27. Social Engineering Awareness
27.2 Types of Social Engineering
| Type | Channel | Example |
|---|---|---|
| Phishing | A fake "your KYC expired" email with a link to a lookalike bank site | |
| Spear phishing | Email, targeted | A personalised mail to one employee, using their real name and role |
| Vishing | Voice call | "Bank officer" asking for OTP to "stop a fraudulent transaction" |
| Smishing | SMS | "Your parcel is held, pay ₹15 here: [link]" |
| Pretexting | Any | A made-up story ("I am from IT support") to gain trust |
| Baiting | Physical/USB | A malware-loaded USB left where someone will plug it in |
| Tailgating | Physical | Following an employee through a secure door without a badge |
| Quid pro quo | Any | "Free tech support" in exchange for access |
Most real attacks start with one of these, then use the technical tools from earlier chapters. The human is the entry point.
Ravindra Bagale's Tip
"Phishing only happens by email" is a misconception. These days most fraud happens over SMS (smishing) and WhatsApp – courier, electricity bill, KYC. Whatever the channel, the rule is the same: don't click links in a hurry, and never give your OTP to anyone.
Ravindra Bagale's Tip – मराठी
"Phishing फक्त email मध्ये असते" हा गैरसमज आहे. आजकाल SMS (smishing) आणि WhatsApp वर सर्वात जास्त फसवणूक होते – courier, electricity bill, KYC. Channel कोणताही असो, नियम एकच: link वर घाईने click करू नका, आणि OTP कोणालाही देऊ नका.
Ravindra Bagale's Tip – हिंदी
"Phishing सिर्फ़ email में होती है" यह गलतफ़हमी है. आजकल SMS (smishing) और WhatsApp पर सबसे ज़्यादा धोखाधड़ी होती है – courier, electricity bill, KYC. Channel कोई भी हो, नियम एक ही: link पर जल्दबाज़ी में click मत करो, और OTP किसी को मत दो.
Practice task
Match each of these to its type: a call claiming to be from the electricity board threatening disconnection; a USB drive found in the parking lot; an SMS about a held courier. Write the type and the trigger for each.