
April 24, 2024
Social engineering is a type of cybercrime. Fraudsters use various techniques to trick people into carrying out things like transferring money, giving away confidential information or sensitive data, or installing malware.
“Social engineers” use various means to carry out their crimes. It might be by email, phone, text message or social media. However they do it, the financial repercussions can be devastating. And the problem is ever-growing.
In 2022, there were 1.2 million+ unique phishing sites detected around the world
Social engineering accounts for 98% of all cyber-attacks
In this article, the latest in our cybersecurity series, we’ll be looking at:
- The different types of social engineering threats
- How to defend against social engineering attacks
- How cyber insurance can help protect against the financial impact of social engineering fraud
What are the different types of social engineering?
There are numerous cybercrimes under the banner of social engineering:
Phishing
Phishing is the most common form of social engineering. It involves attackers deceiving people into revealing sensitive information such as passwords or bank details, or installing malware such as ransomware.
Example: An email ‘from the recipient’s bank’ states that they’ve detected unusual activity on their account. The email prompts the recipient to click a link to ‘secure their account’, but in doing so, they unwittingly install malware on their system, providing an inroad for cybercriminals to steal their data.
Angler phishing
Unlike traditional phishing that uses email, angler phishing targets social media users. Hackers create fake social media accounts, and pretend to be an employee of a legitimate company.
They then contact customers who’ve made complaints to that company via social media, convincing them to disclose private information such as passwords, or install malware, which can monitor device activity, harvest confidential information or launch a cyberattack.
Example: A customer complains via social media that they are having issues accessing their bank account. An attacker quickly creates a fake profile, then contacts the target posing as a customer care agent, offering assistance in return for the target’s bank account login details.
Spear phishing
This is a form of email attack where cyber fraudsters target a specific victim, as opposed to general phishing attacks that blanket target hundreds of people. It can be quite tricky to detect, because the victim is personally addressed.
Again, the criminal looks to steal sensitive information, such as login details, or infect the victim’s device with malware. The core aim of the spear phishing criminal is to obtain trade secrets or confidential information, which they can sell for large sums of money.
Example: An attacker sends an email based on the target’s publicly known interests. For example, if the target is a known travel enthusiast, the spear phisher might send an email suggesting they visit the website of a spoof travel website that’s currently offering a limited time deal. The site is malicious, and only serves to steal personal data and payment credentials.

There are various types of phishing scams to be aware of
Whaling (‘CEO fraud’)
Also known as ‘CEO fraud’, whaling sees criminals posing as influential members of an organisation, such as the CEO or financial director. They email their trusting staff, requesting they provide them with sensitive data, or asking them to transfer money.
Numerous big name organisations have fallen victim to whaling scams, including Snapchat, and toy giant Mattel, which lost almost $3 million as a result.
Example: An accounts assistant receives an email from their ‘finance director’ requesting they send them payroll information about current and past employees. But the person requesting the information is in fact a fraudster, mining for personal data.
Business email compromise
Business email compromise scams involve cybercriminals tricking unsuspecting people into handing over money or sensitive data.
The criminal poses as someone the victim trusts. They then ask for a fake bill to be paid, or request personal data that they can use in another scam.
Example: A company ‘supplier’ emails accounts payable advising them that their latest invoice should be paid using updated bank account details. The ‘supplier’ is in fact a fraudster, and the funds are directed into their account, leaving the genuine supplier unpaid, and the company out of pocket thinking they’ve paid a legitimate bill.
Pharming
Pharming involves installing malicious code on a personal computer. This then redirects website visitors from a genuine site to a malicious site that is barely distinguishable from the real one.
Once the visitor inputs their personal credentials or financial information, it is stolen by the fraudster responsible for setting up the malicious site.
Example: A user opens their browser and enters the web address of their bank in order to complete an online transaction. But the user is redirected to a malicious site, which harvests their login details.
Smishing (SMS phishing)
There are few people who won’t have received a bogus text message from what appears to be a legitimate organisation.
The messages are designed to trick the recipient into disclosing information, such as credit card details, passwords or account or identity numbers in exchange for a ‘reward’, such as compensation, a rebate or refund.
