← Security Center

Social engineering awareness guide

How to spot and stop targeted scams, even when the attacker seems to know everything about you and your company.

Phishing Vishing Smishing Invoice scams

Most people can spot a clumsy scam email. But when attackers compromise an account or get hold of internal data, whether through a past breach, an insider, or scraped information, their attacks stop being "spray and pray" and become highly targeted and personal. Security professionals call this spear phishing (or whaling when it targets executives).

These attacks are dangerous precisely because they remove the usual red flag: the message has context. It references real projects, real coworkers, real invoices. This guide shows you what that looks like for each attack type, and the one habit that defeats all of them.

The golden rule: if a request involves money, credentials, or sensitive data, verify the requester's identity through a separate, pre-established channel. Never trust the channel the request arrived on. Accurate insider details are not proof of legitimacy. In fact, they can be the strongest sign of a sophisticated compromise.

1. Phishing (email)

Standard phishing casts a wide net. Advanced phishing uses stolen data to impersonate a trusted colleague or vendor.

What it looks like with insider knowledge

How to protect yourself

2. Vishing (phone calls)

Vishing uses voice and psychological pressure. With insider knowledge, the caller sounds like they belong.

What it looks like with insider knowledge

How to protect yourself

3. Smishing (text messages)

Text-message phishing is often used to bypass email filters, and with insider knowledge it can mimic your company's own notifications.

What it looks like with insider knowledge

How to protect yourself

4. Invoice scams (business email compromise)

The most financially damaging attack of all. Attackers use stolen invoice data and real vendor relationships to redirect payments.

What it looks like with insider knowledge

How to protect yourself

Quick-reference defense matrix

When an attack includes accurate internal details, the usual "does this look suspicious?" test fails. Use verification of intent instead:

Attack vector The "insider" hook The critical defense step
Phishing References a real project or meeting. Verify via a different medium: call an independently verified number, never one from the email.
Vishing Knows your coworkers, manager, and workflows. Hang up and call back using a known directory number. Caller ID can be spoofed.
Smishing Mentions a specific trip or expense. Don't tap links in texts. Contact your manager or coworker independently to verify.
Invoice scam Includes a real PO number or past invoices. Call the vendor on a pre-verified number to confirm any bank or payment change.

Key takeaway: attackers who have breached an account or database hold the "keys to the castle" when it comes to context. So the presence of accurate internal information proves nothing. When money, credentials, or sensitive data are on the line, always verify through a separate channel you established beforehand.

Want this training for your whole team?

We run practical, jargon-free security awareness sessions for businesses of every size.