Social Engineering
Social Engineering
Social engineering
Activity 1: Phishing
A phishing attack is an attack in which the victim receives an email disguised to look
as if it has come from a reputable source, in order to trick them into giving up
valuable data.
The email usually provides a link to another website where the information can be
inputted.
What three pieces of advice would you give to someone to stop them from becoming
the victim of a phishing attack?
1.
2.
3.
Underline and number the parts of the email that make it suspicious; complete the
table below to describe why it’s suspicious (an example has been provided).
Number Reason
1.
2.
3.
Page 2
Activity 3: Protecting your customers
Put yourself in the shoes of the cybersecurity team of a national bank. Your job is to
try to prevent your customers becoming victims of social engineering.
Shouldering
What is shouldering?
Page 3
4.2 Blagging/phishing email
Write a short blagging email that tries to convince the recipient that they need to
send you some money. Add in some obvious characteristics that are common in
blagging emails.
1.
2.
3.
Page 4
Explorer activity
Using the links to the UK National Cyber Security website to help you, answer the
following questions:
Describe what is
meant by the term
‘spear phishing’?
(https://
www.ncsc.gov.uk/
guidance/phishing)
(https://
www.ncsc.gov.uk/
guidance/suspicious-
email-actions)
What is two-factor
authentication?
(https://
www.ncsc.gov.uk/
guidance/setting-two-
factor-authentication-
2fa)
Page 5
Page 6