Human factors and phishing
By the end of this module you will be able to:
- Classify a social engineering attempt as phishing, spear-phishing, whaling, vishing, smishing, or pretexting
- Explain why detection-based training fails against AI-generated lures and deepfake voice and video
- Design an out-of-band verification procedure for payments and standing data changes
- Choose metrics that measure behaviour change rather than click rates
$37 million transferred. No malware. No hacking. Just a believable email and a sense of urgency.
In August 2019, Toyota Boshoku Corporation, a major Toyota Motor Corporation supplier, lost approximately $37 million in a single bank transfer. An employee in a finance role received an email that appeared to come from a known business partner. The email requested an urgent update to bank account details for a supplier payment. The employee complied. The payment went to an account controlled by fraudsters.
No malware was used. No system was technically compromised. The attacker crafted a believable email, created urgency, and exploited the employee's trust in the apparent sender. This is BEC (Business Email Compromise), a subset of social engineering that the FBI's IC3 (Internet Crime Complaint Center) reported caused over $2.7 billion in losses in 2022 alone, making it one of the highest-revenue cybercrime categories globally.
Technical controls, MFA, firewalls, and endpoint protection, protect what they can see. When an attacker convinces a legitimate user to act on their behalf, those controls are bypassed entirely. Understanding why humans are targeted, and what evidence shows reduces that targeting's effectiveness, is essential for building defences that extend beyond technology.
The employee followed the correct process for supplier payment updates. The attacker simply made themselves look like the right person to follow it with. Where does the defence need to be placed?
7.1 Social engineering: the taxonomy
is the manipulation of people rather than systems to gain unauthorised access, extract information, or trigger an action. Each attack type uses a different channel or targeting approach.
uses deceptive email campaigns sent to large numbers of recipients hoping a percentage will respond. The Toyota Boshoku attack was a targeted form called spear-phishing, where the attacker tailored the message to a specific individual using researched context (their role, their supplier relationships, the urgency of payment processing). Whaling is spear-phishing targeted at senior executives (CEOs, CFOs) who have authority to authorise large transfers or access sensitive systems.
Vishing (voice phishing) uses phone calls, often with spoofed caller ID, to impersonate authority figures such as bank fraud teams, IT support, or government agencies. The Twitter 2020 breach (Module 6) used vishing: attackers called Twitter support staff impersonating IT colleagues. Smishing uses SMS text messages with malicious links or fraudulent instructions.
involves constructing a fabricated scenario (a pretext) to gain trust. An attacker who calls a company reception claiming to be a new IT contractor needing building access is using pretexting. Many sophisticated attacks combine multiple techniques: a smishing message creates urgency, a follow-up vishing call confirms it, and the target complies with a fraudulent request.
7.2 Why people comply: Cialdini's principles of influence
Social engineering attacks are effective because they exploit psychological patterns that are not vulnerabilities in the usual sense: they are features of normal human social behaviour. Robert Cialdini's six principles of influence, documented in his 1984 book "Influence: The Psychology of Persuasion," provide a structured vocabulary for understanding why.
- Authority: people follow instructions from perceived authority figures. An email appearing to come from the CEO requesting an urgent fund transfer exploits authority.
- Urgency and scarcity: artificial time pressure prevents careful verification. "This must be processed today or the contract is lost."
- Social proof: people follow what others appear to be doing. "Everyone in your department has already completed this security update."
- Liking: people comply more readily with those they like or identify with. Attackers research social media to find shared interests, mutual connections, and familiar names.
- Reciprocity: people feel obligated to return favours. A helpdesk attacker who offers to help a user with a problem first may then ask for something in return.
- Commitment and consistency: once someone has agreed to a small request, they are more likely to agree to a larger one. "You said you wanted to keep your account secure? Then I just need you to verify this code."
Social engineering works on cognitive biases that are well established and that training does not remove. The defences that hold combine technical controls, which make the wrong action harder to take, with procedural ones, which make verification easy enough that a busy person still does it.
7.3 The tells are gone
For years, awareness training taught people to spot phishing by its tells: clumsy spelling, broken grammar, a greeting addressed to your email address instead of your name. That advice no longer protects anyone. A lure written by a large language model reads as fluently as a genuine message, and generated voice and video now defeat the older instinct that asks whether something looks real.
