Table of Contents

← Return to the Personal Security Course

Every technical control in this course assumes somebody makes a good decision at the moment it matters. Social engineering targets the decision directly, which is why it survives every improvement to the layers beneath it.

Software did not stop these attacks because the software worked as designed. Someone authorized the action.

Budget about 30 minutes. One habit, calling back on a number you already had, prevents more loss than any tool in this course.

What You Will Learn

  • Explain why urgency, authority, and familiarity are the three levers in a pretext
  • Apply verification which works under pressure rather than only in calm conditions
  • Recognize phishing across email, messaging, calls, and search results
  • Assess voice cloning and video manipulation as a change to what a familiar voice proves
  • Reduce what public records and data brokers expose about you
  • Produce a verified contact list and an agreement with people who might be impersonated
TermMeaning
PretextA fabricated situation which justifies the request being made
VishingVoice phishing, where the attacker calls you rather than messaging
Callback verificationConfirming a request by calling back on a number you already had
Data brokerA company which aggregates and sells personal information
Prompt bombingFlooding approval requests until one is accepted

Why Pretexts Work

Attacks succeed by manipulating decisions, and the levers are consistent.

LeverHow It AppearsCountermeasure
UrgencyAn account closing, a payment due, a limited windowTreat speed pressure as the signal itself
AuthorityA bank, an employer, a government agency, or IT supportVerify independently before acting
FamiliarityA known name, a real colleague, a matching voiceConfirm out of band rather than in the same channel
Fear of consequenceLegal action, account loss, disciplinary outcomeSlow down deliberately
HelpfulnessA reasonable-sounding request for small assistanceNotice you are being recruited, not attacked

The most counterintuitive point: these attacks often do not feel like attacks. A request which arrives from a known name, with plausible context, and a reasonable ask produces no alarm, which is precisely the design.

Notice the emotion rather than the content. Urgency, obligation, and embarrassment are the outputs a pretext engineer aims for, and recognizing the feeling is faster than analyzing the message.

Verification Which Survives Pressure

Verification you devise in the moment is unreliable. Decide in advance.

The Callback Rule

Hang up and call back on a number you already had, from a card, a statement, or a saved contact. Never use a number supplied by the caller, even if it appears to match.

This single habit defeats vishing, bank impersonation, and many business email compromise attempts.

Agreed Verification With People You Know

Arrange a signal with family members and close contacts before it is needed. Options include a phrase, a question with an answer only you both know, or an agreed second channel.

This is worth doing with anyone who might plausibly be impersonated to you, particularly parents, adult children, and anyone with access to shared finances.

Out-of-Band Confirmation for Money

Any payment instruction which arrives by message requires confirmation through a separate channel. This applies to requests from colleagues, contractors, and family.

SituationWhat to Do
New bank details from a supplierCall the supplier on a previously known number
Urgent payment from an executiveConfirm through a known internal channel, not a reply
Family emergency requestCall the family member directly on a stored number
Crypto or gift card requestTreat as fraud until proven otherwise. Both are irreversible and favored by attackers

Warning: a request to pay by gift card, cryptocurrency, or wire transfer under time pressure is the signature of a scam. Legitimate organizations do not operate this way. Stop and verify.

Recognizing Phishing

Phishing has moved past badly spelled email, so the old tells are less useful than the structural ones.

Structural SignalWhy It Matters
Domain differs from the real onepaypa1.com and paypal-secure.net are attacker-owned. Read the domain right to left, before the first slash
Unexpected attachment or linkEven from a known contact, since accounts get compromised
Request for credentials or a codeNo legitimate organization asks for a one-time code
Channel escalationSomeone moves the conversation to messaging to avoid email controls
Payment detail changeA classic business email compromise step
Lookalike page after a redirectThe padlock does not indicate authenticity, as Module 2 established

Two habits which reduce exposure:

  • Enter addresses manually or use a bookmark for anything involving credentials
  • Treat unsolicited pop-ups as hostile, including ones warning about viruses or offering support. A legitimate warning arrives from your operating system, not a web page

Pop-ups which claim to be system alerts are a reliable sign of a scam. Close the window or the browser entirely rather than clicking anything in it.

What a Familiar Voice Proves

Voice cloning changed the threat model for verification by recognition.

A short sample of public audio is enough to produce a convincing replica. Combined with a video call using a manipulated face, the old advice to confirm the caller sounds right no longer holds.

The practical consequence: identity confirmation by voice is no longer sufficient for anything consequential. Replace it with out-of-band verification, which does not depend on recognition at all.

Old AssumptionCurrent Reality
“I recognize their voice”A clone from a few seconds of audio passes
“Their face was on the video call”Real-time face manipulation exists and is improving
“They knew our internal details”Those details are often public or leaked

This does not mean refusing every request. It means confirming consequential ones through a channel the attacker does not control, which is the callback rule applied to people as well as institutions.

Reducing Your Public Exposure

Social engineering begins with research, and a great deal of it is from public sources. Reducing what is available shortens the attacker’s starting material.

Data Brokers

  • Submit opt-out requests to the major people-search sites, and expect to repeat the process periodically
  • Never provide additional personal information when opting out. An opt-out form asking for more detail than the listing contained is a collection mechanism
  • Track what you have submitted, since re-listings are common

Domain Registration

Whois privacy protection hides your name, address, and phone from public registration records. Most registrars offer it at no cost, and it matters most if you registered a personal domain.

This connects to Module 3. A domain used for email aliasing holds your identity in its registration record unless privacy protection is enabled.

Address and Identity Separation

PracticeBenefit
Forwarding address or parcel lockerKeeps your home address out of commercial databases
Opt out of marketing listsReduces the volume of data sold onward
Review social media privacy on a scheduleTerms change, and settings revert with updates

Our Phishing Awareness Checklist covers the organizational training version of this module.

Diagram showing a social engineering attempt interrupted by out-of-band verification, where the recipient calls back on a previously known number rather than trusting the inbound contact

The Human Record

HUMAN ASPECT RECORD
Verified contact list (numbers I already had):
  Bank:                  ______________________
  Card issuer:           ______________________
  Employer IT:           ______________________
  Family members:        ______________________

Agreed verification:
  Person:                ______________________  signal: __________
  Person:                ______________________  signal: __________

Money rules I follow:
  [ ] Never act on payment details received by message alone
  [ ] Never pay by gift card, crypto, or wire under time pressure
  [ ] Always call back on a number I already had
  [ ] Confirm any executive request through a known internal channel

Public exposure reduction:
  Whois privacy enabled:  yes / no / n/a
  Broker opt-outs filed:  ______________________
  Forwarding address:     yes / no
  Social privacy reviewed: date __________

Next Steps

  1. Continue to Module 12 and cover the physical layer: Physical Security
  2. Save verified contact numbers for your bank, card issuers, and employer IT today
  3. Agree a verification signal with the two people most likely to be impersonated to you
  4. Enable Whois privacy if you own a personal domain
  5. File opt-outs with the major data brokers, and diarize a repeat in six months
  6. Read the organizational counterpart: Phishing Awareness Checklist