Cybersecurity
Scams use the same shortcuts
Social engineering sits on this site because it is not a separate skill. Every scam below works by making you act inside a frame someone else built, which is exactly what a viral falsehood does.
The shared structure
Nearly every social engineering attack combines four things: a plausible identity, a reason to act now, a channel the attacker controls, and a request that feels like the obvious next step.
Misinformation uses three of the four. The identity is an outlet or an account that looks real. The urgency is share before they take it down. The channel is the post itself, which supplies its own framing and no route out.
Which is why one move covers both. Leave. Reach the source through a path you chose: type the address, open the app you already have, call the number on the card rather than the number in the message. Everything the attacker built depends on you staying inside their frame.
Phishing, smishing and the lookalike domain
The classic is a message from a service you use, warning of a problem and offering a link. The domain is close but not right: an extra word, a hyphen, a different ending, sometimes a character from another alphabet that renders identically.
Do not audit the domain and then click anyway. Reading a URL carefully is a skill with a real error rate, and it is unnecessary: you do not need to judge the link if you never use it. Open your banking app. Type the address yourself. If the warning was real, the same message is waiting inside your account.
The one-time code is the whole attack
A caller says they are from your bank's fraud team. They know your recent transactions. They ask you to read back the code that just arrived by text.
Hang up. The code is the one thing they do not have, and reading it back is the entire attack. Knowing your transactions proves a breach happened somewhere, not that the caller is your bank. No legitimate institution will ever ask you to read a one-time code to them.
This is worth committing to memory as a flat rule rather than a judgement call, because the moment it happens you will be flustered, and flustered is the condition it was designed for.
Pretexting, authority and the manufactured emergency
Pretexting is the invented situation that makes the request reasonable: IT needs to verify your login before a migration, a supplier has changed bank details, a manager is in a meeting and needs a payment released now.
Authority and urgency do the work together. Authority makes questioning feel rude, urgency makes it feel expensive. Both are cheap to fake and neither is evidence of anything.
The organisational counter is a rule that removes the judgement: any change to payment details is confirmed on a known number, never on the details in the message. A rule survives being flustered. Vigilance does not.
Disaster and charity fraud
After a local emergency, appeals circulate within hours, often with a real photograph taken somewhere else entirely. These target generosity rather than gullibility, which is part of why they work on people who consider themselves careful.
Nothing is lost by giving through an address you found yourself rather than the link you were handed. If the organisation is real, your donation reaches it either way. That asymmetry is what makes this an easy rule to follow.
Account takeover is a misinformation problem too
A compromised account with a real history and real followers is worth far more to a disinformation operation than a new one, because it arrives with borrowed trust. This is where the two subjects stop being neighbours and become the same subject.
It also means an out-of-character post from someone you know is worth a second look rather than a share, and that securing your own account is a contribution to the information environment and not only to your own safety. Turn on two-factor authentication, prefer an authenticator app to text messages where offered, and use a password manager so one breach is not every breach.