In January 2024 an employee in the Hong Kong office of the engineering firm Arup joined a video call to discuss a confidential transaction. The chief financial officer was on the call, and so were several colleagues the employee recognised. Every one of them was a . Reassured by faces and voices that matched people they knew, the employee authorised fifteen transfers worth about 25.6 million US dollars before the fraud came to light. It was a in everything but the channel: the same executive-authority pressure that once arrived by email now arrived as a live meeting nobody thought to doubt.
The lesson is not that the employee was careless. It is that the detection task they had been set was now impossible. Any control that depends on a person noticing that a message, a voice or a face is fake is a broken control, because the fakes are good enough to pass. Detection has to move to something the attacker cannot forge: a procedure that checks the request through a separate, trusted channel, however convincing the request itself appears.
Common misconception
“You can spot a phishing attempt by its bad spelling, clumsy grammar, and anything that looks a bit off.”
That advice is now obsolete. Lures written by a large language model carry no spelling or grammar tells, and deepfake voice and video defeat the instinct that asks whether a face or a voice looks real. The Arup employee saw colleagues they recognised and heard the chief financial officer's voice; there was nothing to spot. Any control that depends on a person detecting the fake is a broken control. The defence has to move to verification through a separate trusted channel, which holds no matter how convincing the request appears.
7.4 Verification procedures, not vigilance
If people can no longer be asked to detect fakery, the defence has to sit in the procedure rather than in the individual’s judgement. A good verification procedure shares one property: following it is easier than breaking it, so the safe path is also the path of least resistance.
is the core move. When a request arrives to move money or to change standing data such as a supplier’s bank details, the person acting on it confirms the request through a separate channel that the requester did not choose. In practice that means a callback on a number already held in the directory, never a number supplied in the message or read out on the call. The Arup transfers would have failed this single test: a call to the real chief financial officer, on the number the finance team already held, would have reached a person who had authorised nothing.
Two further controls harden the procedure. Dual authorisation requires a second named person to approve any payment or standing-data change above a set threshold, so no single deception is enough. Pre-agreed code phrases give executives and their finance teams a shared secret that a synthetic voice cannot produce on demand. None of these steps asks anyone to judge whether a face or a voice is genuine. They replace that impossible judgement with an action a convincing fake cannot complete: reaching the real person, winning a second approver, or repeating a phrase it was never told.
7.5 Measuring what works
When a programme fails, the reflex is to say that users are the weakest link. The NCSC rejects that framing. Its human-centred security guidance holds that people fail because systems are designed badly: security tasks that are confusing, slow, or impossible to complete correctly set people up to make the mistake, and a blame culture then punishes them for it. Blame carries a measurable cost, because staff who fear punishment stop reporting, and reporting is the earliest signal an organisation has that an attack is under way.
This changes what an awareness programme should measure. A simulated phishing click rate looks like a number that means something, but on its own it rewards fear and secrecy: the way to drive it down is to make staff afraid to click anything and afraid to admit when they do. The metrics that matter track behaviour instead. How many people reported the simulated message, and how quickly? When a real suspicious email arrives, how long is it between the first sighting and the security team knowing? Is the reporting rate rising as people learn that reporting is welcomed rather than penalised?
Building that culture is deliberate work. Leaders report their own near misses openly, so that reporting looks normal rather than shameful. Honest mistakes are handled without punishment, so the person who clicked is treated as the source of a useful signal rather than as a failure. Reporting a suspicious message is made a single, obvious action, not a trip through a helpdesk queue. Measured this way, a programme is judged by whether behaviour changes and whether the organisation hears about trouble sooner, not by whether a click-rate chart trends down.
Common misconception
“Users are the weakest link, so the fix is more training and tougher consequences for those who click.”
The NCSC's human-centred security guidance rejects this. People fail when systems are designed badly, and a blame culture then punishes them for the design's faults, which drives reporting underground exactly when early reporting matters most. Tougher consequences lower the simulated click rate by making staff afraid to admit mistakes, not by making the organisation safer. Measure reporting rates and behaviour change, and design security tasks people can actually complete, rather than treating the person as the fault to be corrected.
