Cyber Security Notes— Modules 5
CYBER SECURITY NOTES
Study Notes — Modules 5
Intermediate Phase
Module 5 — Social Engineering & Phishing Awareness
Page 1
Cyber Security Notes— Modules 5
MODULE 5 — Social Engineering & Phishing Awareness
Sessions 49–58 | Duration: 15 hours | Phase: Intermediate
5.1 The Psychology Behind Social Engineering
Social engineering is the manipulation of a person — rather than a machine — into breaking normal security
procedures or divulging confidential information. It exploits predictable human psychology instead of technical
vulnerabilities.
Core Psychological Triggers
Trigger How It Is Exploited Example Phrase
Urgency Rushes the victim so they act before thinking "Your account will be suspended in 1
critically hour!"
Authority Impersonates a trusted figure (boss, bank, IT "This is IT Support — we need your
department, police) password to fix your account."
Fear Threatens a negative consequence to force "Unusual activity detected — verify
compliance now or lose access."
Curiosity Uses an intriguing hook to make the victim "See who viewed your profile!"
click/open something
Trust / Liking Builds rapport or pretends to be a A message from a 'friend's' hacked
friend/colleague account asking for money
Reciprocity Offers something first to make the victim feel A free gift or prize in exchange for
obliged to respond personal details
Key principle:
Social engineering succeeds because it targets emotion and instinct rather than logic — recognising the
emotional trigger is often the fastest way to spot an attack in progress.
5.2 Types of Social Engineering — Phishing, Vishing, Smishing
Type Channel Description Example
Phishing Email Fraudulent emails designed to steal A fake 'bank' email asking you
credentials or install malware to 'verify your account' via a
link
Spear Phishing Email Highly targeted phishing aimed at a An email referencing your
specific person using personal manager's name and a real
details ongoing project
Vishing Voice call Phone-based social engineering, A caller claiming to be from
often impersonating banks, tech your bank asking for your OTP
support, or officials
Page 2
Cyber Security Notes— Modules 5
Type Channel Description Example
Smishing SMS / text Fraudulent text messages "Your parcel could not be
message containing malicious links or delivered, click here to
requests reschedule"
5.3 Types of Social Engineering — Pretexting & Baiting
Pretexting
The attacker fabricates a believable scenario ('pretext') to justify requesting information or access.
Example:
An attacker calls the school office claiming to be a parent who 'forgot' their child's student ID number and
needs it read out over the phone to 'complete an enrolment form'.
Baiting
The attacker offers something enticing — physical or digital — to lure the victim into compromising security.
Example:
A USB drive labelled 'Confidential — Salary Data' is deliberately left in a car park. Plugging it into a curious
employee's computer silently installs malware.
5.4 Identifying Red Flags in Emails and Messages
• Sender address that looks close to genuine but is subtly wrong (e.g., support@[Link]).
• Generic greetings ('Dear Customer') instead of your actual name.
• Spelling and grammar mistakes inconsistent with a professional organisation.
• Urgent calls to action with threats (account suspension, legal action, missed deadline).
• Links where the visible text does not match the real destination URL (hover to check before clicking).
• Unexpected attachments, especially .exe, .zip, or macro-enabled Office files.
• Requests for sensitive information (passwords, OTPs, card numbers) that a legitimate organisation would
never ask for by email.
Quick Verification Checklist
1. Hover over links — does the destination URL match the claimed sender?
2. Check the sender's actual email domain, not just the display name.
3. Is the message creating unnecessary urgency or fear?
4. Contact the organisation directly through a known official channel (not via the message itself) to confirm.
5.5 Reporting Mechanisms
Reporting suspicious messages helps protect not just you, but the wider community, by allowing providers to
block the sender and warn other users.
Page 3
Cyber Security Notes— Modules 5
Channel How to Report
School / Organisation IT Forward the suspicious email to the internal IT/security helpdesk; do not
reply to the sender
Email Provider Use the built-in 'Report phishing' / 'Report spam' option in Gmail,
Outlook, etc.
Mobile Carrier Forward smishing texts to the carrier's spam-reporting short code (e.g.,
7726 'SPAM' in many regions)
National CERT / Cyber Cell Report serious incidents to your country's Computer Emergency
Response Team or cybercrime portal
5.6 Hands-On Labs & Activities — Module 5
🧪 Hands-On Lab Activities
• Analyse sample phishing emails (Set 1): identify sender, links, and red flags using the checklist above.
• Analyse sample phishing emails (Set 2): a second, more advanced set including spear -phishing
examples.
• "Spot the Phish" group challenge: teams compete to correctly classify a mixed set of real and fake
messages.
• Draft a phishing-awareness poster or short message aimed at educating peers.
• Practical exercise: walk through the full process of reporting a phishing attempt using a mock scenario.
Module 5 — Key Takeaways
• Social engineering exploits urgency, authority, fear, curiosity, trust, and reciprocity — not technical flaws.
• Phishing (email), vishing (voice), and smishing (SMS) are channel variants of the same manipulation tactic.
• Pretexting relies on a fabricated story; baiting relies on a tempting offer or object.
• Always verify sender, links, and urgency before acting — and use the organisation's official reporting
Channel.
Page 4