Example: A text message claims to be from HMRC saying they’re in line for a tax rebate and asking the recipient to verify their account details by clicking a link or downloading an attachment. But the link or attachment only serves to install malware on the victim’s device.
Quid pro quo
Cyber attackers contact random people at a company, claiming to be calling for a legitimate reason. It’s a ‘luck of the draw’ approach that can eventually result in finding someone with a genuine issue who is grateful for the assistance.
The fraudster will then attempt to glean sensitive information from the victim, whilst assisting with their problem.
Example: An individual posing as an IT expert offers to fix a PC in exchange for a password, or remote access to a network.
Vishing (voice phishing)
Vishing is a phone-based social engineering attack. The victim receives a call with a usually urgent-sounding recorded message.
They are then prompted to enter sensitive information such as credit card numbers, bank details or passwords through their phone keypad, providing the scammer with access to their accounts.
The fraudsters create fake caller ID profiles to make them look like they’re calling from a local area or a trusted business.
Example: A voice message from a bank’s ‘fraud team’ warns there’s unusual activity on a card or account. The recipient is prompted to disclose their login information, card number or PIN, and sometimes even a One Time Password. But the ‘fraud team’ was actually a fraudster, phishing for personal information.
Water-holing
Water holing attacks involve a chain of events triggered by an attacker to gain access to a victim. The attacker researches and identifies a website that the victim uses regularly, and places malicious code into it.
When the victim visits the site, it starts to infect their device, allowing the attacker to access other assets on the network, and use that device to launch a wider attack to achieve other goals.
Example: A cybercriminal compromises the WiFi network at a public place, leading to users unknowingly downloaded malware as they connect. The criminal then uses this as a backdoor to obtain sensitive information.
Advance fee scams
Scammers email victims asking for their bank details or a fee to help them transfer money out of their country, or in order to claim a prize.
Example: An email from a ‘solicitor’ informs the recipient they are the only living relative of a deceased client. In order to receive their inheritance, they need an upfront fee to cover their legal costs in dealing with the estate. Of course, there is no such inheritance.
How to defend against social engineering attacks?
Defending against social engineering attacks requires a blend of awareness, education and robust security practices.
Employee training
Regular training for staff about common social engineering tactics is vital. Teach them how to recognise suspicious requests, looking out for the likes of:
- Suspicious emails or text messages containing spelling or grammar errors
- Requests for money or personal information
- Calls to action, such as clicking a link or downloading an attachment
- Unfamiliar or unusual email or message senders
- Emails that do not personally address the recipient
- Pressure to respond urgently
Verify requests
Encourage staff to check any unusual requests, especially those involving financial transactions or asking to supply sensitive data.
They should be advised to make enquiries through a separate communication channel rather than replying directly to an email. Or, better still, speak to the person who has made the request face to face.
Policies and procedures
Establish clear policies and procedures and handling sensitive information, and for conducting financial transactions.
Use the ‘least privilege’ approach to limit access to information and systems based on job roles and responsibilities.
Use Multi-Factor Authentication
Make it mandatory for staff to use multi-factor authentication to access sensitive systems and data.
This adds an extra layer of security beyond passwords, making it more difficult for attackers to gain unauthorised access.
Keep software updated
Vulnerabilities in outdated software are easily exploited by attackers.
Therefore, ensure all software, including operating systems, antivirus and applications, are regularly updated with the latest security patches and fixes.
Use monitoring tools
Invest in security measures such as intrusion detection systems, and security information and event management tools, to monitor user behaviour and network activity for signs of unusual or suspicious goings on.
There are also useful email monitoring systems that will flag up or quarantine messages that are have a high likelihood of coming from phishing criminals so that they can be assessed before they do any damage.
Incident response plan
It’s important to have an action plan at the ready so that you are prepared in the event of a social engineering attack.
Your plan should include procedures for containing the incident, mitigating damage, and launching a communications strategy.
For example, if login details have been shared with a fraudster, steps should be taken to urgently reset those details. In cases where banking information has been exposed, the bank should be contacted immediately so that accounts can be frozen. And if malware has been installed, then a device or system scan should be carried out to check for potentially harmful files.

