Think twice before you click, reply, pay, download or share information.
Social engineering scams are designed to manipulate people into revealing personal or confidential information, clicking malicious links, downloading harmful software, sending money or giving fraudsters access to their accounts. These attacks can happen through email, websites, text messages, phone calls, social media and other digital channels. Fraudsters often impersonate people or organizations you know and trust, including financial institutions, government organizations, delivery companies, technology providers and even friends or family members. The good news is that recognizing a few common warning signs can help you stop a scam before it succeeds.
Social engineering is a type of fraud that relies on manipulation and deception rather than simply exploiting a technical vulnerability. A fraudster may create a sense of urgency, fear, excitement or trust to convince you to take an action that benefits them. Common social engineering attacks include phishing emails, fraudulent text messages, fake websites, phone scams, impersonation scams and targeted attacks. Fraudsters may also use publicly available information and artificial intelligence to make scams more convincing and personalized.
One simple rule can help:
If an unexpected message or call asks you to act quickly, stop and verify it independently before doing anything.
Use the A.T.T.A.C.K. technique to help identify common social engineering tactics.
Phishing emails can look surprisingly legitimate. A fraudulent email may appear to come from your financial institution, a government organization, a retailer, delivery company, employer or someone you know.
Be cautious when an unexpected email:
Don't assume an email is legitimate simply because it contains familiar branding or appears to come from someone you recognize.
When in doubt, don't use the link or contact information in the message. Open the organization's official website or app yourself and verify the request.
Phishing is a form of social engineering that can be used to steal credentials, financial information or personal information, or to convince someone to transfer money.
Fraudsters can create websites that closely resemble legitimate websites.
A fake website may copy an organization's:
The website address may contain a subtle spelling difference, an unfamiliar domain or another variation designed to look legitimate.
A professional-looking website can still be fraudulent. Check the website address carefully before entering sensitive information, but remember that HTTPS or a padlock icon does not prove that a website is legitimate. A fraudulent website can also use an encrypted HTTPS connection.
The safest approach is to navigate directly to the organization's official website or use its official mobile app rather than following an unexpected link. Never enter your password, banking credentials, card information or other sensitive information into a website simply because a message directed you there.
Text-message scams, also known as smishing, are increasingly common.
A fraudulent text may appear to come from:
The message might claim:
The goal is usually to get you to react before you have time to verify the request.
Fraudsters can spoof phone numbers and sender information. In some cases, fraudulent texts can even appear in the same conversation thread as legitimate messages from an organization.
If you receive an unexpected text:
Don't click the link. Don't reply. Don't provide sensitive information.
Instead, open the organization's official website or app yourself or contact the organization using a trusted phone number. Suspicious text messages can also be forwarded to 7726 (SPAM) through participating mobile providers.
Phone scams, also called vishing, use voice calls or voicemail to trick people into revealing information, making payments or providing access to accounts.
A fraudster may claim to be calling from:
The caller may use urgency, fear or authority to pressure you into acting immediately. They may also spoof the phone number displayed on your caller ID, making the call appear to come from a legitimate organization.
If you receive an unexpected call asking for sensitive information or money:
If someone claims to be calling from your financial institution, use the phone number on the back of your debit or credit card rather than a number provided by the caller. You are never required to stay on a suspicious call just because the caller claims to represent a legitimate organization.
"Congratulations! You've won!"
A surprise prize or contest notification can be tempting—but ask yourself one important question:
Did you actually enter the contest?
Fraudsters may contact you by email, text message, phone or social media and claim that you've won money, a gift, a vehicle, a vacation or another valuable prize.
You may then be asked to:
If you don't remember entering the contest, be extremely cautious. Don't pay money or provide sensitive information simply because someone tells you that you've won something.
The original ATTACK article referred to "key loggers," but the broader risk is more important than one specific type of malware. Fraudsters may use malicious websites, downloads, attachments, pop-ups or other techniques to steal information or compromise your device. For example, a fake pop-up may claim that your device has a virus and tell you to call a phone number or download software. The person on the other end may then attempt to obtain payment, personal information or remote access to your computer.
