0% found this document useful (0 votes)
3 views4 pages

Module 5 Notes

Module 5 focuses on social engineering and phishing awareness, highlighting the psychological triggers used by attackers to manipulate victims into divulging confidential information. It outlines various types of social engineering tactics such as phishing, vishing, smishing, pretexting, and baiting, along with red flags to identify suspicious communications. The module emphasizes the importance of verification and reporting mechanisms to protect individuals and the wider community from cyber threats.

Uploaded by

jerry.maxinek
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
3 views4 pages

Module 5 Notes

Module 5 focuses on social engineering and phishing awareness, highlighting the psychological triggers used by attackers to manipulate victims into divulging confidential information. It outlines various types of social engineering tactics such as phishing, vishing, smishing, pretexting, and baiting, along with red flags to identify suspicious communications. The module emphasizes the importance of verification and reporting mechanisms to protect individuals and the wider community from cyber threats.

Uploaded by

jerry.maxinek
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Cyber Security Notes— Modules 5

CYBER SECURITY NOTES


Study Notes — Modules 5
Intermediate Phase

Module 5 — Social Engineering & Phishing Awareness

Page 1
Cyber Security Notes— Modules 5

MODULE 5 — Social Engineering & Phishing Awareness


Sessions 49–58 | Duration: 15 hours | Phase: Intermediate

5.1 The Psychology Behind Social Engineering


Social engineering is the manipulation of a person — rather than a machine — into breaking normal security
procedures or divulging confidential information. It exploits predictable human psychology instead of technical
vulnerabilities.

Core Psychological Triggers

Trigger How It Is Exploited Example Phrase

Urgency Rushes the victim so they act before thinking "Your account will be suspended in 1
critically hour!"

Authority Impersonates a trusted figure (boss, bank, IT "This is IT Support — we need your
department, police) password to fix your account."

Fear Threatens a negative consequence to force "Unusual activity detected — verify


compliance now or lose access."

Curiosity Uses an intriguing hook to make the victim "See who viewed your profile!"
click/open something

Trust / Liking Builds rapport or pretends to be a A message from a 'friend's' hacked


friend/colleague account asking for money

Reciprocity Offers something first to make the victim feel A free gift or prize in exchange for
obliged to respond personal details

Key principle:
Social engineering succeeds because it targets emotion and instinct rather than logic — recognising the
emotional trigger is often the fastest way to spot an attack in progress.

5.2 Types of Social Engineering — Phishing, Vishing, Smishing


Type Channel Description Example

Phishing Email Fraudulent emails designed to steal A fake 'bank' email asking you
credentials or install malware to 'verify your account' via a
link

Spear Phishing Email Highly targeted phishing aimed at a An email referencing your
specific person using personal manager's name and a real
details ongoing project

Vishing Voice call Phone-based social engineering, A caller claiming to be from


often impersonating banks, tech your bank asking for your OTP
support, or officials

Page 2
Cyber Security Notes— Modules 5

Type Channel Description Example

Smishing SMS / text Fraudulent text messages "Your parcel could not be
message containing malicious links or delivered, click here to
requests reschedule"

5.3 Types of Social Engineering — Pretexting & Baiting


Pretexting
The attacker fabricates a believable scenario ('pretext') to justify requesting information or access.

Example:
An attacker calls the school office claiming to be a parent who 'forgot' their child's student ID number and
needs it read out over the phone to 'complete an enrolment form'.

Baiting
The attacker offers something enticing — physical or digital — to lure the victim into compromising security.

Example:
A USB drive labelled 'Confidential — Salary Data' is deliberately left in a car park. Plugging it into a curious
employee's computer silently installs malware.

5.4 Identifying Red Flags in Emails and Messages


• Sender address that looks close to genuine but is subtly wrong (e.g., support@[Link]).
• Generic greetings ('Dear Customer') instead of your actual name.
• Spelling and grammar mistakes inconsistent with a professional organisation.
• Urgent calls to action with threats (account suspension, legal action, missed deadline).
• Links where the visible text does not match the real destination URL (hover to check before clicking).
• Unexpected attachments, especially .exe, .zip, or macro-enabled Office files.
• Requests for sensitive information (passwords, OTPs, card numbers) that a legitimate organisation would
never ask for by email.

Quick Verification Checklist


1. Hover over links — does the destination URL match the claimed sender?
2. Check the sender's actual email domain, not just the display name.
3. Is the message creating unnecessary urgency or fear?
4. Contact the organisation directly through a known official channel (not via the message itself) to confirm.

5.5 Reporting Mechanisms


Reporting suspicious messages helps protect not just you, but the wider community, by allowing providers to
block the sender and warn other users.

Page 3
Cyber Security Notes— Modules 5

Channel How to Report

School / Organisation IT Forward the suspicious email to the internal IT/security helpdesk; do not
reply to the sender

Email Provider Use the built-in 'Report phishing' / 'Report spam' option in Gmail,
Outlook, etc.

Mobile Carrier Forward smishing texts to the carrier's spam-reporting short code (e.g.,
7726 'SPAM' in many regions)

National CERT / Cyber Cell Report serious incidents to your country's Computer Emergency
Response Team or cybercrime portal

5.6 Hands-On Labs & Activities — Module 5

🧪 Hands-On Lab Activities


• Analyse sample phishing emails (Set 1): identify sender, links, and red flags using the checklist above.
• Analyse sample phishing emails (Set 2): a second, more advanced set including spear -phishing
examples.
• "Spot the Phish" group challenge: teams compete to correctly classify a mixed set of real and fake
messages.
• Draft a phishing-awareness poster or short message aimed at educating peers.
• Practical exercise: walk through the full process of reporting a phishing attempt using a mock scenario.

Module 5 — Key Takeaways


• Social engineering exploits urgency, authority, fear, curiosity, trust, and reciprocity — not technical flaws.
• Phishing (email), vishing (voice), and smishing (SMS) are channel variants of the same manipulation tactic.
• Pretexting relies on a fabricated story; baiting relies on a tempting offer or object.
• Always verify sender, links, and urgency before acting — and use the organisation's official reporting
Channel.

Page 4

You might also like