✳ Field lesson SE1 / 9 min

Phishing and social engineering: human attack vectors (not a green check, not an Atlas seal)

Name phishing and social engineering as a human attack vector: pretext, urgency, lookalike, MFA fatigue, and help-desk recovery abuse. A technical pass, an MFA approval, and a finished training course are separate from rightful-human intent. Not legal advice, and not an Atlas seal. Not required for beginners.

foundationsphishingsocial-engineeringelective

What you’ll be able to do

  • Name phishing and social engineering as a human attack vector, and list at least three of the five beats: pretext, urgency, lookalike, MFA fatigue (prompt bombing), and help-desk recovery abuse.
  • Refuse three collapses: a green email-auth pass is not a message that is safe to act on; an MFA prompt approval is not proof the rightful human was at the phone; finished awareness training is not an Atlas seal.
  • Transfer one Riverstone habit into F4, S1, E1a, or the finance payment-change exercise without a compliance checklist or a do-it-yourself phishing kit.

A human attack vector, with two thin limits

Not legal advice. Atlas does not issue an awareness-training certificate, a phishing-proof badge, or any seal that a workforce is safe from human attack. Completing this elective does not mean certified, compliant, or protected. This page is practice for Riverstone, FleetLink, and Quayside Mail. It is not a ruling for a real employer.

Phishing, in the Atlas glossary, is social engineering that tricks a person into revealing authenticators or approving a transaction they did not intend. The channel can be email, text, a collaboration tool, a phone call, or a help-desk recovery flow. It is a human attack vector. E1a is the DNS and mailbox lesson (what SPF, DKIM, and DMARC check). F4 is the identity lesson (authentication, authorization, and recovery). This elective assumes F4 and does not replace either page.

CISA, NSA, FBI, and MS-ISAC describe phishing as social engineering that lures a person, often by email, toward login credentials or a malicious site (Phishing Guidance: Stopping the Attack Cycle at Phase One, publication date October 2023). Atlas keeps the same human-vector idea and also counts an unintended approval: a push prompt, or a payment change. The worked examples stay inside the synthetic cast. Do not paste a real mailbox, a real brand kit, or a live credential-harvest page into this exercise.

Five beats on a Riverstone phone

Maya keeps five names for the pressure in a message. A message can use more than one. Naming the beat is the literacy. It is not a score, and it is not a campaign to run against employees.

Five beats of a human attack. Synthetic Riverstone hooks only.
BeatLiteracyRiverstone hook
PretextA believable reason to act: an IT ticket, a vendor invoice, a boss who cannot wait.A FleetLink notice that says IT needs an approval, or a supplier thread that asks finance to change an account.
UrgencyTime pressure that skips the verification habit.A payment cutoff, or a prompt that says approve now or the account locks.
LookalikeA familiar name, domain, or thread is not authorization by itself.A Quayside Mail thread that looks like the supplier. This page does not paste a real brand as a decoy.
MFA fatigue (prompt bombing)Repeated push prompts until someone taps Allow out of annoyance or habit.F4's nephew tapping Allow, and S1's two-second approval. CISA names this MFA fatigue, also called push bombing (October 2022 number-matching fact sheet).
Help-desk recovery abuseSomeone persuades a recovery channel to mint a new authenticator.F4's recovery job. This page does not give a call script for a real help desk.

The log records an approval event

A lookalike FleetLink prompt reaches a Riverstone phone. The pretext is IT. The urgency is a lockout if nobody taps Allow. Kim's nephew likes the button, or Kim is tired of a burst of prompts. Someone taps Allow. Later Maya opens the identity log and sees an MFA-approved login on Kim's account.

The log shows an approval event. It does not show that the rightful human intended the login. F4 already separated the account from the person at the phone. S1 keeps hypothesis (1) alive on purpose: a stolen account with a tired or social-engineered MFA approval. A family member on the same phone is S1 hypothesis (3), and that story can produce the same approval line. Maya writes the event. She does not write the person's intent.

The second habit is shorter, and it is the finance one. Sam Ortiz gets a Quayside Mail thread that continues a real supplier conversation and asks for a new settlement account before the cutoff. Invoice numbers can be real. The verification channel is the telephone number already on file, the one finance last reviewed, not the number printed in the message. That is the verify-payment-changes exercise. A DMARC pass on quayside.example would still leave the new account unapproved.

Help-desk recovery stays at the same altitude. An attacker who cannot win the push may ask recovery to mint a temporary authenticator. F4 already named that door. Priya's habit is the out-of-band check, a time limit on the temporary authenticator, and a record of who approved the reset. This lesson does not script that call.

Five phrases, five corrections

These are literacy corrections. They are not a compliance checklist, and they are not a dashboard. CISA's October 2022 fact sheets are the MFA pins: Implementing Number Matching in MFA Applications defines MFA fatigue (push bombing), and Implementing Phishing-Resistant MFA says some MFA forms remain vulnerable to phishing and to push bombing, while phishing-resistant MFA is a stronger class. Read those fact sheets, and the live SP 800-63-4 explainer, for the authenticator class. This page does not open a FIDO, WebAuthn, or passkey lesson.

Phrases that sound finished, and the correction. Not a compliance checklist.
Phrase people sayLiteracy correction
SPF, DKIM, or DMARC passed, so the message is safe to act on.A technical pass speaks for domain authorization and alignment (E1a). It does not prove the request is legitimate to pay, reset, or approve.
The MFA prompt was approved, so the rightful human was at the phone.Approval is an authenticator event. F4 already taught that a nephew tapping Allow can look like a successful login. S1 keeps human attribution uncertain.
We finished security awareness training, so we are phishing-proof, or Atlas sealed us.Atlas does not issue awareness seals. Training done is not transfer into the F4, S1, E1a, or finance habits.
There were no typos, so it cannot be phishing.The phishing term guide already names the pitfall: polished language and familiar branding are not legitimacy.
Push MFA means we are phishing-resistant.CISA: some MFA forms remain phishable. Push bombing (MFA fatigue) is a named threat. Phishing-resistant MFA is a stronger class. Name only. No passkey page on Atlas in this lesson.

Transfer the habit

F4: proving the account is separate from the human who held the phone. Carry the nephew Allow forward as an authentication weakness that still looks like a successful login.

S1: when the alert says MFA-approved, keep the tired or social-engineered approval hypothesis open until a channel that is not the prompt supports a stronger claim.

E1a: a DMARC pass on quayside.example speaks for authorized use of that Author Domain. It does not make the request safe to pay, reset, or approve.

Finance, verify a changed payment destination: call the contact already on file. The number inside the message is part of the message.

This elective is not a do-it-yourself phishing campaign against real brands. It is not a paste-your-mailbox lab. It is not a click-rate or open-rate dashboard, and it does not invent a training-efficacy figure. It does not rewrite E1a, F4, or S1. It is not a SOC playbook. It is not a compliance awareness checklist as the core. It is not permission to host a credential-harvest page for training inside Atlas.

Exit sentence: we treat phishing and social engineering as a human attack vector (pretext, urgency, lookalike, MFA fatigue, recovery abuse), and we still separate a technical pass, an authenticator approval, and rightful-human intent.

CHECK YOUR JUDGMENT

Quayside Mail shows a DMARC pass on a supplier thread that asks Sam Ortiz to change a settlement account before the cutoff. The same afternoon, Kim's FleetLink phone shows a burst of IT approval prompts, and one of them is tapped Allow. A teammate says awareness training finished last quarter, so both events are safe. What does Maya record?

Put your learning to work ↗

Find your next idea.

Tip: press / to open search. Escape closes this window.