MyLeoNes™

Social engineering: attacking human decisions — Technology, 14–17 years

Many attacks do not break a computer first; they persuade a person to reveal information, open a file or approve an action. Understanding the pressure used helps people pause and verify requests.

The person becomes the target

Social engineering uses trust, fear, urgency or helpfulness to influence someone into taking a risky digital action. The attacker may pretend to be a bank, teacher, colleague or delivery service. The weakness is not a lack of intelligence; it is a normal human response used at the wrong moment.

Why attackers use persuasion

Breaking strong security directly can be difficult, while persuading one person may be cheap and quick. That is why scam messages create a problem that technology alone cannot solve: a genuine user may authorise the attacker. Verification steps add a pause between the request and the action.

Worked example: a fake urgent message

You receive: “Your school account will close today. Sign in here in ten minutes.” First, notice the pressure and avoid the link. Second, check the sender and open the school site using a known address, not the message. Third, ask the school or report it if the warning is false.

Urgency feels like evidence

People often trust a message because it sounds official, uses their name or demands an immediate reply. That mistake is reasonable: real services sometimes send alerts and delays can matter. But urgency is only a claim, not proof; verify through a separate, trusted route before sharing or approving anything.

Where it appears

Phishing emails, fake support calls, scam texts and manipulated social-media messages all use social engineering. Organisations reduce the risk with staff training, approval rules and clear ways to contact them. Individuals can slow down, question unusual requests and never treat secrecy as proof of trust.

Keep exploring

Other languages

Loading MyLeoNes™…