Social Engineering
In a hyper-connected world anyone can be a target.
Cybercriminals are constantly developing new ways to manipulate people into sharing confidential information, granting access to systems, or taking actions that compromise security. These attacks often exploit emotions such as fear, curiosity, urgency, or trust.
The UH Security Awareness Team is here to help you recognize these threats and protect your personal and university data.
Social Engineering Attacks
Social engineering attacks are all about manipulation. Rather than hacking computers, attackers target people—convincing them to click, share, or act in ways that benefit the attacker.
Types of Social Engineering Attacks
1. Phishing - Fake emails or messages designed to steal information or gain access.
2. Smishing - Phishing attacks delivered through text messages.
3. Vishing - Phishing attacks delivered through phone calls or voice messages.
4. Pretexting - Creating a believable story or scenario to obtain information or access.
5. Deepfakes - Using AI-generated audio, video, or images to impersonate trusted individuals.
Common Social Engineering Attacks
Phishing Emails
Fraudulent emails that appear to come from trusted sources, such as your bank, a professor,
or the university. They may ask you to verify account information, enter your password,
open an attachment, or click a link.
Vishing (Voice Phishing)
Phone calls or voice messages from scammers pretending to represent your bank, technical
support, government agencies, or other trusted organizations. Their goal may be to
steal sensitive information, gain access to an account, or convince you to send money.
Smishing (SMS Phishing)
Text messages designed to look legitimate. They may include malicious links, fake
delivery notifications, fraudulent account alerts, or instructions to call a fake
support number.
How to Spot a Social Engineering Attack
Trust your instincts. If something feels suspicious, pause.
Look for these common warning signs:
• Unknown sender or caller?
If you don't recognize the person or weren't expecting the message, treat it with
caution.
• Urgent or threatening language?
Attackers often create a false sense of urgency or fear, or pressure to make you act
before you have time to think.
• Suspicious contact information?
Carefully check email addresses, phone numbers, and website URLs. Small differences
can be a sign of a scam.
• Unexpected links or attachments?
Don’t click or open them until you've verified they're legitimate.
How to Protect Yourself
Pause. Verify. Then act. A few simple habits can help protect your accounts and data
• Verify unexpected requests
Confirm requests using a trusted contact method—not the phone number, email address,
or link provided in the suspicious message.
• Be cautious with phone calls
Never feel pressured to share sensitive information. If you're unsure, hang up and
contact the organization using an official phone number.
• Use multi-factor authentication (MFA)
Enable MFA whenever possible. Even if your password is compromised, MFA provides an
extra layer of protection.
• Create strong unique passwords, passkeys
Use long, unique passwords for every account. A password manager can generate and
securely store passwords, while passkeys offer a more secure, phishing-resistant way
to sign in.
When in Doubt, Check It Out.
If you receive a suspicious message or request involving your UH account or university data, don't respond or click. Pause and verify before you act.
If you have questions or need additional guidance, contact UHS Information Security at security@uh.edu.
Thanks for taking the time to learn how to recognize and prevent social engineering attacks.