Recognizing and Resisting Social Engineering

Important Reminder: VIU will never ask for your password, your 2-Step Verification code, or to approve a login request you did not start.

What Is Social Engineering?

Most cyber attacks target software bugs. Social engineering is different. It targets people.

It is the practice of tricking people into sharing private information, giving access to systems, or sending money.

Attackers know that people want to be helpful. They know people respect leaders and act fast in emergencies. Instead of guessing a password, a scammer tells a convincing lie. They persuade you to hand over access willingly.

Four Common Emotional Triggers Scammers Use

Scammers target your emotions to make you act without thinking. Watch for these four common tricks:

  1. Authority: Impersonating deans, directors or managers. The scammer counts on you wanting to follow orders without asking questions.
  2. Urgency and Fear: Threatening that you will lose account access, drop classes, or face a fine. The scammer rushes you so you cannot stop to think.
  3. Helpfulness: Posing as a colleague or student in trouble. The scammer asks for quick help while they are "stuck in a meeting."
  4. Familiarity: Using real campus names, terms and events to sound like a trusted insider.

Common Social Engineering Tactics on Campus

Scammers use several methods to trick students, staff and faculty:

1. Fake Stories (Pretexting)

An attacker creates a fake scenario to build trust:

  • The "Urgent Favor" Scam: A fake dean or manager emails asking you to buy gift cards for an event.
  • The IT Impersonator: A caller claims your account is locked or broken. They demand your password or login code to "fix" it.
  • Banking Changes: A fake vendor asks to update their direct deposit banking details for an overdue bill.
  • Tuition and Loan Scams: Scammers offer fake tuition discounts or pose as family members offering to pay fees. Learn more in our guide on Tuition Payment Scams: What Students Need to Know.

2. Physical Tricks and Tailgating

Social engineering also happens in person:

  • Tailgating: A stranger follows you through a locked door without tapping their card. They rely on you being polite.
  • Shoulder Surfing: Looking over your shoulder in the library or cafeteria to see your password or student records.
  • Lost USB Drives (Baiting): Leaving an infected USB drive in a hallway or parking lot. The attacker hopes someone plugs it into a VIU computer.

3. Fake QR Codes (Quishing)

Scammers paste fake QR code stickers on parking meters, posters, or cafeteria tables. Scanning the code sends your phone to a fake login page that steals your password.

Watch: Real-World Social Engineering in Action

Watch these short videos to see how easily scammers manipulate people:

Watch a CNN Reporter Get Hacked (YouTube Video)

Security expert Rachel Tobac shows how a hacker uses public info and a friendly phone call to take over accounts in minutes.

Jimmy Kimmel Live: What Is Your Password? (YouTube Video)

A funny street video showing how people give away their passwords during casual conversation.

How to Defend Yourself: The Three-Step Rule

Stay safe by following three simple steps: Pause, Verify and Report.

  • 1. PAUSE: Spot the pressure: urgency, fear, authority or secrecy.
  • 2. VERIFY: Check the request using Out-of-Band Verification.
  • 3. REPORT: Click Report in Outlook or alert the IT Service Desk.

1. Pause and Spot the Triggers

Stop and take a breath whenever a message:

  • Rushes you to act right away.
  • Asks you to keep a secret.
  • Asks you to buy gift cards or send money.
  • Asks you to bypass normal VIU payment or login rules.

2. Conduct Out-of-Band Verification

Out-of-band verification means checking a suspicious request using a second, trusted channel.

  • Never use the contact details in the message: Do not reply to the email. Do not click links in the message. Do not call the number in the email signature.
  • Use official contact sources: Look up the person in the official VIU directory. Call their known campus phone number, start a new chat in Microsoft Teams, or speak to them in person.
  • Always verify high-risk actions: Never send money, buy gift cards, share student records, or change direct deposit details without checking first.

3. Guard Your Logins and Devices

  • Deny unexpected login alerts: If you get a 2-Step Verification prompt you did not start, tap Deny right away.
  • Use strong passphrases: Pick four or more random words. They are easy to remember and hard for computers to guess.
  • Lock your screen: Press Windows key + L whenever you leave your desk. Do not hold secure doors open for strangers.

How to Report Suspicious Activity at VIU

Reporting scams helps protect the entire campus:

Suspicious Emails in Microsoft Outlook

  1. Select the message in Outlook (desktop, web or mobile).
  2. Click Report (or Report Message) on the toolbar.
  3. Select Phishing to send the email directly to the VIU Information Security team.

Suspicious Calls, Messages or In-Person Visits

If someone asks you for passwords, student data, or access:

What to Do If You Made a Mistake:
If you clicked a bad link or shared a password, do not panic. We are here to help, not to judge.

Change your password right away following the VIU Password Reset Guide. Then email infosec@viu.ca or Contact IT Services so we can secure your account.

Official Resources and Further Reading