Social engineering is a type of cyber attack that manipulates people — rather than machines — into revealing confidential information or taking harmful actions. Phishing is its most common form: a deceptive message designed to trick you into clicking a malicious link, entering a password, or handing over personal data.

Why do attackers target people instead of technology?

No matter how strong a firewall or encryption system is, there is always a human in the loop — and humans can be deceived. A technically brilliant hacker might spend weeks trying to break a bank's servers. Or they could send one believable email to an employee, who then clicks a link and hands over their login credentials in minutes. Social engineering is cheaper, faster, and often more successful than technical attacks. The KS3 curriculum covers it because recognising these tactics is itself a security skill.

What are the main types of social engineering?

Type How it works Example
Phishing Deceptive email pretending to be a trusted source Fake HMRC email claiming you're owed a tax refund
Spear phishing Targeted phishing using personal details to seem credible Email using your school name and teacher's name
Vishing Voice phishing — a phone call from a fake "bank" or "IT support" Caller claims your account is compromised, asks for PIN
Smishing SMS phishing — a fake text message Text: "Your parcel is held. Click here to pay £1.45"
Pretexting Inventing a scenario (pretext) to extract information Attacker pretends to be from IT and asks for your password to "fix" an issue
Baiting Luring victims with something desirable (free download, USB drive) USB labelled "Exam Papers 2026" left in a school corridor
Tailgating Physically following an authorised person through a secure door Attacker walks behind a member of staff through a key-card door

How do you recognise a phishing email?

Phishing emails are designed to trigger an emotional response — urgency, fear, or excitement — before your critical thinking catches up. Recognising them requires slowing down and checking:

  1. Sender address: Does the domain match the real organisation? service@amaz0n-support.net is not Amazon's domain.
  2. Greeting: Generic greetings ("Dear Customer", "Dear User") suggest a mass attack; your bank knows your name.
  3. Urgency language: "Your account will be closed in 24 hours!" is a pressure tactic.
  4. Links: Hover over any link (do not click). Does the URL shown match the text? bit.ly/a9kX3 hiding behind "Click here to verify" is suspicious.
  5. Spelling and grammar: Many phishing emails contain errors, though AI-generated fakes are now grammatically flawless — so this alone is not a reliable test.
  6. Attachments: Unexpected attachments from unknown senders can contain malware. Open only if you are certain of the sender.
  7. Requests for personal data: Legitimate organisations never ask for passwords, PINs, or payment details by email.

What makes spear phishing more dangerous than regular phishing?

A regular phishing campaign sends the same message to millions of people, hoping a fraction will fall for it. Spear phishing targets a specific individual using researched personal details — your name, school, friends, interests, recent purchases — gathered from social media and public sources. The result is a message that feels genuine and specific. A spear-phishing email might appear to come from your headteacher, reference a real upcoming event, and ask you to log in to a fake school portal. Always verify unexpected requests through a separate, trusted channel (ring the person directly).

What should you do if you think you have received a phishing message?

Step Action
1 Do not click any links or open attachments
2 Do not reply, even to "opt out" — it confirms your address is active
3 Report it: forward phishing emails to report@phishing.gov.uk (UK government service)
4 Delete the message
5 If you clicked a link: change your passwords immediately and tell a trusted adult or IT staff
6 Enable two-factor authentication (2FA) on affected accounts

How do organisations protect against social engineering?

Technical controls alone are insufficient — organisations also use:

  • Staff training — regular awareness programmes teaching employees to spot attacks
  • Simulated phishing — sending fake phishing emails to staff to test and train responses
  • Email filtering — spam and malware filters quarantine suspicious messages before they reach inboxes
  • Two-factor authentication (2FA) — even if credentials are stolen, a second factor (phone code) prevents login
  • Clear policies — strict rules: IT staff will never ask for your password, so any request for it is automatically suspicious

Frequently asked questions

Is social engineering illegal in the UK?

Yes. Using deception to obtain personal data, financial gain, or unauthorised computer access is a criminal offence under the Computer Misuse Act 1990 and the Fraud Act 2006 in the UK. Perpetrators can face significant fines and prison sentences. Reporting phishing to the police (Action Fraud: 0300 123 2040) and to the NCSC (report@phishing.gov.uk) is encouraged.

Why can't spam filters catch all phishing emails?

Phishing emails constantly evolve to evade filters. Attackers use legitimate-looking domains, HTTPS certificates on fake websites, URL shorteners, and image-based content that filters cannot read. Sophisticated spear-phishing emails may even come from compromised legitimate email accounts, which appear authentic to filters. This is why human vigilance remains the last line of defence.

How does two-factor authentication help against phishing?

Even if you are tricked into entering your password on a fake site, 2FA adds a second requirement — typically a one-time code sent to your phone. The attacker who stole your password cannot log in without also having your phone. Many systems now use time-limited codes (TOTP) that expire after 30 seconds, making stolen codes almost useless. 2FA does not make phishing impossible, but it dramatically raises the cost of a successful attack.

What is the difference between phishing and pharming?

Phishing sends you a deceptive message with a link to a fake site. Pharming hijacks the DNS system itself — when you type a real website address (e.g. www.mybank.co.uk), you are silently redirected to a fake site without any suspicious link being clicked. Pharming is harder to spot because the URL in your browser may look correct. Keeping your router firmware updated and using a reputable DNS provider reduces pharming risk.


Stay sharp on cyber security with Professor Turing's question-led sessions at aitutors.me.