← Tutorials
AwarenessBeginner7 min read

Phishing and Social Engineering: How to Recognise the Attack Aimed at You

You can have perfect passwords and up-to-date software and still be compromised in thirty seconds — because the easiest system to hack is usually a busy, trusting human. Social engineering is the craft of manipulating people into handing over access, and phishing is its most common form.

Updated 2026-08-06

Why it works: the levers of manipulation

Social engineering rarely relies on technical tricks. It relies on predictable human reactions, and almost every scam pulls one or more of the same levers.

  • Urgency: "Your account will be closed in 24 hours." Panic short-circuits careful thinking.
  • Authority: a message that appears to come from your boss, your bank, or "IT support".
  • Fear: a warning that you have been hacked, owe money, or broke a rule.
  • Reward: a refund, a prize, a bonus — anything that makes you act before you reflect.
  • Familiarity: a name or logo you recognise, borrowed to lower your guard.

When a message makes you feel a strong emotion and pushes you to act immediately, that combination itself is the warning sign. Legitimate organisations rarely need you to act within minutes, and never through a link in an unexpected message.

The anatomy of a phishing message

Phishing tries to look like something you trust so you will click a link, open an attachment, or type a password into a fake page. Once you slow down, the seams usually show.

  1. Check the real sender address, not just the display name. Display names are trivial to fake; the actual address often is not the real domain.
  2. Hover over links before clicking to see where they truly lead. A button labelled "your bank" can point anywhere.
  3. Watch for lookalike domains — extra words, hyphens, or swapped letters that resemble a brand you know.
  4. Be suspicious of unexpected attachments, especially ones that ask you to enable content or macros.
  5. Notice generic greetings and small oddities in tone; automated scams often miss details a real sender would know.
Attackersends fake messageLookalike siteurgency · authorityYou typeyour passwordStolenThe trap: you never notice the address is not the real one.Type the URLyourself / bookmarkReal sitechain broken✓ safe — the link never gets a chance to fool you
Phishing routes you through a lookalike site. Typing the real address yourself breaks the chain.

The golden habit

Never log in or pay through a link in a message. Open a new tab and type the site's address yourself, or use your saved bookmark. This one habit defeats the majority of phishing.

Beyond email

Phishing has spread well past the inbox. The same techniques arrive as text messages ("smishing"), phone calls ("vishing"), fake login pop-ups, malicious ads, and direct messages on social platforms. A caller claiming to be your bank's fraud team is using authority and urgency exactly like a phishing email — so respond the same way: hang up and call the number printed on your card, not one they give you.

If you think you clicked

Mistakes happen to careful people; what matters is acting fast.

  • Change the password for that account immediately, and any other account that shared it.
  • Turn on multi-factor authentication if it was not already on.
  • Watch the account for unfamiliar activity and report it to the real organisation.
  • If it was a work account, tell your security or IT team right away — speed limits the damage.

The mindset that protects you

You do not need to be paranoid, just deliberately slow at the right moments. When a message combines a trusted-looking source, a strong emotion, and a request to click or pay, treat that as a full stop. Verify through a channel you already trust. Attackers count on speed and politeness; a short pause is often the entire defence.