Other malicious content can install malware designed to steal information or compromise your device.
Social engineering scams work because fraudsters want you to react before you have time to think. When something unexpected arrives, remember:
Don't click, reply, pay, download or provide information immediately.
Contact the organization independently.
Use its official website, official mobile app or a trusted phone number. Don't use the contact information provided in a suspicious message.
Report suspicious messages and suspected fraud to the appropriate organization. In Canada, suspected fraud can be reported to the Canadian Anti-Fraud Centre (CAFC). The CAFC can be reached at 1-888-495-8501, and Canadians are encouraged to report fraud even when there has been no financial loss.
Be extremely cautious about requests for:
A legitimate organization will not become less legitimate simply because you take time to verify a request.
If someone pressures you to act immediately, that's a reason to slow down—not speed up.
If you believe you provided personal, banking or account information to a fraudster, act quickly.
Contact your financial institution immediately using a trusted phone number and explain what happened.
Change it immediately using a trusted device. If you used the same password anywhere else, change it there too.
Contact the organization associated with the account immediately. A fraudster may have been attempting to gain access to your account.
Contact your financial institution or payment provider immediately. Depending on the type of transaction, they may be able to provide assistance.
Disconnect the affected device from the internet and seek assistance from a qualified and reputable technology professional.
Report suspected fraud to the Canadian Anti-Fraud Centre and, where appropriate, your local police service.
If you are a YNCU member and believe your banking information or account may have been compromised, contact YNCU as soon as possible.
YNCU Service Excellence Centre:
1-888-413-YNCU (9628)
For current hours and contact information, visit YNCU's Contact page. If your YNCU debit card has been lost or stolen, YNCU also provides an after-hours number through its current contact information.
Fraudsters may use fear, urgency, authority, curiosity or excitement to influence your decisions.
You have the right to stop.
You have the right to ask questions.
You have the right to hang up.
You have the right to delete the message.
You have the right to verify the request independently.
You have the right to say no.
When in doubt: Stop. Verify. Report.
Taking a few extra seconds before clicking a link, providing information, sending money or downloading something can help protect your identity, your accounts and your money.
Social engineering is a type of scam or cyberattack that uses manipulation and deception to convince people to reveal information, provide access, send money or take another action that benefits a fraudster.
Phishing is a form of social engineering in which a fraudster sends a message that appears to come from a trusted source to trick someone into revealing information, clicking a malicious link, opening an attachment or transferring money.
Smishing is phishing delivered through SMS or text messages. Fraudsters may impersonate banks, government organizations, delivery companies and other trusted businesses.
Vishing, or voice phishing, is a social engineering scam conducted through phone calls or voicemail. Fraudsters may spoof caller ID or use other techniques to make a call appear legitimate.
Common warning signs include unexpected messages, urgency, suspicious links, requests for sensitive information, unexpected payment requests and unusual instructions. However, professional branding, correct spelling, a familiar sender name or even a familiar phone number does not prove that a message is legitimate.
No. HTTPS encrypts the connection between your browser and the website, but it does not prove that the website itself is legitimate. Always verify the website address and, for sensitive transactions, navigate to the organization's official website or app yourself.
If you weren't expecting the message, don't click the link. Instead, access your financial institution through its official website or mobile app, or call using a trusted number such as the number on the back of your debit or credit card.
Yes. Fraudsters can spoof caller ID and other sender information, making a call or text appear to come from a legitimate organization. Don't rely on the displayed number alone to verify who contacted you.
Don't panic. Close the page and don't enter additional information. If you entered a password, change it using a trusted device. If you provided banking or payment information, contact your financial institution immediately.
Don't click the link or reply. Verify the request independently if necessary, report the message and delete it. Suspicious SMS messages can be forwarded to 7726 (SPAM) through participating mobile providers.
You can report suspected fraud to the Canadian Anti-Fraud Centre at 1-888-495-8501 or through its online reporting system. If you have experienced a financial loss or another crime, you should also contact your financial institution and local police as appropriate.