Social Engineering

Why convincing attacks often look like ordinary work

The hardest messages to recognise are often the ones that fit naturally into the recipient's day.

The easiest malicious messages to recognise are often the worst ones: bad spelling, strange links, unfamiliar organisations, obvious threats.

Modern targeted social engineering does not have to look like that. The message can be polite. The project can be real. The name can be correct. The request can be something the recipient has done many times before.

Context is what makes the difference

Imagine a finance employee receives a request involving a supplier they already know. The message references a real project. The person apparently sending it has the authority to make that request. The timing makes sense.

Nothing about the request feels random.

That is why good security awareness cannot rely only on spotting things that look suspicious. Some attacks are designed specifically not to look suspicious.

Verification beats intuition

People are often told to “trust their gut.” That can help, but it is not a reliable control.

A better approach is deciding in advance which requests require independent verification. Examples might include:

  • Changed banking details
  • Payments outside the usual process
  • Requests for credentials or sensitive information
  • Instructions to bypass a normal approval route
  • Sensitive requests from a new phone number or channel

The exact list depends on the organisation. The important part is consistency.

Use information you already trust

Verification is strongest when it does not depend on information supplied by the request being verified.

If an email says “Call this number to confirm”, the number came from the same source making the claim.

Use contact details already held independently. Use a known number. Use an existing supplier record. Use the established internal process.

That one distinction stops many convincing approaches from becoming decisions.

Awareness should make work easier, not harder

The answer is not telling staff to distrust everything. Organisations would stop functioning.

The objective is teaching people which decisions deserve another channel and how to perform that check quickly. That is the behaviour we focus on in Security Awareness Training.

Explore Security Awareness Training

Filed under social engineering, verification, security awareness

Written by

Teofilus Shaduka

Founder, Principia Works.

Teofilus works across open-source intelligence, cybersecurity awareness and digital exposure research.

About Principia Works

Start with the problem, not the service.

You do not need to know exactly what you need before contacting us.

Tell us what happened, what concerns you or what you are trying to understand.

We will tell you whether Principia Works is the right fit and what the next step would involve.