3. Beyond email
Deepfakes, social media pretexting and MFA fatigue
Three newer techniques are worth knowing about, because each defeats a safeguard people instinctively rely on.
Deepfake voice and video
Voice cloning tools can now produce a convincing copy of someone's voice from a small sample of recorded speech, and video impersonation on live calls is no longer science fiction. There have been real cases of employees authorising large transfers after video calls with what appeared to be their own senior colleagues.
The uncomfortable conclusion: hearing a familiar voice, or seeing a familiar face on a call, is no longer proof of identity when the request is sensitive. The defence is the same one this course keeps returning to: verify unusual requests, especially payments and credential changes, through a separate channel you initiate yourself. Call the person back on their known number. Some teams also agree simple verbal code words for authorising payments, a low-tech control that deepfakes cannot copy.
Social media pretexting
Pretexting means building a believable scenario before making the real request. Fake recruiters approach staff on LinkedIn with flattering roles, then send "job descriptions" carrying malware or invite targets to fraudulent interviews to harvest information. Fake profiles connect with you weeks before any attack, so the eventual approach comes from an established contact.
Your public footprint feeds this. Job titles, colleague names, projects, suppliers, office photos, and out-of-office replies all help an attacker impersonate you or target you convincingly. You do not need to abandon social media, but be conscious that what you post is reconnaissance material, and be sceptical of unsolicited approaches, however flattering.
MFA fatigue attacks
Multi-factor authentication is one of our strongest defences, so attackers now attack the human step in it. In an MFA fatigue (or push bombing) attack, a criminal who already has your password triggers login prompt after login prompt to your phone, sometimes at night, hoping you will eventually approve one out of annoyance or confusion. Some follow up with a call impersonating IT support, asking you to "approve the prompt so we can fix the issue".
The rule is absolute: never approve an MFA prompt for a login you did not just attempt yourself. An unexpected prompt means someone has your password. Deny it, and report it to IT immediately so the password can be changed.
Check your understanding
A short, optional 5-question quiz on this section. It doesn't block your progress, it's just a quick self-check.
Try the section quiz →› Course contents
How social engineering works
Spotting phishing emails
Beyond email
Responding and reporting
Putting it into practice