Social engineering is the umbrella term for tricking a person into handing over access or information, rather than breaking through a technical defense. Phishing is its most common form, but it takes several distinct shapes worth recognizing individually.
| Form | What it looks like |
|---|---|
| Phishing | A generic fake email — a bank, delivery service, or well-known company impersonated, sent to thousands of people at once |
| Spear phishing | The same idea, but personalized with a real name, employer, or recent activity — far more convincing, and worth extra suspicion for that reason |
| Smishing | The same tactic delivered by SMS text message, often a fake delivery notice or "your account has been locked" link |
| Vishing | A phone call, often from a spoofed number, impersonating a bank, tech support, or government agency to extract information verbally |
| Pretexting | An attacker builds a false but plausible scenario — posing as a coworker, IT support, or a vendor — to make a request seem legitimate before asking for anything |
Despite the different delivery methods, the actual tricks repeat: manufactured urgency ("act within 24 hours or your account is closed"), offers that are too good to be true, a sender address or phone number that doesn't quite match who it claims to be, and a request for something a legitimate organization would never actually ask for over email or phone — a full password, a one-time login code, or a card's CVV.
| Warning sign | Why it works on people |
|---|---|
| Urgency / a countdown | Pressure short-circuits careful thinking |
| Too good to be true | A prize, refund, or discount that overrides normal caution |
| Mismatched sender address | A display name that looks right hides a wrong underlying address |
| Request for a code or password | No legitimate service asks for these — this alone is close to a guarantee it's an attack |
The one rule that covers most of it
The single most reliable rule: no legitimate bank, company, or government office will ever ask for a full password, a one-time login code, or a card's CVV over phone, email, or text. Any message asking for one of these is fake, regardless of how convincing it looks otherwise.