An employee in accounts payable receives an email apparently from the CFO saying: 'I need you to process an urgent wire transfer today for an acquisition we can't discuss publicly yet. Do it before 5pm and don't mention it to anyone.' Which social engineering technique and Cialdini principle are most clearly being used?
An attacker calls a company's reception claiming to be a new IT contractor, mentions the name of the actual IT manager (found on LinkedIn), and asks for temporary building access while they 'set up the server room.' Which technique is this, and which Cialdini principle is most directly being exploited?
A CISO is proposing a security awareness programme that consists of one 30-minute e-learning module per year, with a pass mark of 80% on the final quiz. Based on evidence about what reduces phishing click rates, which critique is most valid?
A CFO receives an email appearing to come from the CEO's email address asking them to urgently transfer £95,000 to a new supplier account before end of business. The email uses the CEO's name, references a real ongoing project, and includes a mobile number to call for confirmation that connects to the attacker. The CFO is under time pressure. Which controls would most effectively prevent this Business Email Compromise attack?
In January 2024, staff in Arup's Hong Kong office joined a video call on which the chief financial officer and several colleagues were all deepfakes, and about 25.6 million US dollars was transferred. Which single control would most reliably have stopped the payment, and why?
Core distinctions
- Phishing, spear-phishing, whaling, vishing, smishing, and pretexting are distinct social engineering types that differ by channel and targeting precision. Business email compromise is among the highest-cost categories.
- Social engineering exploits Cialdini's principles of influence: authority, urgency, social proof, liking, reciprocity, and commitment. These are ordinary features of human behaviour, not individual weaknesses.
- The linguistic and visual tells are gone. Model-written lures read fluently and deepfake voice and video pass as real, so any control that depends on a person detecting the fake is broken. The Arup deepfake fraud moved about 25.6 million US dollars in January 2024.
- Verification belongs in the procedure, not the individual's judgement: an out-of-band callback on a pre-held number, dual authorisation above a threshold, and pre-agreed code phrases, each designed so following the safe path is easier than breaking it.
- The NCSC's human-centred security holds that bad design and blame culture set people up to fail. Measure reporting rates and behaviour change, not simulated click rates, and make honest reporting the easy, welcomed action.
A breach will eventually get through, and when it does, data protection law imposes specific duties. Module 8 covers UK GDPR, lawful bases for processing, data subject rights, and the 72-hour breach notification rule.
Standards and sources cited in this module
CNN, Finance worker pays out $25 million after video call with deepfake CFO (February 2024)
Report on the Arup Hong Kong case
Primary source for the Arup deepfake fraud of January 2024: an employee authorised about 25.6 million US dollars in transfers after a video call on which the chief financial officer and colleagues were deepfakes. Cited in Section 7.3.
NCSC UK, Advice and guidance (human-centred security)
All topics, including human-centred security
UK government guidance behind the argument that bad design and blame culture set people up to fail, and that programmes should measure behaviour change and reporting rather than click rates. Cited in Section 7.5.
NCSC UK, Phishing guidance (2023)
Full guidance document
UK government guidance on phishing attack types and defences. Referenced in Section 7.1.
NIST SP 800-50 Rev.1, Building a Cybersecurity and Privacy Learning Program
Section 2.3, Human Factor Threats
US government reference for security awareness programme design. Establishes that training must be complemented by technical and procedural controls. Quoted in Section 7.2.
Cialdini, R. (1984). Influence: The Psychology of Persuasion
Chapters 1-7 (principles of influence)
Academic foundation for the influence principles exploited by social engineering. Cited in Section 7.2.
FBI IC3 Internet Crime Report 2022
Threat overviews for 2022, Business Email Compromise
Source for the $2.7 billion BEC loss figure in 2022. Used in the opening case study context.
Proofpoint State of the Phish 2023
Key findings: organisational phishing rates and training effectiveness
Industry data on phishing prevalence and the limits of annual e-learning. Background for the measurement discussion in Section 7.5.
Module 8 of 41 · Foundations