GCSE · Computer Science · Edexcel · Spec 1CP2
Social engineering
The easiest way into a secure system isn't breaking the code. It's persuading a person to open the door.
Social engineering · Spot the technique
What does the attacker want the victim to do?
Pick a situation, then choose the technique it shows. Before you choose, ask: what is the attacker trying to get the victim to do?
Still to sort
Blagging (0)
An invented story, kept going until the victim hands over data or money.
Where the line is: Blagging is a made-up scenario used to persuade someone, usually in conversation. Phishing is a fake message or website that tries to get you to click or type your details.
Phishing (0)
A fake email, message or website pretending to be someone you trust.
Where the line is: Phishing needs you to take the bait and click. With pharming, you typed the correct address yourself.
Pharming (0)
You type the correct web address and still end up on a bogus site.
Where the line is: Pharming works even when the victim did everything right — no suspicious link was clicked.
Shouldering (0)
Watching someone enter a password or PIN.
Where the line is: Shouldering is watching what someone types. Eavesdropping is listening to what people say.
Name generator attack (0)
A 'fun' quiz or name game that gets people to share personal details.
Where the line is: Unlike phishing, it doesn't pretend to be your bank or ask you to log in. People share the details themselves because it looks like harmless fun.
Tailgating (0)
An unauthorised person following an authorised person into secured premises.
Where the line is: Tailgating gets the attacker physically through a secure door. Shouldering gets them information by watching someone type.
Eavesdropping (0)
Being physically close enough to overhear a confidential conversation.
Where the line is: Eavesdropping is listening in on a conversation. The attacker doesn't have to say a word, which is what separates it from blagging.
Nine situations, seven techniques. Some of them look alike — the reasons show you exactly where the line falls.
Predict, then check
It looks like harmless fun. Think like the person who made it.
A quiz is going round: 'How well do your friends know you? 1. What's your favourite colour? 2. What's your mum's maiden name? 3. Which town were you born in?' What is its creator most likely collecting?
WHAT YOU'VE LEARNED
A quick recap of today's lesson.
Hacking people, not computers: how criminals trick someone into opening the door — and how to spot it.
What you need to know
- Social engineering means tricking or manipulating people into revealing confidential information or taking actions that compromise security.
- It targets human psychology — trust, curiosity, fear and helpfulness — rather than technical weaknesses, and relies on human error such as clicking a link or sharing a password.
- Criminals use it because tricking a person can be easier than hacking software: even strong security can be compromised if someone is tricked.
- Know the seven techniques by what the attacker does: blagging, phishing, pharming, shouldering, name generator attacks, tailgating and eavesdropping.
- To protect yourself: be cautious with emails, links and attachments; never share passwords; check unexpected contacts through official channels; cover your screen or keypad; keep personal details out of online quizzes; and don't rush when you're put under pressure.
The big picture
Social engineering is when cyber criminals trick or manipulate people into revealing confidential information or doing something that compromises security. Instead of attacking weaknesses in the technology, it targets human psychology — trust, curiosity, fear and helpfulness — and it succeeds through human error, like clicking a link or sharing a password. The main techniques are blagging, phishing, pharming, shouldering, name generator attacks, tailgating and eavesdropping. Working out what the attacker wants the victim to do is how you spot each one, and how you protect yourself.
Key points
Worked example
Problem
A receptionist gets a phone call from someone who says they are the company's new IT technician. The caller chats about the office for a few minutes, then says the computer system needs an urgent update and asks for the receptionist's login details. Identify the social engineering technique and justify your answer.
⚠ Watch out
Calling every online trick 'phishing'. If the victim typed the correct web address themselves and still ended up on a fake site, nothing was clicked — that's pharming.
Memory hook
PHishing hooks you with bait, so you click. PHarming moves the road: you typed the right address and still got diverted to a fake site.
Check yourself
A friend says, 'I'm safe from social engineering — I've got a really strong password.' What would you tell them, and why?
Flashcards
(13)What is social engineering?
Which human feelings does social engineering exploit?
Why can social engineering beat strong security?
Blagging (pretexting)
Phishing
Pharming
Shouldering
Name generator attack
Tailgating
Eavesdropping
Will a real bank ask for your password by email or phone?
Someone unexpected contacts you, claiming to be from a company. What should you do before sharing anything?
How can you avoid handing out security-question answers online?
Tap any card to flip it, or use Study as deck to go through them one at a time. In the full lesson these run as a spaced-repetition deck — you rate each card Hard, Good or Easy and the tricky ones keep coming back until they stick.
Learning with Lightbulb is opening soon
You can use this lesson now. Join the waitlist and we'll let you know when the full Lightbulb experience is ready.
Keep me postedMore Edexcel GCSE Computer Science topics
How this lesson was checked. This Edexcel GCSE Computer Science (specification 1CP2)lesson was published through Lightbulb Learning's human-designed editorial process — the educational standards, accuracy rules and publication checks it must pass were authored and approved by Philip Halpin. It passed subject-specific assessment, automated educational checks and technical publication verification before going live (publication checks completed 1 October 2026). Published pages are monitored, human spot-checking is ongoing across the lesson library, and anything found wrong is corrected or withdrawn. How our lessons are made and checked. Spotted a mistake? Email hello@lightbulblearning.co and we'll review it.