Think twice before you click, reply, pay, download or share information.
Social engineering scams are designed to manipulate people into revealing personal or confidential information, clicking malicious links, downloading harmful software, sending money or giving fraudsters access to their accounts. These attacks can happen through email, websites, text messages, phone calls, social media and other digital channels. Fraudsters often impersonate people or organizations you know and trust, including financial institutions, government organizations, delivery companies, technology providers and even friends or family members. The good news is that recognizing a few common warning signs can help you stop a scam before it succeeds.
What is social engineering?
Social engineering is a type of fraud that relies on manipulation and deception rather than simply exploiting a technical vulnerability. A fraudster may create a sense of urgency, fear, excitement or trust to convince you to take an action that benefits them. Common social engineering attacks include phishing emails, fraudulent text messages, fake websites, phone scams, impersonation scams and targeted attacks. Fraudsters may also use publicly available information and artificial intelligence to make scams more convincing and personalized.
One simple rule can help:
If an unexpected message or call asks you to act quickly, stop and verify it independently before doing anything.
A.T.T.A.C.K.: Six warning signs of a social engineering scam
Use the A.T.T.A.C.K. technique to help identify common social engineering tactics.
A — An email
Phishing emails can look surprisingly legitimate. A fraudulent email may appear to come from your financial institution, a government organization, a retailer, delivery company, employer or someone you know.
Be cautious when an unexpected email:
- Asks you to click a link
- Requests personal or financial information
- Contains an unexpected attachment
- Creates a sense of urgency
- Asks you to change payment information
- Tells you that your account has been locked or compromised
- Asks you to log in through a link
Don't assume an email is legitimate simply because it contains familiar branding or appears to come from someone you recognize.
When in doubt, don't use the link or contact information in the message. Open the organization's official website or app yourself and verify the request.
Phishing is a form of social engineering that can be used to steal credentials, financial information or personal information, or to convince someone to transfer money.
T — Trick websites
Fraudsters can create websites that closely resemble legitimate websites.
A fake website may copy an organization's:
- Logo
- Colours
- Fonts
- Page layout
- Login screen
- Language and branding
The website address may contain a subtle spelling difference, an unfamiliar domain or another variation designed to look legitimate.
Don't judge a website by appearance alone
A professional-looking website can still be fraudulent. Check the website address carefully before entering sensitive information, but remember that HTTPS or a padlock icon does not prove that a website is legitimate. A fraudulent website can also use an encrypted HTTPS connection.
The safest approach is to navigate directly to the organization's official website or use its official mobile app rather than following an unexpected link. Never enter your password, banking credentials, card information or other sensitive information into a website simply because a message directed you there.
T — Text messages
Text-message scams, also known as smishing, are increasingly common.
A fraudulent text may appear to come from:
- Your financial institution
- A delivery company
- A government organization
- A retailer
- A telecommunications provider
- A utility company
The message might claim:
- Your account has been locked.
- A payment failed.
- There has been suspicious activity.
- A package could not be delivered.
- You need to verify your identity.
- You are entitled to a refund or rebate.
- You need to make an urgent payment.
The goal is usually to get you to react before you have time to verify the request.
Don't trust the sender information alone
Fraudsters can spoof phone numbers and sender information. In some cases, fraudulent texts can even appear in the same conversation thread as legitimate messages from an organization.
If you receive an unexpected text:
Don't click the link. Don't reply. Don't provide sensitive information.
Instead, open the organization's official website or app yourself or contact the organization using a trusted phone number. Suspicious text messages can also be forwarded to 7726 (SPAM) through participating mobile providers.
A — A telephone call
Phone scams, also called vishing, use voice calls or voicemail to trick people into revealing information, making payments or providing access to accounts.
A fraudster may claim to be calling from:
- Your financial institution
- The Canada Revenue Agency
- A government organization
- A technology company
- A delivery company
- Your employer
- A police service
- Another trusted organization
The caller may use urgency, fear or authority to pressure you into acting immediately. They may also spoof the phone number displayed on your caller ID, making the call appear to come from a legitimate organization.
What should you do?
If you receive an unexpected call asking for sensitive information or money:
- Don't provide personal or financial information.
- Don't give the caller remote access to your computer or device.
- Don't rely on caller ID to verify the caller.
- End the call if you are uncomfortable or uncertain.
- Contact the organization independently using a trusted phone number.
If someone claims to be calling from your financial institution, use the phone number on the back of your debit or credit card rather than a number provided by the caller. You are never required to stay on a suspicious call just because the caller claims to represent a legitimate organization.
C — Contest winner
"Congratulations! You've won!"
A surprise prize or contest notification can be tempting—but ask yourself one important question:
Did you actually enter the contest?
Fraudsters may contact you by email, text message, phone or social media and claim that you've won money, a gift, a vehicle, a vacation or another valuable prize.
You may then be asked to:
- Pay a fee to receive your prize
- Provide banking information
- Provide identification
- Click a link
- Purchase gift cards
- Send money
- Provide a verification code
If you don't remember entering the contest, be extremely cautious. Don't pay money or provide sensitive information simply because someone tells you that you've won something.
K — Key threats
The original ATTACK article referred to "key loggers," but the broader risk is more important than one specific type of malware. Fraudsters may use malicious websites, downloads, attachments, pop-ups or other techniques to steal information or compromise your device. For example, a fake pop-up may claim that your device has a virus and tell you to call a phone number or download software. The person on the other end may then attempt to obtain payment, personal information or remote access to your computer.
