
Social engineering is a technique used by criminals and cyber-crooks to trick users into revealing confidential information. An attacker may seem unassuming and respectable, possibly claiming to be a new employee, repair person, or researcher and even offering credentials to support that identity.
Cyber criminals want your information, so they can commit identify theft or fraud – which can be avoidable if you take the right precautions. The best defense is to be aware and know what to do if you suspect you are a target.
There are three main types of social engineering attacks: phishing (email), vishing (phone), and smishing (text). Here’s some great advice on how to spot them, what to do if you receive one, and who to call if you think you’ve fallen victim to an attack.
Phishing emails are the primary attack method in the cyber criminal’s playbook. These attacks try to trick you into taking an action, such as clicking a link, opening an attachment or responding with sensitive information. We’re all a target, both at work and at home, because our information – and our devices – are worth good money to cyber criminals.
These are the most common identifiers associated with phishing attempts. Use these red flags to review all external email:
If you fall victim to a phishing attack, a swift response is pivotal. Change your password for all online accounts including your email, banking, retail, and any others. After your account access is resecured, contact your credit card company to find out if one or more of your cards should be replaced. You should also notify one of the three major credit bureaus to place a fraud alert or freeze on your account. It also can’t hurt to update your antivirus software and keep a watchful eye on all your accounts to monitor any suspicious activity over the following days.1
Vishing is a telephone-based form of social engineering where someone calls you directly and pretends to be from a legitimate company or service. Once on the line, they ask questions, try to get you to do something, or direct you to a website to obtain personal information, such as social security or financial account numbers.
If you accidentally provided your financial information to a scammer over the phone, it is crucial that you take immediate steps to protect yourself. Call your bank and alert them to the possibility of fraudulent charges – there is a chance some have already been made that need to be canceled. You’ll also probably need to cancel your cards and get new ones, and you may even need to change your account numbers. You should also put a fraud alert or freeze on your credit with one of the three major credit bureaus. In the fallout from the attack, think about red flags you can learn from and recognize in future scam attempts.2
Smishing is a form of social engineering that exploits SMS, or text, messages. Text messages can contain links to such things as webpages, email addresses or phone numbers that when clicked may automatically open a browser window or email message or dial a number.
This ruse tends to be effective because while most of us have learned to recognize phishing emails, we are still conditioned to trust text messages. Also, there’s no easy way for us to preview links in a text message like we can if we are viewing an email on a PC.
If you believe you have fallen victim to a smishing scam, change your account passwords and PINs and contact your bank to put them on watch for or cancel any fraudulent charges. You may also want to put a fraud alert or freeze on your credit with one of the three major credit bureaus.3 You should also report the attack to a law enforcement agency such as the FTC.4
Phishing, vishing, and smishing are all examples of the constantly evolving nature of criminal activity as the world moves more and more of itself into digital space. To stay on top of these threats, it’s about these threats and the resources available to you in facing them, check out the Nationwide Business Solutions Center.
[1] https://us.norton.com/internetsecurity-online-scams-what-to-do-when-you-fall-for-an-email-scam.html, Accessed September 2021.
[2] https://us.norton.com/internetsecurity-online-scams-vishing.html, Accessed September 2021.
[3] https://www.kaspersky.com/resource-center/threats/what-is-smishing-and-how-to-defend-against-it, Accessed September 2021.
[4] https://www.fcc.gov/avoid-temptation-smishing-scams, Accessed September 2021.