Lesson 1 of 5

How manipulation works

Social engineering is manipulating people into doing something that helps an attacker: revealing a password, approving a login, opening a file, or sending money. Phishing is the most common form: messages designed to look genuine that trick the recipient into acting.

It works because it targets normal human behaviour, not weakness or stupidity. Attackers use a handful of reliable levers:

  • Authority: the message appears to come from a boss, a bank, a regulator or the police.
  • Urgency: "act now or your account will be closed".
  • Fear: a threat of loss, penalty or trouble.
  • Opportunity, greed or scarcity: a prize, refund, job or investment that is "only available today".
  • Helpfulness and trust: a colleague or supplier asking for a small favour.
  • Curiosity: an unexpected parcel notice, invoice or shared document.

These levers push people to act quickly, before they think. That is why the single most useful habit is to slow down when a message creates pressure, and to check it through a separate, trusted route before acting.

Anyone can be caught, including security professionals, when the timing and the story are right. Treating people who are caught as foolish makes them hide mistakes, which is exactly what an attacker wants.

Lesson 2 of 5

The channels attackers use

Phishing is not only email. Attackers use every channel people trust:

  • Email phishing: fake login pages, malicious attachments and links, often imitating well-known services, banks or the recipient's own organisation.
  • Spear phishing: messages tailored to a specific person, using details about their role, colleagues or recent activity to seem credible.
  • Business email compromise: impersonating an executive, colleague or supplier, often from a real but compromised mailbox or a look-alike address, to request payments or changes to bank details.
  • Smishing: phishing by text message, such as fake delivery, bank or mobile money messages.
  • Vishing: phishing by voice call, with callers posing as bank staff, IT support or officials.
  • Messaging apps and social media: fake profiles, job offers and "friends" whose accounts have been taken over.
  • QR code phishing ("quishing"): codes in emails, on parcels, or stuck over genuine codes on posters and payment points, that lead to fake login or payment pages or to harmful downloads. People cannot read the web address inside a QR code before scanning it, and scanning takes them onto a phone, which often has fewer protections than a work computer.
  • Multi-factor fatigue (prompt bombing): an attacker who already has someone's password triggers repeated login approval requests until the person accepts one to make them stop.

Warning signs are similar across channels: an unexpected request, pressure to act fast, a request for credentials, codes or money, a sender or link that does not quite match, and a request to bypass normal process or keep things secret. Display names are easy to fake: check the full sender address and the real web address behind a link, and watch for look-alike spellings such as extra letters or different endings.

Lesson 3 of 5

AI-enabled impersonation

Generative AI has removed some of the traditional warning signs and added new threats.

  • Fluent, personalised messages: phishing emails no longer need spelling mistakes or awkward grammar, and can be written in any language and tailored to each target at scale.
  • Voice cloning: a short recording can be used to imitate a known person's voice on a phone call.
  • Deepfake video: fake video of real people can appear in video calls or recorded messages.
  • Faster research: AI can gather and summarise public information about a target to make a story more convincing.

The practical response is to stop relying on how a message looks or sounds, and rely on process:

  • Verify requests, not voices. Any request involving money, credentials, bank details or sensitive data is confirmed by calling back on a known number, or through another channel you already trust.
  • No exceptions for seniority or urgency, because those are exactly what impersonators use.
  • Agreed verification steps, such as code words for high-risk requests between executives and finance teams.
  • Teach that poor spelling is no longer a reliable clue; the request itself is what matters.
Lesson 4 of 5

Technical controls that help

People are an important layer of defence, but they should not be the only one. Technical controls stop many attacks before anyone sees them, and limit the damage when someone is fooled.

  • Email authentication: publishing SPF, DKIM and DMARC records for your domains makes it much harder for attackers to send email that uses your exact domain as the sender. Once the DMARC policy is set to quarantine or, strongest, reject, receiving systems are asked to treat failing messages as suspicious or refuse them. These records do not stop look-alike domains, which is why filtering and careful checking still matter.
  • Filtering: email and web filtering that blocks known malicious messages, links and attachments, and warns on messages from outside the organisation or from look-alike domains.
  • Phishing-resistant multi-factor authentication: methods based on public-key cryptography, such as security keys and passkeys built on the FIDO2 standards, are phishing-resistant: each credential is tied to the genuine website's address, so a fake site cannot use it, and there is no code for the person to type in or read out. Keep weaker fallback login methods to a minimum, because attackers will try to push people onto them. Some phishing kits sit between the victim and the real site and capture codes and login sessions as they are entered, which is why phishing-resistant methods matter.
  • Number matching and limits on login approval prompts, to defeat multi-factor fatigue where phishing-resistant methods are not yet in place.
  • Least privilege and payment controls: even a fooled employee cannot move large sums alone if payments need a second approver.
  • Easy reporting: a single button or address to report suspicious messages, with fast feedback.

Layered together, these controls mean that one person's mistake does not become a breach.

Lesson 5 of 5

A culture that reports

The goal of awareness work is not a workforce that never clicks. It is a workforce that notices, pauses and reports, quickly and without fear.

  • Make reporting easy and rewarded. Thank people for every report, including false alarms. A report made in the first minutes can protect everyone else who received the same message.
  • Make it safe to admit a mistake. Someone who clicked and reports it at once is an asset; the security team can reset passwords and block the attack. Someone afraid to report gives the attacker time.
  • Train with realistic, relevant examples, short and often, rather than once a year: the scams people actually see, including local ones such as fake mobile money messages and impersonated officials.
  • Use phishing simulations carefully. Simulations can help people practise, but they should teach rather than trap. Avoid cruel lures, such as fake bonuses during hard times, and never use results to shame individuals.
  • Measure what matters: how many people report, and how quickly, not only how many click.
  • Teach the "I clicked, what now?" steps: report it immediately, change the password from a device you trust, and if money or a mobile money account is involved, call the bank or provider at once using the number on the card or its official app. Never share a one-time code, PIN or login approval with anyone; genuine bank, mobile money or IT staff will never ask for one. A sudden loss of mobile signal can mean the SIM has been swapped, so contact the provider immediately.
  • Share what is happening: tell staff about real attacks the organisation has seen, so the threat feels concrete.

In Kenya, cyber incidents can be reported to the National Kenya Computer Incident Response Team – Coordination Centre (National KE-CIRT/CC), hosted by the Communications Authority of Kenya, and fraud to the National Police Service and the Directorate of Criminal Investigations.

Knowledge check

Ten questions

Answer all ten questions, then check your answers. You need 9 out of 10 to pass and receive a certificate. If you score less, you will see which answers were right and wrong, and then go through the course again before you retake the check. Your answers, progress and times are kept only in this browser.

Sources

The official documents this course relies on. Laws and guidance change, so check the current version.

  1. RFC 9989: Domain-Based Message Authentication, Reporting, and Conformance (DMARC) · Internet Engineering Task Force
  2. Phishing attacks: defending your organisation · UK National Cyber Security Centre
  3. FIDO Alliance, passkeys · FIDO Alliance
  4. National KE-CIRT/CC · Communications Authority of Kenya
  5. Implementing Phishing-Resistant MFA (fact sheet) · US Cybersecurity and Infrastructure Security Agency
  6. Implementing Number Matching in MFA Applications (fact sheet) · US Cybersecurity and Infrastructure Security Agency
  7. Spot and report scam emails, texts, websites and calls · UK National Cyber Security Centre
  8. T1621: Multi-Factor Authentication Request Generation · MITRE ATT&CK