Cyber security often brings to mind sophisticated hackers, malicious software and complex technical attacks. Yet many successful cyber attacks start in a much simpler way.
A conversation.
An email.
A phone call.
A text message.
This type of attack is known as social engineering. Rather than attacking technology, criminals target people. They rely on trust, urgency, curiosity and human nature to convince someone to reveal information, click a link, approve a payment or bypass a security process.
The worrying part is that social engineering attacks are becoming harder to spot. They often look completely legitimate and can catch out even experienced professionals.
Here are ten common social engineering red flags that should make you stop and think before you act.
1. The Request Is Extremely Urgent
“Can you do this immediately?”
“I need this payment sent before lunch.”
“This can’t wait.”
One of the most common tactics used by attackers is urgency. The goal is simple: stop you thinking and start you reacting.
When people feel pressure, they are more likely to skip checks and make mistakes.
Whenever somebody is demanding immediate action, especially where money or sensitive information is involved, take a moment to pause and verify the request.
If it is genuine, an extra five minutes is unlikely to matter. If it is fraudulent, those five minutes could save your business thousands of pounds.
2. Something Feels Out of Character
Most people learn the communication habits of their colleagues, customers and suppliers.
Perhaps your Managing Director never asks for purchases directly.
Maybe your finance manager always follows a specific approval process.
Perhaps your supplier normally calls before making important requests.
Social engineering often works because the message looks genuine at first glance, but something feels slightly different.
Trust your instincts.
If a request seems unusual, verify it using a different communication method before proceeding.
3. The Email Arrived at an Odd Time
An email arriving at 11:47pm on a Saturday.
A request sent while somebody is on holiday.
A message apparently coming from a senior manager outside their normal working hours.
This doesn’t automatically mean the email is malicious, but unexpected timing can sometimes be a warning sign.
Attackers know that unusual timing can reduce scrutiny, especially if they hope the recipient is rushing to clear emails before starting work.
Always take a closer look when a message arrives at an unexpected time and contains requests for action.
4. Someone Wants to Change Payment Details
This is one of the most expensive scams affecting UK businesses.
A supplier emails to say their bank account has changed.
The request appears legitimate.
An invoice is attached.
The email signature looks genuine.
The account number belongs to a criminal.
Before updating payment details, always verify the change using a trusted phone number that you already have on file. Never rely on contact details included in the email itself.
A two-minute phone call can prevent a costly mistake.
5. “Please Keep This Confidential”
Social engineers often try to isolate their target.
You may see phrases such as:
- “Don’t discuss this with anyone else.”
- “Keep this between us.”
- “I need your help discreetly.”
- “This is confidential.”
The objective is simple. The fewer people involved, the less likely somebody is to identify the fraud.
Legitimate confidential discussions do happen, of course, but requests involving money, credentials or unusual processes should always follow established business procedures.
6. Unexpected Links, Documents or QR Codes
Curiosity is a powerful tool.
Attackers know people are naturally inclined to investigate unexpected invoices, reports, missed delivery notices and shared documents.
Examples include:
- “Review this urgent invoice.”
- “Your parcel couldn’t be delivered.”
- “Open the attached report.”
- “Someone mentioned you in a document.”
Modern phishing attacks can look remarkably convincing.
Before opening links or attachments, consider whether you were genuinely expecting them and whether the sender is who they claim to be.
7. Somebody Claims to Be an Authority Figure
Social engineering often relies on authority.
The attacker pretends to be:
- Your Managing Director
- Microsoft Support
- HMRC
- A senior customer
- Your bank
- A trusted supplier
People naturally want to help authority figures and avoid causing delays.
Criminals understand this and exploit it.
Remember that genuine organisations will not object to reasonable verification checks when sensitive information, payments or account access is involved.
8. Social Media Quizzes Ask Suspicious Questions
We’ve all seen them.
“What was your first pet called?”
“What was the model of your first car?”
“What’s your mother’s maiden name?”
“Which school did you attend?”
Some quizzes are harmless fun, but others may be collecting information commonly used in account recovery processes and security questions.
Even when the intention is innocent, sharing large amounts of personal information publicly can provide criminals with useful pieces of a much larger puzzle.
Think carefully before sharing personal details online.
9. The Message Creates Fear or Panic
Social engineers frequently use fear to influence decisions.
Examples include:
- “Your account will be suspended.”
- “Payment has failed.”
- “Your tax records are being investigated.”
- “Your mailbox is full.”
- “Your computer has been compromised.”
Fear encourages people to act quickly without checking facts.
Whenever a message triggers panic, stop and verify the information through official channels before clicking links or following instructions.
10. You Are Being Asked to Bypass Normal Processes
This may be the biggest red flag of all.
If a request involves:
- Skipping approvals
- Ignoring procedures
- Sharing passwords
- Disabling security controls
- Circumventing established processes
You should immediately question why.
Most organisations have controls and procedures for a reason. Attackers know this and often attempt to persuade individuals that their situation is somehow an exception.
When someone asks you to bypass the rules, it is time to stop and verify.
Final Thoughts
Technology plays a vital role in cyber security.
Firewalls help.
Email filtering helps.
Multi-factor authentication helps.
But even the best technology cannot stop every social engineering attempt.
Your people remain your strongest defence and, unfortunately, often the primary target.
The good news is that most social engineering attacks share common warning signs. By recognising these red flags and encouraging a culture where staff feel comfortable questioning unusual requests, businesses can dramatically reduce their risk.
When in doubt, pause.
Verify.
Ask questions.
A few moments of caution today could prevent a major security incident tomorrow.
How Core Team One Can Help
At Core Team One, we help organisations strengthen both the technical and human sides of cyber security. Regular phishing simulations and cyber security training helps keep security at the forfront of employees minds – this helps businesses build practical defences against modern threats.
If you’d like to improve your organisation’s resilience against social engineering attacks, get in touch with us today.