Quick Video
Module 4: Phishing & Social Engineering 🎣
Recognize common scams and learn strategies to avoid falling victim.
What Is Phishing?
Phishing is a cyber attack where criminals impersonate trusted sources (like banks, companies, or coworkers) to trick people into revealing sensitive information.
- Goal: Steal usernames, passwords, credit card numbers, or other personal data.
- Methods: Fake emails, text messages, phone calls, or websites.
- Example: An email that looks like it’s from your bank asking you to “verify your account” by clicking a link.
What Is Social Engineering?
Social engineering manipulates human behavior rather than exploiting technical flaws. Attackers rely on trust, fear, or urgency to trick people.
- Pretexting: Creating a false scenario to gain information (e.g., pretending to be IT support).
- Baiting: Offering something enticing (like free software) that hides malware.
- Tailgating: Following someone into a secure area without authorization.
- Example: A caller pretending to be from tech support asking for your login credentials.
🎭 Common Signs of Phishing & Scams
- Unexpected emails or messages with urgent requests
- Suspicious links or attachments
- Poor grammar, spelling mistakes, or unusual formatting
- Sender addresses that don’t match the organization’s domain
- Offers that seem “too good to be true”
🛡️ Strategies to Avoid Falling Victim
- Pause before clicking: Verify links and attachments.
- Check the sender: Confirm email addresses and phone numbers.
- Enable security tools: Use spam filters and antivirus software.
- Report suspicious activity: Alert your IT/security team.
- Educate yourself: Stay updated on common scams and tactics.
📌 Key Takeaways
- Phishing and social engineering target people, not just technology.
- Recognizing warning signs helps prevent scams.
- Awareness, caution, and reporting are critical defenses.