Lição 4 de 4 · 8 min
Social engineering: phishing, pretexting and baiting
Many attacks target people rather than software. Learn how phishing, pretexting and baiting work, the pressure tricks they rely on, and the habits that defeat them.
Por agora esta página está em inglês.
Why break through a firewall when you can ask someone to open the door? Social engineering is the use of deception to manipulate people into giving away information, money or access. It works on intelligent, careful people too, because it does not attack intelligence: it attacks trust, habit and emotion. That is also why it remains one of the most common ways attackers get their first foothold, as MITRE ATT&CK’s long list of phishing-based intrusions shows.
The levers every scam pulls
- Urgency: “Your account will be closed in 24 hours.” Rushing stops you from checking.
- Authority: the message seems to come from a boss, a bank, IT support, the police or a government office.
- Fear or greed: a problem to fix, or a prize, refund or deal too good to miss.
- Helpfulness and politeness: people want to help a colleague in trouble.
- Familiarity: a real logo, a real name found online, a reply in an existing email thread.
When a message makes you feel any of these strongly, that feeling is itself the warning sign. Slow down precisely when you are being pushed to hurry.
Phishing: the mass-market lure
Phishing uses messages, usually email but also text messages (smishing) and phone calls (vishing), to make you click a link, open an attachment or type your password into a fake page. Mass phishing is sent to huge numbers of people. Spear phishing is tailored to one person or organisation using details found online, which makes it far more convincing. Whaling is spear phishing aimed at executives.
- Check where a link really goes before clicking: on a Mac, hover over it to see the real address.
- Look at the sender’s actual address, not just the display name.
- Never enter a password on a page you reached from a message; go to the site yourself instead.
- Be wary of attachments you did not expect, even from people you know: their account may be compromised.
- Use a password manager: it will not fill your password on a look-alike domain, which is a useful alarm.
Pretexting: a story that earns trust
In pretexting, the attacker invents a scenario, the pretext, to justify an unusual request. A caller from “IT support” needs your login code to fix an urgent problem. A new “supplier contact” asks finance to update the bank details for the next payment. A “recruiter” needs a copy of your ID. Business email compromise, where criminals impersonate executives or suppliers to redirect payments, is pretexting at scale and causes some of the largest financial losses in cybercrime.
Baiting: curiosity as a weapon
Baiting offers something tempting in exchange for an action. The classic version is a USB stick left in a car park, labelled “Salaries 2026”, carrying malicious software that runs when a curious finder plugs it in. The online version is a “free” film, game or cracked app download that installs something unwanted alongside it. The rule is simple: never plug in storage you did not buy yourself, and only install software from its official source.
On a Mac, this is where a firewall helps limit the damage if bait does get through. FireAI’s USB Network Protection makes sure an app launched from an external drive cannot reach the internet silently: it always asks, and in the Paranoid and Under attack modes such connections are denied outright.
Building habits that work
| Situation | Habit |
|---|---|
| A message asks you to log in | Open the site yourself, never through the link |
| Someone asks for a code sent to your phone | Refuse: real support never needs your one-time code |
| A request to change payment details | Call back on a number you already had |
| A found USB stick or a “free” download | Do not plug it in; do not install it |
| You think you clicked something bad | Report it immediately; speed limits the damage |
Organisations should make reporting easy and blame-free. People who admit a click quickly save far more than people who hide it for fear of punishment. And everyone benefits from multi-factor authentication, ideally phishing-resistant methods such as passkeys or hardware keys, so that a stolen password alone is not enough.
A reter
- Social engineering attacks trust, habit and emotion, not intelligence.
- Urgency, authority, fear and greed are the levers; a strong push to hurry is a warning sign.
- Verify unusual requests through a second channel you already trust.
- Never plug in unknown storage or install “free” copies of paid software.
Teste-se
1. A caller says they are from IT and need the code just sent to your phone to fix your account. What is this?
- Normal support procedure
- Pretexting: an invented story to obtain your one-time code — Certo.
- Baiting
- A software vulnerability
Real support never needs your one-time code. The invented scenario is the pretext.
2. What is the best defence against a request to change a supplier’s bank details?
- Reply to the email to confirm
- Verify through a second, independent channel, such as a phone number you already had — Certo.
- Make the change quickly to avoid delays
- Forward it to a colleague to decide
Replying reaches the attacker. Only an independent channel confirms the request is genuine.
3. Which of these is baiting?
- An email pretending to be your bank
- A USB stick labelled “Salaries” left in a car park — Certo.
- A fake IT support call
- A denial-of-service attack
Baiting uses a tempting item, like a found USB stick or a free download, to get the victim to take the harmful action themselves.
Praticar com o FireAI
Ponha esta lição em prática no seu próprio Mac.
- Regras: app, sítio, domínio, IP ou um intervalo, para sempre ou até reiniciar — Escreva uma regra tão precisa como um único endereço ou tão ampla como um domínio inteiro.
- Modos de segurança: Casa, Café, Paranoico, Sob ataque — Ajuste o rigor do FireAI ao sítio onde o seu Mac está de facto, com um toque.
- USB Network Protection: nothing from a USB drive goes online unasked — Plug in a drive someone handed you without letting what’s on it phone home.
- Investigue uma ligação — Decida com os factos à sua frente, não com um aviso vago.
Fontes
- CISA: Avoiding social engineering and phishing attacks
- CISA: Recognize and report phishing
- NIST Glossary: social engineering
- MITRE ATT&CK: Phishing (T1566)
Ponha em prática no seu Mac
Experimente todas as funcionalidades grátis durante 17 dias, sem cartão.