Defending against social engineering attacks requires a blend of awareness, education and robust security practices.
How can cyber insurance protect against the risks of social engineering?
Cyber insurance is a valuable tool for reducing the monetary risks connected with all types of cybercrime. Depending on the specific cover, it may also provide valuable resources to help manage and recover from cyber incidents.
A critical aspect of cyber insurance is social engineering cover. This provides financial protection against losses resulting from fraudulent activities, or fraudulent instructions obtained via deceptive tactics, such as unwittingly making payments to a cybercriminal’s bank account instead of a legitimate account.
The cover is designed to help businesses recover from financial losses, to cover legal expenses, and to restore their reputation after falling victim to an attack.
What does social engineering cover in a cyber insurance policy include?
Social engineering cover may include various components:
Funds transfer fraud – Cover for losses resulting from the fraudulent transfer of funds resulting from a social engineering attack.
Impersonation fraud – Protection against losses caused when a criminal impersonates an authorised individual or organisation.
Phishing – Cover for losses resulting from phishing emails, deceptive websites or calls that trick individuals into sharing sensitive information.
Staff training – Certain policies may offer cover for the costs associated with training staff to recognise and respond to social engineering attempts.
Incident response and forensic services – Covering the costs of investigating and mitigating the impact of a social engineering attack.
Reputational damage – Financial cover for the communications expenses involved in managing reputational damage.
Legal expenses – Cover for the legal fees and liabilities resulting from social engineering attacks, including regulatory fines and civil action awards.

Social engineering cyber insurance cover includes various components.
Cyber insurance is a proactive way to mitigate the potential damage that can be caused by the ever-prevalent threat of social engineering.
As cyber threats keep evolving, it is vital to stay ahead by putting robust risk management strategies in place. Cyber insurance being one of them.
For advice on protecting against social engineering attacks with insurance cover tailored to your specific needs, we welcome you to get in touch with our dedicated cyber protection team.
Share This Story, Choose Your Platform!
Social engineering is a type of cybercrime. Fraudsters use various techniques to trick people into carrying out things like transferring money, giving away confidential information or sensitive data, or installing malware.
“Social engineers” use various means to carry out their crimes. It might be by email, phone, text message or social media. However they do it, the financial repercussions can be devastating. And the problem is ever-growing.
In 2022, there were 1.2 million+ unique phishing sites detected around the world
Social engineering accounts for 98% of all cyber-attacks
In this article, the latest in our cybersecurity series, we’ll be looking at:
- The different types of social engineering threats
- How to defend against social engineering attacks
- How cyber insurance can help protect against the financial impact of social engineering fraud
What are the different types of social engineering?
There are numerous cybercrimes under the banner of social engineering:
Phishing
Phishing is the most common form of social engineering. It involves attackers deceiving people into revealing sensitive information such as passwords or bank details, or installing malware such as ransomware.
Example: An email ‘from the recipient’s bank’ states that they’ve detected unusual activity on their account. The email prompts the recipient to click a link to ‘secure their account’, but in doing so, they unwittingly install malware on their system, providing an inroad for cybercriminals to steal their data.
Angler phishing
Unlike traditional phishing that uses email, angler phishing targets social media users. Hackers create fake social media accounts, and pretend to be an employee of a legitimate company.
They then contact customers who’ve made complaints to that company via social media, convincing them to disclose private information such as passwords, or install malware, which can monitor device activity, harvest confidential information or launch a cyberattack.
Example: A customer complains via social media that they are having issues accessing their bank account. An attacker quickly creates a fake profile, then contacts the target posing as a customer care agent, offering assistance in return for the target’s bank account login details.
Spear phishing
This is a form of email attack where cyber fraudsters target a specific victim, as opposed to general phishing attacks that blanket target hundreds of people. It can be quite tricky to detect, because the victim is personally addressed.
Again, the criminal looks to steal sensitive information, such as login details, or infect the victim’s device with malware. The core aim of the spear phishing criminal is to obtain trade secrets or confidential information, which they can sell for large sums of money.
