Phishing and Social Engineering: Understanding the Human Side of Cyber Attacks
Threats & Attacks → Phishing & Social Engineering Level: Beginner → Intermediate

Cyber attacks are often associated with sophisticated malware, zero-day vulnerabilities, or complex hacking techniques. But many successful attacks begin with something much simpler: a human being making a decision.
An attacker may not need to exploit a complicated vulnerability if they can convince someone to click a link, open an attachment, reveal a password, approve a login request, or transfer money.
This is where phishing and social engineering become important.
Phishing is a type of cyber attack that uses deceptive messages, websites, emails, or other communication methods to trick victims into performing an action that benefits the attacker. Social engineering is the broader concept of manipulating human behavior to obtain information, access, money, or another desired outcome.
Together, they represent one of the most important human-centered threats in cybersecurity.
What Is Social Engineering?
Social engineering is the psychological manipulation of people to influence their actions or decisions.
Instead of attacking a computer directly, an attacker may target:
Trust
Fear
Curiosity
Urgency
Authority
Greed
Familiarity
Helpfulness
For example, an attacker could pretend to be an organization's IT administrator and tell an employee:
"Your account has a security problem. Please verify your password immediately."
The attacker is not technically forcing the employee to provide the password. Instead, they are attempting to create enough trust and urgency that the employee willingly provides it.
This is what makes social engineering different from many purely technical attacks.
The attacker is exploiting human behavior.
What Is Phishing?
Phishing is one of the most common forms of social engineering.
In a typical phishing attack, the attacker sends a deceptive communication designed to appear legitimate.
The message may impersonate:
A bank
Microsoft or another technology provider
An employer
A university
A colleague
A government organization
A delivery company
A social media platform
The objective may be to make the victim:
Click a malicious link
Enter credentials
Open an attachment
Download malware
Approve an authentication request
Transfer money
Provide sensitive information

Common Types of Phishing
Phishing is not limited to email.
Email Phishing
The attacker sends fraudulent emails to large numbers of users.
Example:
"Your account will be suspended. Verify your account now."
Spear Phishing
A targeted phishing attack aimed at a specific person or organization.
The attacker may research the victim beforehand and customize the message.
Business Email Compromise
Attackers impersonate executives, employees, suppliers, or business partners to convince victims to make payments or disclose sensitive information.
Smishing
Phishing conducted through SMS or text messages.
Example:
"Your parcel could not be delivered. Confirm your delivery details."
Vishing
Voice phishing, where attackers use phone calls to manipulate victims.
The attacker may pretend to be:
Bank staff
IT support
Police
Government officials
Company executives
QR Phishing
Attackers use malicious QR codes to redirect victims to fraudulent websites or credential-harvesting pages.
Why Does Phishing Work?
A common misconception is:
"Only inexperienced people fall for phishing."
That is not accurate.
Even experienced professionals can be deceived when an attack is convincing and arrives at the right moment.
Attackers frequently exploit psychological triggers.
Urgency
"Your account will be deleted within 30 minutes."
Authority
"This is your organization's security administrator."
Fear
"Suspicious activity has been detected on your account."
Curiosity
"Here are the confidential documents discussed in today's meeting."
Financial incentive
"You've received a refund."
The goal is to make the victim act before thinking critically.
The Anatomy of a Phishing Attack
A typical phishing campaign can contain several stages:
1. Reconnaissance
The attacker collects information about the target.
Sources may include:
Company websites
Social media
Public documents
Previous data breaches
Professional networking sites
2. Delivery
The attacker sends the malicious message.
3. Social Engineering
The message creates a reason for the victim to act.
4. Credential Theft or Malware Delivery
The victim may enter credentials or execute malicious content.
5. Account Compromise
The attacker uses stolen credentials, session information, or other access mechanisms.
6. Follow-on Activity
The compromised account may be used for:
Data theft
Internal phishing
Financial fraud
Privilege escalation
Lateral movement
Further compromise
Therefore, phishing should not be viewed simply as "a malicious email."
It can be the initial access stage of a much larger intrusion.
Latest posts
3 entries, most recent posts.
Understanding Network Traffic During an Investigation
Level: Intermediate

Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes
Category: Phishing / Artificial Intelligence

Citrix patches NetScaler SAML zero-day exploited in attacks
Severity: High CVSS: 8.7 Affected Products: Citrix NetScaler ADC & NetScaler Gateway Attack Type: Denial of Service / Possible Remote Code Execution

