1. How social engineering works
Mass attacks vs targeted attacks
Not all phishing is created equal. Understanding the two ends of the spectrum helps explain why some attacks are easy to spot and others fool experienced professionals.
Mass phishing
At one end sit bulk campaigns: millions of identical emails impersonating banks, delivery companies, streaming services, or HMRC, sent to every address the attacker can find. The attacker does not know or care who you are. They only need a tiny fraction of recipients to click for the campaign to pay off.
Mass phishing is often, though not always, the easier kind to spot. Generic greetings like "Dear customer", references to services you do not use, and mismatched sender addresses are common giveaways. But volume is the point: send enough, and someone, somewhere, is expecting a parcel that day.
Spear phishing
At the other end is spear phishing: attacks crafted for a specific person or organisation. The attacker researches you first, using your company website, LinkedIn, social media, press releases, and previously leaked data. The result is a message that names your real colleagues, references a real project, mimics your supplier's invoice format, or arrives just after your company announces a new contract.
When the target is senior, a director or executive with the authority to move money or approve access, this is sometimes called whaling. These attacks are worth days of an attacker's preparation time because the payoff from one success can be enormous.
Why this matters to you
Two practical conclusions follow. First, "it looks personal and specific, so it must be genuine" is not a safe assumption. Personalisation is cheap: much of the detail an attacker needs about you and your employer is publicly available, and AI tooling has made convincing, well-written, tailored messages faster to produce than ever.
Second, your role does not exempt you. Junior staff are targeted because they are less likely to question instructions that appear to come from above. Senior staff are targeted because their accounts and approvals are worth more. Finance and HR are targeted because of what they can access. Everyone is a target, just for different reasons.
Check your understanding
A short, optional 5-question quiz on this section. It doesn't block your progress, it's just a quick self-check.
Try the section quiz →› Course contents
How social engineering works
Spotting phishing emails
Beyond email
Responding and reporting
Putting it into practice