Hello.
As we’ve seen, social engineering can take the form of seemingly legitimate emails, messages, or phone calls.
Even if I change the channel, the goal is always the same: to influence our decisions so that we act without verifying the facts.
Behind these techniques, the same signals tend to recur:
- The need to act quickly.
- Unusual requests or contacts.
- Request for credentials or sensitive information.
- Requests for payment or changes to bank account information.
Situations that attempt to take advantage of our trust or prevent us from verifying the information.
When several of these signs appear at the same time, it’s time to stop and check.
Some of the most common types are:
- CEO Fraud: When a cybercriminal impersonates an executive to request payments, information, or urgent action.
- Supplier/Supply Chain Impersonation: where an attacker impersonates a supplier or regular business partner to modify data, request payments, or alter established processes.
In both cases, trust and urgency are used to get us to act without verifying the facts.
You know, be wary of:
- unexpected requests,
- last-minute changes,
- urgent payment requests or
- instructions that deviate from standard procedures.
Always verify the applicant’s identity and confirm any sensitive requests through an alternative channel.
Stop, think, and check.
Because when it comes to social engineering, taking a few seconds to verify something can prevent serious consequences.
Think before you act.
IMPORTANT NOTE:
If, despite complying with all these measures, you encounter situations that do not conform to the level of security required or established in internal policies, do not hesitate to inform your line manager, the Security Manager, security personnel and/or the IT department, depending on the type of suspicion.
If it happens to you on a personal level, report it directly to the police authorities, so that they can give you appropriate advice and conduct an investigation.
