Phishing and Social Engineering
Attacks that trick people instead of breaking code.
Also known as: social engineering, spear phishing, pretexting
Phishing is an attack that tricks a person into giving up a secret or doing something harmful, usually through a message that looks legitimate: an email, SMS or chat. Social engineering is the wider category: any attack that targets people rather than code, including phone calls and someone just asking nicely.
Typical examples:
- An email that looks like it comes from IT, asking you to “verify your password” on a lookalike login page.
- A message that seems to come from your boss asking you to urgently buy gift cards or approve a payment.
- A fake “security alert” that makes you install something.
- Spear phishing: the same idea aimed at one person, using real details about them.
Why developers should care
You hold powerful access: production, source code, cloud consoles, package registries. One stolen developer credential can become a company-wide incident. Attackers pick developers on purpose.
Warning signs
- Urgency or threats (“act in 10 minutes”).
- A request to do something unusual with money, access or credentials.
- A sender address or link that is slightly off. Hover over links and check the real domain before clicking; lookalike names are common (see typosquatting).
- Unexpected attachments or login pages reached from a message.
What to do
- Don’t click, verify: contact the person through a channel you already trust.
- Report it to your security or IT team, even if you clicked. Fast reports limit the damage.
- Turn on MFA everywhere. Hardware keys and passkeys are especially strong because they won’t work on a fake site.
- Never share passwords or one-time codes with anyone, even someone claiming to be support.
Defences should assume someone will eventually be fooled; this is where defense in depth and least privilege help.