Example: An attacker sends an email based on the target’s publicly known interests. For example, if the target is a known travel enthusiast, the spear phisher might send an email suggesting they visit the website of a spoof travel website that’s currently offering a limited time deal. The site is malicious, and only serves to steal personal data and payment credentials.

There are various types of phishing scams to be aware of
Whaling (‘CEO fraud’)
Also known as ‘CEO fraud’, whaling sees criminals posing as influential members of an organisation, such as the CEO or financial director. They email their trusting staff, requesting they provide them with sensitive data, or asking them to transfer money.
Numerous big name organisations have fallen victim to whaling scams, including Snapchat, and toy giant Mattel, which lost almost $3 million as a result.
Example: An accounts assistant receives an email from their ‘finance director’ requesting they send them payroll information about current and past employees. But the person requesting the information is in fact a fraudster, mining for personal data.
Business email compromise
Business email compromise scams involve cybercriminals tricking unsuspecting people into handing over money or sensitive data.
The criminal poses as someone the victim trusts. They then ask for a fake bill to be paid, or request personal data that they can use in another scam.
Example: A company ‘supplier’ emails accounts payable advising them that their latest invoice should be paid using updated bank account details. The ‘supplier’ is in fact a fraudster, and the funds are directed into their account, leaving the genuine supplier unpaid, and the company out of pocket thinking they’ve paid a legitimate bill.
Pharming
Pharming involves installing malicious code on a personal computer. This then redirects website visitors from a genuine site to a malicious site that is barely distinguishable from the real one.
Once the visitor inputs their personal credentials or financial information, it is stolen by the fraudster responsible for setting up the malicious site.
Example: A user opens their browser and enters the web address of their bank in order to complete an online transaction. But the user is redirected to a malicious site, which harvests their login details.
Smishing (SMS phishing)
There are few people who won’t have received a bogus text message from what appears to be a legitimate organisation.
The messages are designed to trick the recipient into disclosing information, such as credit card details, passwords or account or identity numbers in exchange for a ‘reward’, such as compensation, a rebate or refund.
Example: A text message claims to be from HMRC saying they’re in line for a tax rebate and asking the recipient to verify their account details by clicking a link or downloading an attachment. But the link or attachment only serves to install malware on the victim’s device.
Quid pro quo
Cyber attackers contact random people at a company, claiming to be calling for a legitimate reason. It’s a ‘luck of the draw’ approach that can eventually result in finding someone with a genuine issue who is grateful for the assistance.
The fraudster will then attempt to glean sensitive information from the victim, whilst assisting with their problem.
Example: An individual posing as an IT expert offers to fix a PC in exchange for a password, or remote access to a network.
Vishing (voice phishing)
Vishing is a phone-based social engineering attack. The victim receives a call with a usually urgent-sounding recorded message.
They are then prompted to enter sensitive information such as credit card numbers, bank details or passwords through their phone keypad, providing the scammer with access to their accounts.
The fraudsters create fake caller ID profiles to make them look like they’re calling from a local area or a trusted business.
Example: A voice message from a bank’s ‘fraud team’ warns there’s unusual activity on a card or account. The recipient is prompted to disclose their login information, card number or PIN, and sometimes even a One Time Password. But the ‘fraud team’ was actually a fraudster, phishing for personal information.
Water-holing
Water holing attacks involve a chain of events triggered by an attacker to gain access to a victim. The attacker researches and identifies a website that the victim uses regularly, and places malicious code into it.
When the victim visits the site, it starts to infect their device, allowing the attacker to access other assets on the network, and use that device to launch a wider attack to achieve other goals.
Example: A cybercriminal compromises the WiFi network at a public place, leading to users unknowingly downloaded malware as they connect. The criminal then uses this as a backdoor to obtain sensitive information.
Advance fee scams
Scammers email victims asking for their bank details or a fee to help them transfer money out of their country, or in order to claim a prize.
Example: An email from a ‘solicitor’ informs the recipient they are the only living relative of a deceased client. In order to receive their inheritance, they need an upfront fee to cover their legal costs in dealing with the estate. Of course, there is no such inheritance.
