GCSE · Computer Science · AQA · Spec 8525

Social engineering

The strongest lock in the building is no help if someone politely asks the person holding the key — and is handed it.

Computer Science · Structure

Social engineering and its three forms

Tap the top box for the definition, then each form below to see what it is and the habit it exploits.

Tap any part of the diagram to see what it does.

Two inventions, two different tricks

Blagging (pretexting)vsPhishing

Blagging and phishing are the pair most often mixed up. Both are inventions; what separates them is what is invented — a scenario put to a chosen person, or a fraudulent request for private information.

Focus

What the invention is

Blagging (pretexting)

An invented scenario — a role, and a reason for asking — used to engage a chosen victim. It can be put to them by phone, by message or face to face; the scenario is what makes it blagging, not the channel.

Phishing

A fraudulent request for private information — most often an email or a text written to look as though it came from an organisation the reader already trusts.

The insight

One is a story built to fit one chosen target; the other is a false request made to look as though it came from somewhere the reader trusts.

Who it is aimed at

Blagging (pretexting)

A chosen victim, with the scenario built to fit them — their employer, their account, the situation they are actually in.

Phishing

Often a wide group at once, with the same message sent out in the expectation that some readers will act on it.

What it asks the target to do

Blagging (pretexting)

Divulge information, or carry out an action they would not perform in ordinary circumstances, because the invented story makes it sound routine.

Phishing

Hand private information over in response to it — by replying, or by entering details on the page it leads to.

A sign worth noticing

Blagging (pretexting)

Someone who made contact with you is asking for information that their own job should already give them access to, and there is a reason it has to be right now.

Phishing

A message you were not expecting asks you to confirm private details, and the sender's real address does not match the organisation it names.

Predict, then check

There is a person at the centre of every form of social engineering. Use that to decide.

A company's customer records are stolen. The attacker spoke to nobody there: they found a weakness in the company's website software and used it to read the records directly. Which is it?

Why the defence is human

?

Reason it through

Why does protecting against social engineering come down to what people do, rather than what the technology does?

Link 1 of 4

First link · your turn

Start with what the attack actually targets. Where does a social engineering attack do its work?

2
Locked — reveal the link above first
3
Locked — reveal the link above first
4
Locked — reveal the link above first

WHAT YOU'VE LEARNED

A quick recap of today's lesson.

The attack that walks past the technology and asks a person instead.

What you need to know

  • Social engineering is the art of manipulating people so they give up confidential information.
  • Blagging (pretexting) is the act of creating and using an invented scenario to engage a targeted victim, in a way that increases the chance they will divulge information or perform actions that would be unlikely in ordinary circumstances.
  • Phishing is a technique of fraudulently obtaining private information, most often using email or SMS.
  • Shouldering (shoulder surfing) is observing a person's private information over their shoulder — cashpoint machine PIN numbers, for example.
  • Because the target is a person rather than a system, protecting against social engineering rests on what people do: verifying who is asking, keeping passwords and PINs private, and shielding screens and keypads.

The big picture

Social engineering is the art of manipulating people so they give up confidential information. This lesson defines it, works through its three forms — blagging, phishing and shouldering — and shows why protecting against it rests on what people know to do.

Key points

1What is attacked is the person, not the machine — which is why a well-maintained system is no defence on its own.
2Blagging works through an invented scenario, phishing through a fraudulent message, and shouldering through plain observation.
3Of the three, shouldering is the one that needs no invented story at all: the attacker only has to be in a position to watch.
4A security system cannot tell an honest request from a manipulated one, so training and procedure have to carry the defence.
5Verifying a request through a route you already trust answers both blagging and phishing, because each of them depends on you using the route the attacker supplied.

Worked example

Problem

A text message says that a parcel could not be delivered and asks you to confirm your address and card details by following a link. Identify the form of social engineering, and explain how the person receiving it could protect themselves.

⚠ Watch out

Using phishing as the name for any attempt to obtain private information. Phishing is fraudulently obtaining private information, most often through an email or a text that someone reads and acts on — an invented scenario put to a chosen victim is blagging, and somebody watching your keypad is shouldering.

🧠

Memory hook

Three ways in — a story (blagging), a message (phishing), a glance (shouldering) — and a person in the middle of all three.

✓

Check yourself

Without looking back: define social engineering, name its three forms, and say what each one needs from its target. Then give one precaution against a fraudulent message and one against being watched.

Flashcards

(6)
What is social engineering?
The art of manipulating people so they give up confidential information.
What is blagging (pretexting)?
Creating and using an invented scenario to engage a targeted victim, so that they become more likely to divulge information or perform actions that would be unlikely in ordinary circumstances.
What is phishing?
A technique of fraudulently obtaining private information, most often using email or SMS.
What is shouldering (shoulder surfing)?
Observing a person's private information over their shoulder — for example a cashpoint machine PIN number.
Why is technical security on its own not enough against social engineering?
The attack is made on the person rather than the system. The details handed over are genuine, so the system sees nothing wrong.
Give three precautions against social engineering.
Verify who is asking through a route you already trust; keep passwords and PINs to yourself however reasonable the request sounds; shield keypads and screens in public places.

Tap any card to flip it, or use Study as deck to go through them one at a time. In the full lesson these run as a spaced-repetition deck — you rate each card Hard, Good or Easy and the tricky ones keep coming back until they stick.

Learning with Lightbulb is opening soon

You can use this lesson now. Join the waitlist and we'll let you know when the full Lightbulb experience is ready.

Keep me posted

More AQA GCSE Computer Science topics

See the full AQA Computer Science curriculum →

How this lesson was checked. This AQA GCSE Computer Science (specification 8525)lesson was published through Lightbulb Learning's human-designed editorial process — the educational standards, accuracy rules and publication checks it must pass were authored and approved by Philip Halpin. It passed subject-specific assessment, automated educational checks and technical publication verification before going live (publication checks completed 29 September 2026). Published pages are monitored, human spot-checking is ongoing across the lesson library, and anything found wrong is corrected or withdrawn. How our lessons are made and checked. Spotted a mistake? Email hello@lightbulblearning.co and we'll review it.