GCSE · Computer Science · Edexcel · Spec 1CP2

Social engineering

The easiest way into a secure system isn't breaking the code. It's persuading a person to open the door.

Social engineering · Spot the technique

What does the attacker want the victim to do?

Pick a situation, then choose the technique it shows. Before you choose, ask: what is the attacker trying to get the victim to do?

Still to sort

Blagging (0)

An invented story, kept going until the victim hands over data or money.

Where the line is: Blagging is a made-up scenario used to persuade someone, usually in conversation. Phishing is a fake message or website that tries to get you to click or type your details.

Phishing (0)

A fake email, message or website pretending to be someone you trust.

Where the line is: Phishing needs you to take the bait and click. With pharming, you typed the correct address yourself.

Pharming (0)

You type the correct web address and still end up on a bogus site.

Where the line is: Pharming works even when the victim did everything right — no suspicious link was clicked.

Shouldering (0)

Watching someone enter a password or PIN.

Where the line is: Shouldering is watching what someone types. Eavesdropping is listening to what people say.

Name generator attack (0)

A 'fun' quiz or name game that gets people to share personal details.

Where the line is: Unlike phishing, it doesn't pretend to be your bank or ask you to log in. People share the details themselves because it looks like harmless fun.

Tailgating (0)

An unauthorised person following an authorised person into secured premises.

Where the line is: Tailgating gets the attacker physically through a secure door. Shouldering gets them information by watching someone type.

Eavesdropping (0)

Being physically close enough to overhear a confidential conversation.

Where the line is: Eavesdropping is listening in on a conversation. The attacker doesn't have to say a word, which is what separates it from blagging.

9 of 9 still to sort.

Nine situations, seven techniques. Some of them look alike — the reasons show you exactly where the line falls.

Why does this work?

Is strong security enough?

A company has just installed strong, up-to-date security on every one of its computers.

Which is closest to what you think right now?
How sure are you?

Phishing vs pharming

PhishingvsPharming

Both end on a fake website. The difference is how the victim got there.

Focus

How the victim reaches the fake site

Phishing

They're tricked into clicking a link in a fake email, message or website.

Pharming

They're redirected to a bogus site even though they typed the correct web address.

The insight

This is the difference that matters. Phishing needs the victim to take the bait; pharming works even when they do everything right.

What starts the attack

Phishing

A message pretending to be a trusted source, such as a bank or a company.

Pharming

No message is needed. The victim heads to the real address themselves and gets sent somewhere fake.

What the attacker is after

Phishing

Personal details the victim types in, such as usernames, passwords or bank information.

Pharming

Details typed into a fake copy of a site — pharming is often aimed at bank or online shopping websites.

The question to ask in a scenario

Phishing

Did the victim get here by clicking something they were sent?

Pharming

Did the victim type the correct address and still end up somewhere fake?

Predict, then check

It looks like harmless fun. Think like the person who made it.

A quiz is going round: 'How well do your friends know you? 1. What's your favourite colour? 2. What's your mum's maiden name? 3. Which town were you born in?' What is its creator most likely collecting?

Your turn

Give advice that fits the attack

Jess gets a phone call from someone who says they're from her bank. They tell her that her account has been used for fraud, that she must act within five minutes, and that they need her online banking password to 'secure' the account.

Give three different pieces of advice to help Jess protect herself in this situation. For each one, say briefly why it helps. [3 marks]

0 words · your answer stays on this page and is not sent anywhere.

WHAT YOU'VE LEARNED

A quick recap of today's lesson.

Hacking people, not computers: how criminals trick someone into opening the door — and how to spot it.

What you need to know

  • Social engineering means tricking or manipulating people into revealing confidential information or taking actions that compromise security.
  • It targets human psychology — trust, curiosity, fear and helpfulness — rather than technical weaknesses, and relies on human error such as clicking a link or sharing a password.
  • Criminals use it because tricking a person can be easier than hacking software: even strong security can be compromised if someone is tricked.
  • Know the seven techniques by what the attacker does: blagging, phishing, pharming, shouldering, name generator attacks, tailgating and eavesdropping.
  • To protect yourself: be cautious with emails, links and attachments; never share passwords; check unexpected contacts through official channels; cover your screen or keypad; keep personal details out of online quizzes; and don't rush when you're put under pressure.

