Phishing & Pretexting
Understand the most common social engineering attacks and develop methods to recognize them.
Phishing & Pretexting is a free Ethical Hacking Academy lesson on CoddyKit — lesson 2 of 3. You can read the complete lesson below for free — then practise it hands-on in the browser with a built-in code editor and a 24/7 AI tutor. It is part of the Ethical Hacking Academy learning path, one of 3 lessons in the course, and your progress syncs across the web and the CoddyKit app.
1
Welcome to Phishing & Pretexting
Phishing and pretexting are common social engineering attacks used to steal sensitive information.

2
What is Phishing?
Phishing is an attack where attackers impersonate trusted entities to trick victims into providing sensitive information.
3
Types of Phishing Attacks
- Email Phishing - Fake emails pretending to be from legitimate sources.
- Spear Phishing - Targeted phishing aimed at specific individuals.
- Whaling - High-profile attacks targeting executives.
- Smishing - Phishing via SMS messages.
4
Example of an Email Phishing Attack
Attackers use fake emails that appear to be from banks, requesting login details.
5
What is Pretexting?
Pretexting involves creating a fabricated scenario to manipulate victims into revealing information.
6
Examples of Pretexting Attacks
- Tech Support Scams - Attackers impersonate support agents.
- CEO Fraud - Attackers pretend to be executives requesting financial transactions.
- Fake Job Offers - Victims are tricked into providing personal details.
7
Preventing Phishing and Pretexting
- Verify the sender's email address before clicking links.
- Use multi-factor authentication (MFA).
- Be cautious of unsolicited requests for sensitive information.
- Train employees to recognize phishing attempts.
8
9
How to Report Phishing Attempts
- Report suspicious emails to your IT department.
- Use anti-phishing browser extensions.
- Never share personal information over unsecured channels.
10
Summary
Phishing and pretexting are deceptive tactics used to steal information. Awareness and vigilance are key to preventing such attacks.

Frequently asked questions
Is the “Phishing & Pretexting” lesson free?
Yes — the full text of “Phishing & Pretexting” is free to read here on the web, and the Ethical Hacking Academy course includes 3 lessons in total. To practise it interactively (a built-in code editor and a 24/7 AI tutor) and unlock the rest of the Ethical Hacking Academy course, upgrade to CoddyKit PRO.
What will I learn in “Phishing & Pretexting”?
Understand the most common social engineering attacks and develop methods to recognize them. You practise Ethical Hacking Academy with hands-on code you run directly in the browser, and a 24/7 AI tutor answers your questions as you work through the lesson.
Do I need any experience to start Ethical Hacking Academy?
No prior experience is required. Ethical Hacking Academy on CoddyKit is structured for beginners through advanced learners; this is — lesson 2 of 3, so you can start here or from the beginning and move at your own pace.
How long does the “Phishing & Pretexting” lesson take?
Most CoddyKit lessons take about 5–10 minutes. Each one is bite-sized and interactive, so you make steady progress and pick up exactly where you left off across the web and the app.
Can I write and run code in this Ethical Hacking Academy lesson?
Yes. Every Ethical Hacking Academy lesson includes a built-in code editor, so you write and run real code right in your browser and get instant AI feedback — no local setup required.
All lessons in this course
- Psychology of Deception
- Phishing & Pretexting
- Building a Human Firewall