Phishing & social engineering
Phishing is a message, usually email or text, that pretends to be from someone you trust in order to make you do something: click a link, enter a password, approve a payment, open an attachment. The technology behind it is simple. The skill is in the psychology, which is why it is called social engineering.
Almost every phishing message leans on the same levers: urgency ("your account will be closed in 24 hours"), authority ("this is the IT department"), fear ("suspicious sign-in detected"), or reward ("you have a refund waiting"). The goal is to make you act before you think. Well-crafted phishing now looks polished, uses correct logos and can even reference real recent events, so "it looks professional" is no longer a sign of safety.
The most reliable defence is not spotting typos. It is a habit: never act on a link or phone number inside an unexpected message. Instead, go to the service the way you normally would, through your bookmark or the app, and check there. If the problem is real, it will be waiting for you.
- Bookmark the sites that matterBank, email, tax office, payroll. Use the bookmark, never the link in a message, when there is anything to check.
- Slow down on urgencyA real organisation gives you time. Any message that says "immediately", "within 24 hours" or "final notice" earns extra suspicion.
- Verify through a second channelUnexpected request from your boss or a supplier? Call the number you already have, not the one in the message.