Skip to content
Updated: 5 min read

Phishing and social engineering: how to spot an attack

Phishing and social engineering exploit psychology, not technical vulnerabilities — how to spot an attack before you click, and how to build a lasting verification habit in your team.

Adrian Kwiatkowski Author: Adrian Kwiatkowski

Phishing is an attack where someone impersonates a trusted institution or person to trick a victim into revealing data, clicking a malicious link, or making a payment. It’s one form of social engineering — a manipulation technique that exploits human behaviour rather than technical vulnerabilities in systems.

Quick Overview

What you’ll learn from this article:

  • How phishing differs from other forms of social engineering
  • Which warning signs point to a phishing attempt before you even click a link
  • What a typical attack sequence looks like, step by step
  • How to build a lasting verification habit across a team, not a one-off training session

Who this article is for: managers responsible for organisational security, HR and admin teams most often targeted by BEC attacks, and any employee using a work email account.

Reading time: 6 minutes

Phishing and social engineering: how to spot an attack

The US agency CISA defines social engineering as a manipulation technique that exploits human error rather than technical vulnerabilities to gain access to systems, networks or physical data. Phishing — an attack delivered by email or message — is its most common form, but the same manipulation logic also underlies vishing (a phone-based attack) and smishing (an SMS-based attack).

Phishing’s effectiveness doesn’t come from sophisticated technology — it comes from exploiting psychological mechanisms: time pressure (“act now or your account will be locked”), authority (“a message from the CEO”), and curiosity (“see who viewed your profile”). Understanding these mechanisms is a more effective defence than memorising a list of technical red flags.

Warning signs to watch for

SignalWhy it’s suspicious
Time pressure (“act within the hour”)The attacker wants you to skip verifying the message
Sender address slightly different from expected (e.g. @company-support.com instead of @company.com)A classic domain-spoofing technique
A request for login credentials or payment details over email/SMSLegitimate institutions don’t ask for passwords through that channel
A link pointing to a different domain than the visible text suggestsCheckable by hovering without clicking
An unusual request from a “manager” for an urgent wire transferA typical Business Email Compromise (BEC) attack pattern

A typical attack sequence, step by step

  1. Reconnaissance — the attacker gathers information about the organisation, its structure and names from publicly available sources (LinkedIn, the company website).
  2. Crafting the message — a message is created impersonating a known person or institution, tailored to the victim’s context.
  3. Delivery — the message arrives by email, SMS or messaging app, often paired with time pressure.
  4. Exploiting the reaction — the victim clicks the link, provides data, or makes a transfer before they get a chance to verify the source.

Building a lasting verification habit in your team

  • The “call to confirm” rule — any unusual request for a transfer or data, even from a “manager,” requires confirmation through a different communication channel (a phone call, not a reply to the same message).
  • Regular, short phishing simulations instead of a one-off yearly training session — a habit is built through repeated exposure, not a single presentation.
  • A no-blame reporting culture — an employee who clicked a suspicious link should feel safe reporting it immediately, rather than hiding the incident out of fear of consequences.
  • A clear, simple reporting procedure — a single “report phishing” button in the mail client is more effective than a detailed instruction nobody remembers in a stressful moment.

Read Also

Develop Your Skills

Want to raise security awareness across your team? Check out our training led by experienced EITT instructors.

➡️ Advanced Applications of SSL/TLS Protocols in Secure Communications — EITT training ➡️ Advanced Cryptographic Techniques in Information Systems — EITT training

Frequently Asked Questions (FAQ)

How does phishing differ from other forms of social engineering?

Phishing is an attack delivered by email or text message, while social engineering is a broader category of manipulation techniques that exploit human error — it also includes vishing (a phone-based attack) and smishing (an SMS-based attack). All of these forms rely on the same psychological mechanism: time pressure, authority, or the victim’s curiosity.

The simplest way is to hover your cursor over the link (without clicking) and check where it actually leads, in your browser’s status bar or your mail client. If the visible link text and the real destination address differ, or the domain looks unusual, that’s a strong warning sign.

The most important step is reporting the incident to IT/security immediately, without fear of consequences — the sooner the organisation knows about the incident, the faster it can respond (resetting passwords, monitoring the account, blocking access). An organisational culture that punishes people for reporting a mistake leads to hidden incidents and far greater damage.

Is a one-off cybersecurity training session enough for a team to recognise phishing?

No — a one-off training session builds theoretical knowledge, but not a lasting habit of recognising attacks in everyday work under time pressure. Regular, short phishing simulations spread out over time are more effective, because they exercise an actual reaction under conditions similar to a real attack.

Adrian Kwiatkowski
Adrian Kwiatkowski Opiekun szkolenia

Request a quote

Develop Your Competencies

Check out our training and workshop offerings.

Request Training
Call us +48 22 487 84 90