Social engineering: phishing in all its forms, impersonation and deepfakes
This course teaches SY0-801, the Security+ exam that launches on or around 17 November 2026. If you are booked on SY0-701, which can be taken until 11 June 2027, use our SY0-701 course instead.
Listen to this lesson
Every episode of this course is also a podcast: listen on Spotify.
This episode is a study companion for CompTIA Security+ SY0-801 and is not produced by or endorsed by CompTIA.
Objective 2.5 asks you to analyse indicators of malicious activity, and in SY0-801 social engineering has moved into it. That move is the useful hint: you are expected to read a message, a call or a request and recognise the signs that it is an attack. This lesson takes the named techniques — phishing and its variants, smishing, vishing, quishing, impersonation and deepfakes — as the evidence each leaves and the control that defeats it.
Why this matters
The overwhelming majority of real intrusions begin with a person being persuaded to do something — not with an exploit, but with an email, a text, a code to scan or a phone call. The exam reflects that, and the terminology is the marks: the techniques are named precisely, the distinctions between them are small, and the question is usually "which technique is this?" given a two-sentence scenario.
The other half of the marks is the control. Social engineering attacks people, but the best answers are rarely "more training". They are processes that do not depend on anyone spotting the trick: call-backs, dual authorisation, phishing-resistant MFA.
The lesson
Phishing, spear phishing and whaling, and what changes as the target gets more senior
Phishing is sending a fraudulent message to get someone to reveal information, click a link, open a file or take an action. The channel is the vector (covered in 2.3); phishing is the technique. Its variants are defined by targeting:
- Phishing in the broad sense is untargeted — the same lure to thousands of recipients, relying on volume.
- Spear phishing is aimed at a specific person or small group, using details about them: their role, their manager's name, a project they are working on, a supplier they really use. Far higher success rate.
- Whaling is spear phishing aimed at senior executives.
What changes as the target gets more senior is not the technique but the stakes and the cover. Executives can approve payments and grant access on their own authority; they are busy and often read on a phone; they may be exempted from controls that apply to everyone else; and their assistants, who act in their name, are a route in too. Lures shift to match: legal notices, board matters, regulatory correspondence, confidential deals.
Indicators worth teaching: urgency; an unexpected request; a display name that does not match the sending address; a link whose destination differs from its text; a request to break a normal process or keep something secret; and any request for credentials or payment changes. Spelling mistakes are now a weak signal — generated text is fluent — and a poor thing to train people on. Lookalike domains (a letter swapped, a different ending) and copied branding are common supporting tricks.
Smishing, vishing, and the phone call that defeats an otherwise good control
Smishing is phishing by text message. It works disproportionately well because phones show truncated links, texts are read in seconds, and SMS borrows legitimacy from genuine bank and delivery alerts. Typical lures are a missed delivery, an unpaid toll or fine, or a bank fraud alert.
Vishing is phishing by voice call. It is the technique most likely to defeat controls that look strong on paper, because a live human can adapt to the victim's hesitation.
The scenario the exam likes: an organisation has deployed MFA. An attacker who already has a password calls the user, claims to be IT investigating suspicious activity, and asks them to read out the code they are about to receive — or to approve the prompt that is about to appear. The control did its job; the person was talked out of it. The credential attacks lesson covers this as MFA bypass.
Vishing also targets the help desk. A caller who knows an employee's name, manager and start date — all findable online — can often get a password reset or a new MFA device enrolled. The defence is an identity verification procedure for resets that does not rely on facts an attacker can look up: a call-back to the number on record, a manager's approval, or verification in person.
Quishing: the QR code that carries a link past the email filter
Quishing is phishing with a QR code. The message — usually an email, but also a letter, a poster or a sticker on a parking meter — carries a code instead of a link. It works for two reasons. An email filter that inspects links in text sees only an image. And the person scans it with a phone, which is often personal, outside corporate protection, and shows the destination address only briefly if at all.
Common lures: "re-register your MFA", "scan to view the shared document", "your payroll details need updating", "pay here".
Indicators: a QR code in an email asking you to sign in; a code arriving from outside the organisation for an internal process; a code that leads to a login page on a phone. Controls: email security that decodes and checks QR images; a simple rule that internal processes never ask staff to sign in through a QR code; phishing-resistant MFA, so that even a captured password and code cannot be replayed; and checking public QR codes for stickers placed over the original.
