Skip to content

Services, Wiki-Artikel und Blog-Beiträge durchsuchen

↑↓NavigierenEnterÖffnenESCSchließen

Phishing and Social Engineering: Attack Methods and Defense

Phishing and social engineering guide: mass, spear, whaling, BEC, smishing, vishing, QR and AiTM. Cialdini, DMARC, FIDO2 MFA, awareness.

Summary: Manipulating people rather than systems using psychological principles such as authority, urgency, and reciprocity. Tools: phishing (email), vishing (phone), smishing (SMS), pretexting, baiting. Unlike an insider threat, the attacker comes from outside the organization and uses deception to gain access. 91% of all cyberattacks begin with social engineering.

Sources & References

  1. [1] APWG Phishing Activity Trends Report 2024 - APWG
  2. [2] BSI Lagebericht zur IT-Sicherheit 2024 - BSI
  3. [3] Verizon Data Breach Investigations Report 2024 - Verizon
  4. [4] Anti-Phishing Working Group (APWG) Trends Report - APWG

Questions about this topic?

Our experts advise you free of charge and without obligation.

Free Consultation

About the Author

Vincent Heinen
Vincent Heinen

Head of Offensive Services

E-Mail

M.Sc. in IT Security with more than 5 years of experience in offensive security analysis. Leads the delivery of penetration tests, specializing in web applications, network infrastructure, reverse engineering and hardware security. Responsible for several responsible disclosures.

OSCP+ OSCP OSWP OSWA
This article was last edited on 03/29/2026. Responsible: Vincent Heinen, Head of Offensive Services at AWARE7 GmbH. License: CC BY 4.0 - free use with attribution: "AWARE7 GmbH, https://a7.de"

Rufen Sie uns an

Mo-Fr, 8:00-17:00 Uhr - persönlich und unverbindlich.

0209 8830 6764
Jetzt anrufen