The big picture

Social engineering is when cyber criminals trick or manipulate people into revealing confidential information or doing something that compromises security. Instead of attacking weaknesses in the technology, it targets human psychology — trust, curiosity, fear and helpfulness — and it succeeds through human error, like clicking a link or sharing a password. The main techniques are blagging, phishing, pharming, shouldering, name generator attacks, tailgating and eavesdropping. Working out what the attacker wants the victim to do is how you spot each one, and how you protect yourself.

Key points

1Blagging (pretexting): an invented story, often kept going in conversation until the victim hands over data or money.
2Phishing: a fake email, message or website posing as a trusted source, such as a bank, to get you to click a link or type in your details.
3Pharming: you type the correct web address and are still redirected to a bogus site — often a bank or online shopping site.
4Shouldering is watching someone enter a password or PIN; eavesdropping is being physically close enough to overhear a confidential conversation.
5A name generator attack is a 'fun' quiz or name game that collects answers to security questions, such as mother's maiden name or place of birth.
6Tailgating is a physical breach: an unauthorised person follows an authorised person into secured premises.

Worked example

Problem

A receptionist gets a phone call from someone who says they are the company's new IT technician. The caller chats about the office for a few minutes, then says the computer system needs an urgent update and asks for the receptionist's login details. Identify the social engineering technique and justify your answer.

⚠ Watch out

Calling every online trick 'phishing'. If the victim typed the correct web address themselves and still ended up on a fake site, nothing was clicked — that's pharming.

🧠

Memory hook

PHishing hooks you with bait, so you click. PHarming moves the road: you typed the right address and still got diverted to a fake site.

✓

Check yourself

A friend says, 'I'm safe from social engineering — I've got a really strong password.' What would you tell them, and why?

Flashcards

(13)
What is social engineering?
Tricking or manipulating people into revealing confidential information or doing something that compromises security.
Which human feelings does social engineering exploit?
Trust, curiosity, fear and helpfulness. It targets people's psychology rather than technical weaknesses.
Why can social engineering beat strong security?
It relies on human error. If someone is tricked into sharing a password or clicking a link, the security is bypassed — and tricking a person can be easier than hacking software.
Blagging (pretexting)
The attacker invents a scenario to persuade the victim to give them data or money, often keeping a conversation going until the victim gives in.
Phishing
Fake emails, messages or websites that pretend to be a trusted source, to trick victims into clicking a link or entering details such as passwords or bank information.
Pharming
Redirecting victims to a bogus website even when they typed the correct web address. It's often aimed at bank or online shopping websites.
Shouldering
Watching a victim — for example over their shoulder — while they enter sensitive information such as a password or a PIN at a cash machine.
Name generator attack
A quiz or 'name game' that gets people to combine or share personal details, collecting answers to security questions such as mother's maiden name or place of birth.
Tailgating
A physical security breach: an unauthorised person follows an authorised person into secured premises.
Eavesdropping
The attacker is physically present to overhear confidential conversations.
Will a real bank ask for your password by email or phone?
No. Real organisations don't ask for passwords that way, so a request like that is a warning sign.
Someone unexpected contacts you, claiming to be from a company. What should you do before sharing anything?
Check who they are through the company's official channels — and don't let pressure rush you into a decision.
How can you avoid handing out security-question answers online?
Don't share personal details, such as your mother's maiden name or place of birth, in online quizzes or on social media.

Tap any card to flip it, or use Study as deck to go through them one at a time. In the full lesson these run as a spaced-repetition deck — you rate each card Hard, Good or Easy and the tricky ones keep coming back until they stick.

Learning with Lightbulb is opening soon

You can use this lesson now. Join the waitlist and we'll let you know when the full Lightbulb experience is ready.

Keep me posted

More Edexcel GCSE Computer Science topics

See the full Edexcel Computer Science curriculum →

How this lesson was checked. This Edexcel GCSE Computer Science (specification 1CP2)lesson was published through Lightbulb Learning's human-designed editorial process — the educational standards, accuracy rules and publication checks it must pass were authored and approved by Philip Halpin. It passed subject-specific assessment, automated educational checks and technical publication verification before going live (publication checks completed 1 October 2026). Published pages are monitored, human spot-checking is ongoing across the lesson library, and anything found wrong is corrected or withdrawn. How our lessons are made and checked. Spotted a mistake? Email hello@lightbulblearning.co and we'll review it.