CyberIncidents Logo
Phishing & Social Engineering

Phishing and Social Engineering: Understanding the Human Side of Cyber Attacks

Threats & Attacks → Phishing & Social Engineering Level: Beginner → Intermediate

Rohith HariOctober 4, 20264 min read
Phishing and Social Engineering: Understanding the Human Side of Cyber Attacks

Cyber attacks are often associated with sophisticated malware, zero-day vulnerabilities, or complex hacking techniques. But many successful attacks begin with something much simpler: a human being making a decision.

An attacker may not need to exploit a complicated vulnerability if they can convince someone to click a link, open an attachment, reveal a password, approve a login request, or transfer money.

This is where phishing and social engineering become important.

Phishing is a type of cyber attack that uses deceptive messages, websites, emails, or other communication methods to trick victims into performing an action that benefits the attacker. Social engineering is the broader concept of manipulating human behavior to obtain information, access, money, or another desired outcome.

Together, they represent one of the most important human-centered threats in cybersecurity.

What Is Social Engineering?

Social engineering is the psychological manipulation of people to influence their actions or decisions.

Instead of attacking a computer directly, an attacker may target:

  • Trust

  • Fear

  • Curiosity

  • Urgency

  • Authority

  • Greed

  • Familiarity

  • Helpfulness

For example, an attacker could pretend to be an organization's IT administrator and tell an employee:

"Your account has a security problem. Please verify your password immediately."

The attacker is not technically forcing the employee to provide the password. Instead, they are attempting to create enough trust and urgency that the employee willingly provides it.

This is what makes social engineering different from many purely technical attacks.

The attacker is exploiting human behavior.

What Is Phishing?

Phishing is one of the most common forms of social engineering.

In a typical phishing attack, the attacker sends a deceptive communication designed to appear legitimate.

The message may impersonate:

  • A bank

  • Microsoft or another technology provider

  • An employer

  • A university

  • A colleague

  • A government organization

  • A delivery company

  • A social media platform

The objective may be to make the victim:

  • Click a malicious link

  • Enter credentials

  • Open an attachment

  • Download malware

  • Approve an authentication request

  • Transfer money

  • Provide sensitive information

CyberIncidents article image

Common Types of Phishing

Phishing is not limited to email.

Email Phishing

The attacker sends fraudulent emails to large numbers of users.

Example:

"Your account will be suspended. Verify your account now."

Spear Phishing

A targeted phishing attack aimed at a specific person or organization.

The attacker may research the victim beforehand and customize the message.

Business Email Compromise

Attackers impersonate executives, employees, suppliers, or business partners to convince victims to make payments or disclose sensitive information.

Smishing

Phishing conducted through SMS or text messages.

Example:

"Your parcel could not be delivered. Confirm your delivery details."

Vishing

Voice phishing, where attackers use phone calls to manipulate victims.

The attacker may pretend to be:

  • Bank staff

  • IT support

  • Police

  • Government officials

  • Company executives

QR Phishing

Attackers use malicious QR codes to redirect victims to fraudulent websites or credential-harvesting pages.

Why Does Phishing Work?

A common misconception is:

"Only inexperienced people fall for phishing."

That is not accurate.

Even experienced professionals can be deceived when an attack is convincing and arrives at the right moment.

Attackers frequently exploit psychological triggers.

Urgency

"Your account will be deleted within 30 minutes."

Authority

"This is your organization's security administrator."

Fear

"Suspicious activity has been detected on your account."

Curiosity

"Here are the confidential documents discussed in today's meeting."

Financial incentive

"You've received a refund."

The goal is to make the victim act before thinking critically.

The Anatomy of a Phishing Attack

A typical phishing campaign can contain several stages:

1. Reconnaissance

The attacker collects information about the target.

Sources may include:

  • Company websites

  • Social media

  • Public documents

  • Previous data breaches

  • Professional networking sites

2. Delivery

The attacker sends the malicious message.

3. Social Engineering

The message creates a reason for the victim to act.

4. Credential Theft or Malware Delivery

The victim may enter credentials or execute malicious content.

5. Account Compromise

The attacker uses stolen credentials, session information, or other access mechanisms.

6. Follow-on Activity

The compromised account may be used for:

  • Data theft

  • Internal phishing

  • Financial fraud

  • Privilege escalation

  • Lateral movement

  • Further compromise

Therefore, phishing should not be viewed simply as "a malicious email."

It can be the initial access stage of a much larger intrusion.