They say sharing is caring, but sometimes it’s best to NOT share, particularly when it comes to social engineering. Staying knowledgeable about how you can unwittingly hand over your information to scammers is key to keeping your devices, accounts, and your identity safe.
What is Social Engineering?
Social Engineering is when someone gathers your information through seemingly harmless interactions or methods, such as email, social media, or even conversations. In a social engineering attack, the fraudster uses a simple interaction to manipulate someone into providing information. More often than not, your ability to trust others is used against you to commit fraud or identity theft.
Examples of Social Engineering
Social Engineering can happen in a variety of instances, but most commonly you’ll see them occur through the following:
- Website spoofing: When a fake website is created to look like a legitimate one. Users are fooled or misled into sharing sensitive information.
- Email phishing: Phishing emails are often sent with a sense of false urgency, too-good-to-be-true messaging, or can look like emails from people you know. These emails contain malicious links or attachments.
- Phishing phone calls: Same as with emails, scammers will call a person with an urgent or appealing message and encourage them to provide sensitive information over the phone.
- Face-to-face interactions: These types of social engineering can be as simple as conversations or someone looking over your shoulder while you’re on the computer
How to Stay Safe from Social Engineering
Protecting yourself from social engineering attempts is all about understanding how they occur and thinking twice before providing your information to people or sites you don’t know.
Ask yourself if you should be sharing sensitive information and, if so, why? Do you know the person? Do you trust the site? What will the information be used for? These are simple questions that can save you massive headaches down the road.
- Pay attention to URLs. A website could look legitimate but check for mistakes in spelling or information or a different domain. Additionally, use websites with a secure connection. You can tell by web addresses that begin with “https://” (the S means secure!).
- Suspicious of a site, email, or phone call? Close the page, delete the email, or hang up and contact the company or person directly.
- Don’t click on or open unknown links or attachments from unfamiliar people. You can always type the address into your browser as a safer alternative.
If you think you’ve fallen victim to a social engineering attack, make sure to contact your financial institution to let them know. It’s also good practice to regularly monitor your accounts and transaction activity, including checking your annual credit report!