How to defend against social engineering attacks?
Defending against social engineering attacks requires a blend of awareness, education and robust security practices.
Employee training
Regular training for staff about common social engineering tactics is vital. Teach them how to recognise suspicious requests, looking out for the likes of:
- Suspicious emails or text messages containing spelling or grammar errors
- Requests for money or personal information
- Calls to action, such as clicking a link or downloading an attachment
- Unfamiliar or unusual email or message senders
- Emails that do not personally address the recipient
- Pressure to respond urgently
Verify requests
Encourage staff to check any unusual requests, especially those involving financial transactions or asking to supply sensitive data.
They should be advised to make enquiries through a separate communication channel rather than replying directly to an email. Or, better still, speak to the person who has made the request face to face.
Policies and procedures
Establish clear policies and procedures and handling sensitive information, and for conducting financial transactions.
Use the ‘least privilege’ approach to limit access to information and systems based on job roles and responsibilities.
Use Multi-Factor Authentication
Make it mandatory for staff to use multi-factor authentication to access sensitive systems and data.
This adds an extra layer of security beyond passwords, making it more difficult for attackers to gain unauthorised access.
Keep software updated
Vulnerabilities in outdated software are easily exploited by attackers.
Therefore, ensure all software, including operating systems, antivirus and applications, are regularly updated with the latest security patches and fixes.
Use monitoring tools
Invest in security measures such as intrusion detection systems, and security information and event management tools, to monitor user behaviour and network activity for signs of unusual or suspicious goings on.
There are also useful email monitoring systems that will flag up or quarantine messages that are have a high likelihood of coming from phishing criminals so that they can be assessed before they do any damage.
Incident response plan
It’s important to have an action plan at the ready so that you are prepared in the event of a social engineering attack.
Your plan should include procedures for containing the incident, mitigating damage, and launching a communications strategy.
For example, if login details have been shared with a fraudster, steps should be taken to urgently reset those details. In cases where banking information has been exposed, the bank should be contacted immediately so that accounts can be frozen. And if malware has been installed, then a device or system scan should be carried out to check for potentially harmful files.

Defending against social engineering attacks requires a blend of awareness, education and robust security practices.
How can cyber insurance protect against the risks of social engineering?
Cyber insurance is a valuable tool for reducing the monetary risks connected with all types of cybercrime. Depending on the specific cover, it may also provide valuable resources to help manage and recover from cyber incidents.
A critical aspect of cyber insurance is social engineering cover. This provides financial protection against losses resulting from fraudulent activities, or fraudulent instructions obtained via deceptive tactics, such as unwittingly making payments to a cybercriminal’s bank account instead of a legitimate account.
The cover is designed to help businesses recover from financial losses, to cover legal expenses, and to restore their reputation after falling victim to an attack.
What does social engineering cover in a cyber insurance policy include?
Social engineering cover may include various components:
Funds transfer fraud – Cover for losses resulting from the fraudulent transfer of funds resulting from a social engineering attack.
Impersonation fraud – Protection against losses caused when a criminal impersonates an authorised individual or organisation.
Phishing – Cover for losses resulting from phishing emails, deceptive websites or calls that trick individuals into sharing sensitive information.
Staff training – Certain policies may offer cover for the costs associated with training staff to recognise and respond to social engineering attempts.
Incident response and forensic services – Covering the costs of investigating and mitigating the impact of a social engineering attack.
Reputational damage – Financial cover for the communications expenses involved in managing reputational damage.
Legal expenses – Cover for the legal fees and liabilities resulting from social engineering attacks, including regulatory fines and civil action awards.

Social engineering cyber insurance cover includes various components.
Cyber insurance is a proactive way to mitigate the potential damage that can be caused by the ever-prevalent threat of social engineering.
As cyber threats keep evolving, it is vital to stay ahead by putting robust risk management strategies in place. Cyber insurance being one of them.
For advice on protecting against social engineering attacks with insurance cover tailored to your specific needs, we welcome you to get in touch with our dedicated cyber protection team.