Impersonation and deepfaked voice or video, and the call-back that defeats both
Impersonation is claiming to be a specific person or role: the chief executive, a supplier's account manager, an auditor, an IT technician, a police officer. It works because people defer to authority and want to be helpful, and because most requests are checked against who appears to be asking rather than against a process.
A deepfake is synthetic audio or video that imitates a real person. A few minutes of public speech — an earnings call, a conference talk, a video post — is enough to clone a voice convincingly, and live video impersonation is now practical. A widely reported 2024 case involved a finance employee transferring tens of millions of dollars after a video call in which the other participants, including a senior executive, were synthetic.
Indicators are weaker than they used to be, but still worth knowing: a call from an unusual number or platform; reluctance to switch channel or call back; urgency combined with secrecy; a request that skips the normal approval path; and, on video, odd lighting, lip movement out of step with speech, or a refusal to do anything unscripted.
The control that survives both is process, not recognition. If a request moves money, changes bank details, grants access or releases data, it is verified through a separate channel the requester did not supply — a call-back to a number already on file, a message through the internal directory — and high-value actions need two people. A deepfake can imitate a voice; it cannot answer a call placed to the real person's phone.
Pretexting and business email compromise, and the clues a scenario question plants
Pretexting is inventing a scenario that gives the attacker a reason to be asking: "I'm from the audit team and need to confirm a few account details before Friday." SY0-801 no longer lists it by name, but it is the foundation every technique above is built on — the pretext is the story, the technique is how it is delivered.
Business email compromise (BEC) is the high-value case. An attacker gains access to a genuine business mailbox, or convincingly imitates one, and uses a real conversation to redirect a payment: a supplier's "new bank details", a chief executive's urgent transfer, a payroll change. There may be no malware and no link at all, which is why it defeats controls aimed at attachments. Signs: a change of payment details by email; a reply in a real thread from a slightly different address; mailbox rules created to hide replies; a sign-in to the mailbox from an unusual location. The control is out-of-band verification of every payment change, every time.
The clues a scenario question plants, and what they point to:
| Clue in the question | Technique |
|---|---|
| Same lure to the whole company | Phishing |
| Uses the target's role, project or manager | Spear phishing |
| Aimed at the chief financial officer or chief executive | Whaling |
| Text message with a link | Smishing |
| Phone call, often to the help desk | Vishing |
| QR code in an email or on a poster | Quishing |
| Claims to be a specific person or role | Impersonation |
| Synthetic voice or video of a real person | Deepfake |
| Payment details changed within a real email thread | BEC |
What to take into the exam
- Spear phishing is targeted; whaling targets executives; smishing is text; vishing is voice; quishing is a QR code.
- Quishing works because filters see an image and the scan happens on a phone.
- Vishing defeats MFA by talking the user out of it; help desk resets need verification that cannot be researched.
- Deepfakes defeat recognition, so the answer is process: call back on a known number and require two approvers.
- BEC may carry no malware or link; out-of-band verification of payment changes is the control.
Practise what you just read
1. An attacker who already has a user's password phones them claiming to be from IT and asks them to read out the code they are about to receive. What is this?
Select one
Show answer
C. Vishing is phishing by voice call, and it is the technique most likely to defeat a control that looks strong on paper, because a live human adapts to hesitation. The MFA did its job; the person was talked out of it, which is why phishing-resistant MFA matters.
2. Why does a QR code in an email so often get past an email security gateway?
Select one
Show answer
D. A filter that inspects links in text sees only a picture, and the scan happens on a phone that is often personal, outside corporate protection, and shows the destination only briefly. Decoding QR images at the gateway and a rule that internal processes never use QR sign-ins are the controls.
3. A finance employee joins a video call in which the chief executive, apparently live, orders an urgent transfer. Which control defeats a convincing deepfake here?
Select one
Show answer
A. Deepfakes defeat recognition, so the control that survives is process: verify through a separate channel the requester did not supply, such as a call to the number on file, and require two people for high-value actions. A synthetic voice cannot answer a call placed to the real person.
Hands-on labs
Part of the free CompTIA Security+ SY0-801 course — 47 lessons and 78 hands-on labs.
This is an independent study companion for CompTIA Security+ SY0-801 and is not produced by or endorsed by CompTIA.