Social Engineering in Cybercrime
SyllabusBasics of cyber security: cyber crime, data protection and critical infrastructure
Social engineering is the manipulation of people into revealing information or taking actions that benefit a fraudster. In cyber-enabled financial fraud, attackers exploit trust, fear, urgency or greed to obtain payment credentials or induce victims to authorise transfers. The immediate weakness is often human decision-making rather than a technical flaw in the banking system.
How human behaviour is exploited
The attacker creates a believable situation in which complying appears safer or more rewarding than questioning the request. Information gathered about the victim can make this deception more convincing.
- Authority and trust are exploited by impersonating a bank employee, government official, customer-support agent or familiar person.
- Urgency and fear are created through threats of account blocking, financial loss or other adverse consequences, discouraging independent verification.
- Attractive rewards, refunds or investment returns exploit the desire for financial gain and can persuade victims to ignore warning signs.
- A helpful or familiar-looking interaction can lower suspicion, leading victims to share information they would otherwise protect.
How deception becomes financial loss
Social engineering connects a persuasive story to an actionable request. The victim may disclose a secret, install software or approve a transaction, allowing the attacker to turn deception into financial loss.
- Phishing uses deceptive messages and imitation websites to collect banking credentials or other sensitive information.
- Vishing and smishing deliver similar deception through voice calls and SMS messages respectively.
- Fraudsters may solicit passwords, card details, PINs or one-time passwords under the pretext of account verification or assistance.
- Under a customer-support pretext, attackers may persuade victims to install remote-access software that enables access to their devices and sensitive information.
- A UPI collect request may be misrepresented as a way to receive money; entering the UPI PIN to approve it authorises a debit.
- Even without stealing credentials, impersonation can persuade victims to transfer money voluntarily to an attacker-controlled account.
Breaking the manipulation chain
Prevention requires both informed users and institutional safeguards. The key is independent verification before disclosing information or authorising payment.
- Users should contact institutions through independently obtained official channels rather than numbers or links supplied in an unsolicited message.
- Passwords, OTPs and PINs must remain confidential; a UPI PIN is not required to receive money.
- Users should check the recipient, amount and payment request before approval and avoid installing applications at an unknown caller's direction.
- Financial institutions should combine customer awareness with transaction monitoring and fraud-reporting mechanisms.
- Suspected fraud should be reported promptly to the bank and official cybercrime-reporting channels to support attempts to limit loss.
Keep reading
The news behind topics like this, explained every day
Every day Gyaanam reads The Hindu, the Indian Express and PIB and picks what matters for UPSC. Each story is written up against the syllabus line it belongs to. Your first 7 days or 3 articles are free, whichever ends first.