Produce an infographic that explains how to handle an unexpected delivery or account-warning text message without opening the link.
- Workplace role-play: In pairs, role-play a suspicious phone request and a safe verification response, then reflect on which phrases created pressure.
- Reporting map: Create a simple process diagram showing whom a trainee should contact after a suspicious email, unexpected MFA prompt, lost badge, or accidental click.
- Physical security observation: With permission, visit a reception area, workshop entrance, or training facility and document visible access-control practices without photographing badges, personal data, or restricted details.
Advanced
- Tabletop incident exercise: Design a harmless tabletop scenario in which a fake supplier requests new bank details, then map the verification, reporting, and recovery decisions your team should make.
- Defence in depth analysis: Evaluate how training, MFA, least privilege, email controls, software updates, and payment procedures work together if one employee makes a mistake.
- Awareness video: Produce a two-minute training video for apprentices that explains one social-engineering technique and demonstrates a safe verification response without using real credentials or deceptive live links.
- Process improvement proposal: Review a fictional workplace procedure for urgent payments or password resets and propose changes that reduce social-engineering risk while keeping the process practical.
Learning Assessment
- Scenario analysis: You receive an urgent message from a senior manager asking for a confidential file through an unfamiliar sharing service. Explain how you would assess context, verify identity, and choose a safe response.
- Payment fraud transfer task: A supplier email announces new bank details. Design a verification process that remains secure even if the supplier mailbox has been compromised.
- Authentication comparison: Compare password-only login, one-time codes, push approval, and phishing-resistant authentication in terms of how each can respond to a fake login site.
- Incident response reasoning: A trainee entered a password on a suspicious page and then closed the browser. Prioritise the next actions and justify why fast reporting matters.
- Human and technical controls: Explain why staff awareness alone cannot stop every phishing attack and propose at least four complementary organisational controls.
- Cross-channel transfer: Apply the same verification principles to an email, a phone call, a QR code, and a visitor at a secure door, explaining what changes and what stays the same.
Evidence of Learning
Evidence of learning should show more than recall. You should be able to explain how phishing and social engineering exploit trust and workplace routines; distinguish common channels such as email phishing, spear phishing, smishing, vishing, QR phishing, pretexting, baiting, and physical impersonation; and recognise that professional appearance alone does not establish identity.
Your skills should include pausing under pressure, checking context, verifying through an independent trusted channel, following payment and access procedures, protecting credentials, handling unexpected MFA prompts, reporting incidents quickly, and communicating concerns professionally.
Useful learning products include a red-flag poster, verification script, reporting process map, awareness infographic, role-play reflection, tabletop exercise, short training video, and process-improvement proposal.
Transfer achievement is shown when you can apply the same principles to unfamiliar situations in different vocational settings, including offices, workshops, retail, healthcare, logistics, hospitality, administration, technical support, and remote work.
OERs on the Topic
The English Wikipedia articles below provide additional background on phishing and social engineering.
Linked Learning Areas
This topic connects human behaviour, workplace processes, technical controls, and professional responsibility. The most important transfer idea is that secure work depends on both careful decisions and systems designed to limit the impact of mistakes.
aiMOOC Projects
MOOCwiki · Deutsch
Nach dem Lernen ist vor dem Lernen
Entdecke direkt den nächsten Lernkurs. Weitere Inhalte erscheinen, wenn Du weiter nach unten scrollst.
Zur MOOCwiki-HauptseiteMediathek
Mediathek
Mediathek wird aus dem Wiki geladen ...
Keine passenden Inhalte gefunden. Bitte ändere Suche oder Filter.
NEWSLernweltNOAH fragen