Skip to content
atlas

Don't confuse these

Phishing vs Pretexting

Phishing

People, culture & awareness

Fake emails or messages sent in bulk to trick people into handing over information or clicking something harmful.

Formal

A form of social engineering in which messages pretending to come from a trusted sender are sent to many people, aiming to capture a password or other credential, or to get the reader to open a harmful file or link.

In plain English

Like casting a net with bait into the sea - the sender does not care which fish bites, only that some do.

In practice

Hundreds of employees in a region receive a mail “from MitID” saying their login is about to expire; a few follow the link to a copy of the login page and type in their details.

Why it matters

It is cheap to send and needs only one person to fall for it, which makes it one of the most common first steps in an attack.

Pretexting

People, culture & awareness

Inventing a believable cover story and role, such as a new colleague or an auditor, to get someone to share information.

Formal

A form of social engineering built around a made-up situation and identity, usually prepared with research about the target; the story gives the victim a reason to help, so the request feels normal rather than suspicious.

In plain English

Like an actor who turns up in a delivery uniform with a clipboard - nobody asks questions, because the costume and the story fit.

In practice

Someone calls the payroll office of a municipality, says she is from the auditors, names the finance manager and asks for a list of staff salaries “for this year's audit”.

Why it matters

A good story beats most of the warning signs people are taught to look for, so staff need clear permission to check who is asking before they help.

Shared connections

Atlas is in beta.