Social Engineering and Phishing
Recognize attacks that target people instead of machines.
Social Engineering and Phishing is a free Network+ Academy lesson on CoddyKit — lesson 3 of 4. You can read the complete lesson below for free — then practise it hands-on in the browser with a built-in code editor and a 24/7 AI tutor. It is part of the Network+ Academy learning path, one of 4 lessons in the course, and your progress syncs across the web and the CoddyKit app.
Hacking the Human
Social engineering attacks people rather than technology. Instead of breaking through firewalls, the attacker tricks a person into giving up information, access, or money by exploiting trust, fear, curiosity, or helpfulness.
It is often the easiest way in: why crack a password when you can convince someone to simply hand it over? Humans are frequently the weakest link in security.
Phishing
Phishing is the most common social engineering attack: fraudulent emails or messages that appear to come from a trusted source, luring victims into clicking malicious links, opening infected attachments, or entering credentials on fake sites.
A phishing email might imitate your bank or IT department, creating urgency so you act before thinking. It casts a wide net, sent to many people at once.
Spear Phishing and Whaling
Targeted variants are more dangerous. Spear phishing tailors the message to a specific person using details about them, making it far more convincing. Whaling targets high-value executives like CEOs.
Because these messages are personalized and well-researched, they are much harder to spot than generic phishing and often succeed where mass campaigns fail.
Vishing and Smishing
Phishing is not only email. Vishing (voice phishing) uses phone calls, such as a fake support agent extracting passwords. Smishing (SMS phishing) uses text messages with malicious links.
Attackers spread across channels because people may distrust a suspicious email yet readily answer a phone call or tap a text-message link, especially one that seems urgent.
Pretexting and Impersonation
Pretexting invents a believable scenario to extract information, like an attacker posing as IT support who needs to verify your login to fix a problem. Impersonation means pretending to be someone trusted, in person or remotely.
The fabricated context lowers the victim guard, making them comply with requests they would normally question.
Physical Tactics
Some social engineering is physical. Tailgating (or piggybacking) is following an authorized person through a secure door without badging in. Shoulder surfing is watching someone type a password or PIN.
Dumpster diving recovers sensitive information from discarded papers and devices. These remind us that security includes physical awareness, not just computers.
Baiting and Quid Pro Quo
Baiting dangles something tempting, like a USB drive labeled Payroll left in a parking lot, hoping a curious person plugs it in and infects their machine.
Quid pro quo offers a benefit in exchange for information or access, such as fake tech support promising help if you give them remote access. Both exploit human desire for gain or assistance.
Why It Works
Social engineering succeeds by exploiting psychology: authority (we obey those who seem in charge), urgency (we act fast under pressure), fear, trust, and helpfulness.
Recognizing these triggers is the first defense. When a message pressures you to act immediately or bypass normal procedure, that pressure itself is a warning sign worth pausing on.
Defending Against It
The best defenses are human and procedural:
- Security awareness training so users recognize attacks.
- Verification procedures, like calling back a known number before acting on a request.
- Multi-factor authentication, so a stolen password alone is not enough.
- A culture where questioning suspicious requests is encouraged, not punished.
Spotting Phishing
Red flags include unexpected urgency, generic greetings, spelling and grammar errors, mismatched or odd sender addresses, links whose true destination differs from the text, and requests for credentials or payment.
Hovering over a link to inspect its real URL before clicking, and verifying unusual requests through a separate channel, stop most phishing attempts cold.
Bringing It Together
Social engineering attacks people, not machines, using phishing (and spear phishing, whaling, vishing, smishing), pretexting, baiting, tailgating, and more. It exploits authority, urgency, fear, and trust. The defenses are mainly human: awareness training, verification procedures, and multi-factor authentication.
Quick Check
Test your social engineering knowledge.
Recap
Social engineering manipulates people instead of technology. Phishing and its variants (spear phishing, whaling, vishing, smishing), plus pretexting, baiting, and tailgating, exploit authority, urgency, and trust. The defenses are human: awareness training, verification procedures, and multi-factor authentication.
Frequently asked questions
Is the “Social Engineering and Phishing” lesson free?
Yes — the full text of “Social Engineering and Phishing” is free to read here on the web, and the Network+ Academy course includes 4 lessons in total. To practise it interactively (a built-in code editor and a 24/7 AI tutor) and unlock the rest of the Network+ Academy course, upgrade to CoddyKit PRO.
What will I learn in “Social Engineering and Phishing”?
Recognize attacks that target people instead of machines. You practise Network+ Academy with hands-on code you run directly in the browser, and a 24/7 AI tutor answers your questions as you work through the lesson.
Do I need any experience to start Network+ Academy?
No prior experience is required. Network+ Academy on CoddyKit is structured for beginners through advanced learners; this is — lesson 3 of 4, so you can start here or from the beginning and move at your own pace.
How long does the “Social Engineering and Phishing” lesson take?
Most CoddyKit lessons take about 5–10 minutes. Each one is bite-sized and interactive, so you make steady progress and pick up exactly where you left off across the web and the app.
Can I write and run code in this Network+ Academy lesson?
Yes. Every Network+ Academy lesson includes a built-in code editor, so you write and run real code right in your browser and get instant AI feedback — no local setup required.
All lessons in this course
- Spoofing and On-Path Attacks
- Denial-of-Service Attacks
- Social Engineering and Phishing
- Building Practical Mitigations