Glossary
The social engineering
glossary.
This glossary defines the attacks people face at work, from phishing and vishing to QR code, calendar-invite and WhatsApp lures, and the terms used to defend against them, such as phishing simulation, just-in-time training and policy attestation.
- Terms
- Attacks, channels and defences
- Format
- Definition, how it works, simulated example, FAQ
- Examples
- Simulated, with generic senders and .example links
- Next step
- Each term links to the matching KeenSec page
All terms
Attacks, channels
and defences.
Start with the umbrella terms, then the channels attackers use, then the ways organisations prepare people for them.
Social engineering
Social engineering is the manipulation of people, rather than technology, to get them to share information, grant access or move money.
Read definition AttackPhishing
Phishing is a social engineering attack in which someone sends a fraudulent message, usually by email but also by SMS, chat or phone, pretending to be a trusted person or organisation.
Read definition AttackSpear-phishing
Spear-phishing is a targeted form of phishing aimed at a specific person, team or organisation.
Read definition AttackBusiness email compromise
Business email compromise (BEC) is a fraud in which an attacker impersonates, or takes over, a trusted business email account, such as a supplier, executive or colleague, to trick staff into sending money or sensitive data.
Read definition AttackCredential harvesting
Credential harvesting is an attack that collects usernames, passwords and sometimes one-time codes by luring people to a fake login page.
Read definition AttackCallback phishing
Callback phishing is a hybrid attack in which a message, usually an email about an unexpected charge, subscription or invoice, urges the recipient to phone a number.
Read definition ChannelVishing
Vishing (voice phishing) is a social engineering attack carried out over the phone.
Read definition ChannelSmishing
Smishing (SMS phishing) is a phishing attack sent by text message.
Read definition ChannelRCS phishing
RCS phishing is phishing delivered through Rich Communication Services, the messaging standard that adds images, logos, buttons and read receipts to text messages.
Read definition ChannelQuishing
Quishing (QR code phishing) is a phishing attack that hides a malicious link inside a QR code.
Read definition ChannelWhatsApp phishing
WhatsApp phishing is a social engineering attack sent through WhatsApp messages.
Read definition ChannelCalendar phishing
Calendar phishing is an attack that uses a fake meeting invitation to deliver a malicious link, file or phone number.
Read definition DefencePhishing simulation
A phishing simulation is a controlled, authorised exercise in which an organisation sends realistic but harmless phishing messages to its own employees.
Read definition DefenceSecurity awareness training
Security awareness training is an ongoing programme that teaches employees to recognise and respond to security threats such as phishing, social engineering and unsafe data handling.
Read definition DefenceJust-in-time training
Just-in-time training is a short lesson delivered at the moment someone needs it, typically right after they make a risky choice such as clicking a simulated phishing link.
Read definition DefenceMicro-learning
Micro-learning is a training approach that delivers content in short, focused lessons, usually a few minutes long, each covering a single idea or behaviour.
Read definition DefencePolicy attestation
Policy attestation is an employee’s recorded confirmation that they have read, understood and agree to follow a specific version of an organisational policy, such as an acceptable use or information security policy.
Read definition DefenceHuman risk management
Human risk management is an approach to security that measures and reduces the risk created by people’s behaviour, such as clicking phishing links, mishandling data or skipping policies.
Read definitionEvery example here is simulated. Senders are generic and links use .example domains, so you can share any entry with colleagues as a quick lesson.
Questions buyers ask
Frequently asked questions.
What is the difference between phishing and social engineering?
Social engineering is the wider idea of manipulating people into unsafe actions. Phishing is one form of it, delivered through messages such as email, SMS or chat.
Are the examples in this glossary real attacks?
No. They are simulated examples written for teaching, with generic senders and .example links. They mirror common patterns without copying any real message.
Which phishing channels should organisations prepare for?
Email is still the most familiar, but lures also arrive by SMS and RCS, phone calls, WhatsApp, collaboration tools, QR codes and calendar invites. Preparing people across channels matters because attackers switch between them.
Let’s connect the dots
See the human risk.
Change what happens next.
Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.
Book a demo