July 27, 2026 phishing habits

Most account compromises start with a person being tricked, not a system being hacked

When people think about accounts being compromised, they tend to picture something technical — software vulnerabilities, code exploits, servers being broken into. This happens. But a much larger portion of real-world account compromises start somewhere simpler: a person was convinced to do something they shouldn't have.

Social engineering is the practice of manipulating people into taking actions that benefit an attacker. It doesn't require hacking anything. It just requires understanding how people respond to certain kinds of pressure, and applying that pressure.

The reason it works so consistently is that the techniques exploit cognitive shortcuts we rely on every day.

The patterns that appear over and over

Urgency. An attacker who can make you feel rushed makes you less likely to pause and verify. "Your account will be suspended in 24 hours." "Unauthorized access was detected — respond immediately." "Your package has been held — click now to release it." The urgency is manufactured, but the feeling it triggers is real. Acting under pressure is exactly when verification steps get skipped.

Authority. People comply more readily with requests from apparent authority figures. Impersonating an IT department, a bank fraud team, a government agency, or a senior employee exploits this tendency. "This is Microsoft support" and "This is your bank's security team" both work because the implied authority makes compliance feel like the right response.

Pretexting. This is constructing a believable scenario that gives the attacker a reason to request something unusual. "We're doing an IT security audit and need to verify your credentials" or "I'm the new vendor and need access to the shared folder" — the backstory makes the request seem reasonable before the target has a chance to think through whether it actually is.

Familiarity and reciprocity. An attacker who's done some research can reference your manager's name, your company's recent news, or your internal tool names. This makes them seem legitimate and makes requests feel less suspicious. People also tend to want to help when someone seems friendly or claims to be in a bind.

Fear of getting things wrong. "If you don't act now, you'll be responsible for the breach" puts the target in a position where complying feels like the safer option. This is especially effective in professional environments where the cost of a mistake feels high.

Why technical defenses aren't enough

A strong password and two-factor authentication will stop an attacker who's trying to break in through normal login channels. They don't stop an attacker who convinces you to type your credentials into a site they control, who tricks you into approving a login on your own authenticator app, or who calls you pretending to be your bank and talks you through reading them a one-time code.

The credential you hand over willingly bypasses whatever's protecting the account from unwanted logins. This is why the most technically secured accounts can still be compromised through social engineering — the attacker isn't attacking the account, they're attacking the person with access to it.

The one habit that disrupts most of it

Almost every social engineering attack depends on you responding to a channel the attacker initiated. They called you, emailed you, texted you, sent you a chat message. They control that channel — they can make the caller ID say anything, the email address look close enough, the message seem official.

The habit that breaks this is: verify through a channel you initiate.

If someone calls claiming to be from your bank about suspicious activity, hang up and call the number on the back of your card. If you get an email from IT saying to verify your credentials, don't click the link — go to the IT portal directly and check. If a vendor contacts you asking to update payment details, call them at the number you have on record, not the one they gave you.

This doesn't require assuming everyone is lying. Most requests from banks and IT teams are real. It just means responding to an unexpected contact by reaching back through a channel whose legitimacy you control.

The delay this creates is part of its value. Urgency is manufactured. Taking five minutes to make a callback gives you time to think, and legitimate organizations will always accommodate that.

A few things worth internalizing

You cannot tell a social engineering call is fake by how professional the caller sounds. Skilled attackers are convincing — that's the point. The caller ID on a spoofed call will often show a real number. The email domain may have a character substituted that's easy to miss. Appearance of legitimacy is something they construct.

Being targeted doesn't mean you did something wrong. Social engineering is often done at scale — attackers run through contact lists until someone responds. The person who falls for it isn't necessarily less careful than average; they just encountered a more convincing scenario, or happened to be distracted at the right moment.

The goal isn't perfect skepticism about everything. It's building one reliable habit: when an unexpected contact is asking for credentials, access, or a verification code — verify before complying, through a channel you chose.

That single step makes most social engineering attacks substantially harder.

← All posts