Other malicious content can install malware designed to steal information or compromise your device.
Protect yourself
- Don't download software from unexpected pop-ups.
- Don't give an unknown person remote access to your device.
- Keep your operating system, browser and applications updated.
- Use reputable security software where appropriate.
- Be cautious with unexpected attachments and downloads.
- If you believe your device has been compromised, disconnect it from the internet and seek help from a qualified and reputable source.
The golden rule: Stop, Verify and Report
Social engineering scams work because fraudsters want you to react before you have time to think. When something unexpected arrives, remember:
STOP
Don't click, reply, pay, download or provide information immediately.
VERIFY
Contact the organization independently.
Use its official website, official mobile app or a trusted phone number. Don't use the contact information provided in a suspicious message.
REPORT
Report suspicious messages and suspected fraud to the appropriate organization. In Canada, suspected fraud can be reported to the Canadian Anti-Fraud Centre (CAFC). The CAFC can be reached at 1-888-495-8501, and Canadians are encouraged to report fraud even when there has been no financial loss.
What should you never share with an unexpected caller or message?
Be extremely cautious about requests for:
- Passwords
- Banking credentials
- Debit or credit card information
- PINs
- Security codes or one-time verification codes
- Social Insurance Numbers
- Answers to security questions
- Personal identification information
- Remote access to your computer or phone
A legitimate organization will not become less legitimate simply because you take time to verify a request.
If someone pressures you to act immediately, that's a reason to slow down—not speed up.
What should you do if you think you've been scammed?
If you believe you provided personal, banking or account information to a fraudster, act quickly.
If you provided your banking information
Contact your financial institution immediately using a trusted phone number and explain what happened.
If you provided a password
Change it immediately using a trusted device. If you used the same password anywhere else, change it there too.
If you provided a verification code
Contact the organization associated with the account immediately. A fraudster may have been attempting to gain access to your account.
If you sent money
Contact your financial institution or payment provider immediately. Depending on the type of transaction, they may be able to provide assistance.
If you downloaded suspicious software
Disconnect the affected device from the internet and seek assistance from a qualified and reputable technology professional.
Report the incident
Report suspected fraud to the Canadian Anti-Fraud Centre and, where appropriate, your local police service.
YNCU members: Think you've been targeted?
If you are a YNCU member and believe your banking information or account may have been compromised, contact YNCU as soon as possible.
YNCU Service Excellence Centre:
1-888-413-YNCU (9628)
For current hours and contact information, visit YNCU's Contact page. If your YNCU debit card has been lost or stolen, YNCU also provides an after-hours number through its current contact information.
Remember: You don't have to respond immediately
Fraudsters may use fear, urgency, authority, curiosity or excitement to influence your decisions.
You have the right to stop.
You have the right to ask questions.
You have the right to hang up.
You have the right to delete the message.
You have the right to verify the request independently.
You have the right to say no.
When in doubt: Stop. Verify. Report.
Taking a few extra seconds before clicking a link, providing information, sending money or downloading something can help protect your identity, your accounts and your money.
Frequently asked questions about social engineering scams
What is social engineering?
Social engineering is a type of scam or cyberattack that uses manipulation and deception to convince people to reveal information, provide access, send money or take another action that benefits a fraudster.
What is phishing?
Phishing is a form of social engineering in which a fraudster sends a message that appears to come from a trusted source to trick someone into revealing information, clicking a malicious link, opening an attachment or transferring money.
What is smishing?
Smishing is phishing delivered through SMS or text messages. Fraudsters may impersonate banks, government organizations, delivery companies and other trusted businesses.
What is vishing?
Vishing, or voice phishing, is a social engineering scam conducted through phone calls or voicemail. Fraudsters may spoof caller ID or use other techniques to make a call appear legitimate.
How can I tell if a message is a scam?
Common warning signs include unexpected messages, urgency, suspicious links, requests for sensitive information, unexpected payment requests and unusual instructions. However, professional branding, correct spelling, a familiar sender name or even a familiar phone number does not prove that a message is legitimate.
Is HTTPS enough to prove that a website is safe?
No. HTTPS encrypts the connection between your browser and the website, but it does not prove that the website itself is legitimate. Always verify the website address and, for sensitive transactions, navigate to the organization's official website or app yourself.
Should I click a link in a text message from my financial institution?
If you weren't expecting the message, don't click the link. Instead, access your financial institution through its official website or mobile app, or call using a trusted number such as the number on the back of your debit or credit card.
Can scammers spoof phone numbers?
Yes. Fraudsters can spoof caller ID and other sender information, making a call or text appear to come from a legitimate organization. Don't rely on the displayed number alone to verify who contacted you.
What should I do if I accidentally clicked a suspicious link?
Don't panic. Close the page and don't enter additional information. If you entered a password, change it using a trusted device. If you provided banking or payment information, contact your financial institution immediately.
What should I do if I receive a suspicious text?
Don't click the link or reply. Verify the request independently if necessary, report the message and delete it. Suspicious SMS messages can be forwarded to 7726 (SPAM) through participating mobile providers.
Where can I report a scam in Canada?
You can report suspected fraud to the Canadian Anti-Fraud Centre at 1-888-495-8501 or through its online reporting system. If you have experienced a financial loss or another crime, you should also contact your financial institution and local police as appropriate.



