Glossary

The social engineering
glossary.

This glossary defines the attacks people face at work, from phishing and vishing to QR code, calendar-invite and WhatsApp lures, and the terms used to defend against them, such as phishing simulation, just-in-time training and policy attestation.

Terms
Attacks, channels and defences
Format
Definition, how it works, simulated example, FAQ
Examples
Simulated, with generic senders and .example links
Next step
Each term links to the matching KeenSec page

All terms

Attacks, channels
and defences.

Start with the umbrella terms, then the channels attackers use, then the ways organisations prepare people for them.

Attack

Social engineering

Social engineering is the manipulation of people, rather than technology, to get them to share information, grant access or move money.

Read definition
Attack

Phishing

Phishing is a social engineering attack in which someone sends a fraudulent message, usually by email but also by SMS, chat or phone, pretending to be a trusted person or organisation.

Read definition
Attack

Spear-phishing

Spear-phishing is a targeted form of phishing aimed at a specific person, team or organisation.

Read definition
Attack

Business email compromise

Business email compromise (BEC) is a fraud in which an attacker impersonates, or takes over, a trusted business email account, such as a supplier, executive or colleague, to trick staff into sending money or sensitive data.

Read definition
Attack

Credential harvesting

Credential harvesting is an attack that collects usernames, passwords and sometimes one-time codes by luring people to a fake login page.

Read definition
Attack

Callback phishing

Callback phishing is a hybrid attack in which a message, usually an email about an unexpected charge, subscription or invoice, urges the recipient to phone a number.

Read definition
Channel

Vishing

Vishing (voice phishing) is a social engineering attack carried out over the phone.

Read definition
Channel

Smishing

Smishing (SMS phishing) is a phishing attack sent by text message.

Read definition
Channel

RCS phishing

RCS phishing is phishing delivered through Rich Communication Services, the messaging standard that adds images, logos, buttons and read receipts to text messages.

Read definition
Channel

Quishing

Quishing (QR code phishing) is a phishing attack that hides a malicious link inside a QR code.

Read definition
Channel

WhatsApp phishing

WhatsApp phishing is a social engineering attack sent through WhatsApp messages.

Read definition
Channel

Calendar phishing

Calendar phishing is an attack that uses a fake meeting invitation to deliver a malicious link, file or phone number.

Read definition
Defence

Phishing simulation

A phishing simulation is a controlled, authorised exercise in which an organisation sends realistic but harmless phishing messages to its own employees.

Read definition
Defence

Security awareness training

Security awareness training is an ongoing programme that teaches employees to recognise and respond to security threats such as phishing, social engineering and unsafe data handling.

Read definition
Defence

Just-in-time training

Just-in-time training is a short lesson delivered at the moment someone needs it, typically right after they make a risky choice such as clicking a simulated phishing link.

Read definition
Defence

Micro-learning

Micro-learning is a training approach that delivers content in short, focused lessons, usually a few minutes long, each covering a single idea or behaviour.

Read definition
Defence

Policy attestation

Policy attestation is an employee’s recorded confirmation that they have read, understood and agree to follow a specific version of an organisational policy, such as an acceptable use or information security policy.

Read definition
Defence

Human risk management

Human risk management is an approach to security that measures and reduces the risk created by people’s behaviour, such as clicking phishing links, mishandling data or skipping policies.

Read definition
HOW TO USE THIS GLOSSARY

Every example here is simulated. Senders are generic and links use .example domains, so you can share any entry with colleagues as a quick lesson.

Questions buyers ask

Frequently asked questions.

What is the difference between phishing and social engineering?

Social engineering is the wider idea of manipulating people into unsafe actions. Phishing is one form of it, delivered through messages such as email, SMS or chat.

Are the examples in this glossary real attacks?

No. They are simulated examples written for teaching, with generic senders and .example links. They mirror common patterns without copying any real message.

Which phishing channels should organisations prepare for?

Email is still the most familiar, but lures also arrive by SMS and RCS, phone calls, WhatsApp, collaboration tools, QR codes and calendar invites. Preparing people across channels matters because attackers switch between them.

Let’s connect the dots

See the human risk.
Change what happens next.

Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.

Book a demo