How to spot social engineering and protect your accounts
We share this article to help you learn how to spot social engineering and protect your accounts. A few figures from a third-party source show the scale of the problem. However, Activest has not independently verified them, and some date from 2020 and 2021.
- Attackers reportedly hack about 30,000 websites worldwide each day.
- Roughly 64% of companies worldwide have experienced at least one form of cyber attack.
- March 2021 alone saw about 20 million breached records.
- Meanwhile, ransomware cases grew by about 150% in 2020.
- Email delivers around 94% of all malware.
- On average, a new attack occurs somewhere on the web every 39 seconds.
- Security tools block an average of around 24,000 malicious mobile apps daily.
Source: techjury.net
Where social engineering fits
Increasingly, attackers pair social engineering with technical cyber attacks to obtain information from the victim. In other words, social engineering is the practice of manipulating and deceiving someone to gain control of private information. For example, an attacker may use the phone, email or direct contact. The goal is to gain illegal access to sensitive details such as usernames, passwords and account information.
How to spot social engineering and protect your accounts
Start with email. The same source ties most malware to email, including viruses and other malicious programs. Therefore, treat any email that asks you to change account credentials or transfer funds as a warning sign. Do not answer it, click its links or reply with any information. Instead, contact the sender through a phone number you already know is genuine.
Common tactics to watch for
Social engineering usually relies on pressure rather than technical skill. First, an attacker may create a sense of urgency. The message may claim that an account will close or a payment will fail unless you act at once. Next, the message may appear to come from someone you trust, such as a colleague, a bank or a service provider. In addition, the sender may ask you to keep the request private or to skip your usual checks.
Look closely at the details. For instance, a display name can look familiar while the actual email address contains small misspellings. Links may also point to a website that imitates a real login page. As a result, a quick glance is often not enough to judge whether a message is safe.
Phone calls, texts and direct contact
Email is not the only channel. Callers may pose as support staff and ask you to read out a code that your bank or app sent to your phone. Meanwhile, text messages can carry links that lead to fake sites or harmful apps. In person, someone may simply ask for help getting into a building or borrowing a device. In each case, the safest response is to pause and verify the request independently.
Everyday steps that reduce your risk
Learning how to spot social engineering and protect your accounts works best when you pair awareness with simple habits. Consider the following steps:
- First, use a unique, strong password for each important account.
- Next, turn on multi-factor authentication wherever it is available.
- In addition, keep your devices and apps updated with the latest security patches.
- Review your account statements regularly for activity you do not recognize.
- Finally, never share one-time codes, passwords or PINs with anyone who contacts you.
Above all, give yourself permission to slow down. A legitimate organization will understand if you hang up and call back on a verified number. In practice, that short delay is often enough to stop a scam before it causes harm.
Of course, no single habit can stop every attack, and criminals may also use calls or texts. As a matter of policy, Activest does not ask clients to change accounts or make transfers by email. Most importantly, if you suspect unusual activity, please contact our office right away.