Social Engineering
Social Engineering
Section titled “Social Engineering”Social engineering bypasses encryption, MFA, and most technical controls by targeting the human. It is still the most effective initial-access technique used by both nation-state and criminal actors — including against communities that otherwise practice strong digital hygiene.
“Phishing remains one of the most unsophisticated, yet effective means of cyber compromise, often rendering other protections irrelevant including end-to-end encryption.” — FBI/CISA PSA I-032026, March 2026
Pages in this section
Section titled “Pages in this section”- Phishing — Defender’s Guide — How to recognize, verify, report, and recover from phishing across email, SMS, voice, QR, and in-app messages.
- Signal/CMA Account Takeover — Russian Intelligence Services — Active campaign. RIS actors targeting Signal and other commercial messaging apps via linked-device QR abuse and 2FA code phishing. FBI/CISA PSA, March 2026.
Common patterns
Section titled “Common patterns”Across vectors, social engineering attacks share a recognizable shape:
- Pretext — actor establishes a context (impersonates a contact, a “support” account, a service, a deadline)
- Urgency — manufactured time pressure (“suspicious activity detected,” “your account will be locked”)
- Authority — claim to represent something official (Signal Security, IT department, FBI, a known executive)
- Action — request the victim do something they wouldn’t normally do (type a code, click a link, scan a QR, install an app, transfer money, run a script)
- Quiet — instruct the victim not to verify out-of-band (“don’t tell anyone, including Signal employees”)
If a message hits 3 or more of these in a row, treat it as phishing until proven otherwise.
Sub-vectors (planned)
Section titled “Sub-vectors (planned)”The general Phishing — Defender’s Guide covers all of the below at a working level. Dedicated sub-vector pages will be split out as content depth justifies it. Contributions welcome.
- Smishing — SMS phishing, common lures, carrier reporting channels (covered in the general phishing guide)
- Vishing — voice phishing, AI-cloned voice, callback scams (covered in the general phishing guide)
- QR code phishing (quishing) — physical and digital QR-based lures (covered in the general phishing guide)
- Verification code theft — the “read me the code your bank just sent” pattern (see also the Signal/RIS page)
- Impersonation — fake executive / fake contact / fake support
- Business email compromise — wire-fraud and invoice-redirect schemes
Related
Section titled “Related”- Adversary Threats Catalog
- Digital Force Protection Guide — prevention baseline
- Cyber Incident Response Guide — response playbook
- Email Hardening Guide — phishing-resistant email setup