Call NowFree Quote
Cybersecurity

Social Engineering Attacks: What Perth Businesses Need to Know

The majority of successful cyber attacks don't begin by breaking through a firewall - they begin by convincing a human to open a door. Social engineering exploits trust, urgency, and familiarity rather than technical vulnerabilities. It's the number one threat vector for Perth SMBs, and it's getting more sophisticated.

What is social engineering?

Social engineering is the practice of manipulating people into taking actions that benefit an attacker - usually providing credentials, making payments, or granting system access. Unlike purely technical attacks, social engineering targets human psychology: the instinct to be helpful, the fear of authority, the desire to avoid conflict, and the tendency to trust familiar brands or contexts.

Attackers increasingly use AI tools to personalise attacks at scale, improve language quality, and clone voices. What once required skill and effort can now be automated. Perth businesses that believe "our staff would spot a scam email" are often surprised during simulated phishing tests.

Common social engineering attack types

Phishing

Mass emails that impersonate a trusted brand - Microsoft, ATO, Australia Post, a bank - and direct recipients to a fake login page or malicious attachment. The attacker nets whoever clicks.

Red flags

  • Urgency or threats of account suspension
  • Generic greeting ('Dear Customer')
  • Slightly wrong sender domain (micros0ft.com)
  • Links that don't match the display text

Spear Phishing

A targeted phishing attack where the attacker researches the victim first. The email may reference your business name, a colleague, a recent invoice, or a project. Vastly more convincing than generic phishing.

Red flags

  • Unexpected email from a known contact asking for urgent action
  • Requests involving money transfer or credential entry
  • Slightly different email address from a real contact

Business Email Compromise (BEC)

The attacker either compromises a real email account or spoofs one convincingly, then intercepts or redirects payments. A supplier's email gets compromised; the attacker changes the bank account on invoices. Perth businesses lose hundreds of thousands to this annually.

Red flags

  • Changed bank account details on a known supplier's invoice
  • Unusual payment requests from internal accounts
  • Pressure to pay quickly or outside normal process

Vishing (Voice Phishing)

Phone-based social engineering. The caller claims to be Microsoft support, the ATO, your bank, or a colleague with an IT issue. The goal is to extract credentials, remote access, or payment authorisation over the phone.

Red flags

  • Unsolicited call claiming your computer has a virus
  • Caller asking for remote access or passwords
  • Unexpected calls claiming to be from the ATO requesting immediate payment

Pretexting

The attacker constructs a convincing false identity or scenario - a new supplier, a new staff member from head office, a contractor - to gain trust and extract information or access over time.

Red flags

  • Requests for system access or sensitive data from unfamiliar contacts
  • Someone who 'can't verify through normal channels'

Why Perth businesses are targeted

SMBs are attractive targets precisely because they lack the security resources of larger organisations. A 20-person firm in Perth is unlikely to have a dedicated security team, unlikely to have phishing simulation training in place, and likely to have more informal approval processes for payments and access changes. Attackers know this.

Perth's heavy resources sector also creates specific risks - BEC attacks targeting subcontractor invoicing, pretexting attacks that exploit the transient nature of project-based relationships, and voice phishing targeting FIFO-related payment processes.

Defending against social engineering

Multi-factor authentication (MFA)

If a user's credentials are stolen via phishing, MFA is often the difference between a credential compromise and an account takeover. Even if an attacker has the password, they can't log in without the second factor. MFA should be mandatory on all accounts - especially email, financial systems, and remote access.

Payment verification procedures

BEC attacks succeed because businesses don't have a robust out-of-band verification step for payment changes. Establish a rule: any new or changed bank account details must be verified by phone (using a number already on record - not a number from the email) before payment is made. No exceptions.

Staff security training

Annual security awareness training and periodic simulated phishing exercises are the most effective countermeasures for social engineering. Staff who have been shown what a convincing phishing email looks like, and who have an easy way to report suspicious messages, catch attacks that technology would miss.

Simulated phishing exercises and staff training are the single most effective defence against social engineering.

Security Awareness Training →

Email authentication (DMARC, DKIM, SPF)

Properly configured email authentication makes it significantly harder for attackers to impersonate your domain when targeting your suppliers or customers. It also helps email providers identify and filter inbound spoofed emails. If your domain's DMARC record is not set to "reject" or "quarantine", anyone can send emails that appear to come from your domain.

Technical controls as backstops

Modern email security tools use AI to detect anomalous patterns - unusual sender behaviour, links to newly registered domains, content that matches known phishing templates. These aren't a substitute for staff training but add a meaningful catch layer.

What to do if your business is targeted

If a staff member suspects they have responded to a social engineering attack - clicked a link, entered credentials, or authorised a payment - act immediately:

  1. Change the compromised password immediately and revoke all active sessions
  2. If a payment was made, contact your bank immediately - there may be a narrow window to reverse it
  3. Notify your IT provider to investigate for any malware installed or further compromise
  4. Review what data the compromised account had access to and what may have been exfiltrated
  5. Consider whether the incident triggers your Privacy Act notification obligations

Frequently Asked Questions

What's the difference between phishing and spear phishing?

Regular phishing is a mass, generic email sent to as many people as possible hoping someone clicks, while spear phishing is targeted at a specific person using details the attacker has researched beforehand, like your business name, a colleague, or a real project. Spear phishing is far more convincing because it doesn't look like the generic scam emails staff are trained to spot.

How does Business Email Compromise actually cause financial loss?

An attacker either compromises a real email account or spoofs one convincingly, then uses it to change bank account details on what looks like a legitimate supplier invoice. Without a proper verification step, the payment gets sent straight to the attacker's account instead of the real supplier's, and it's often not noticed until the real supplier chases the missing payment.

What should we do if someone actually clicks a phishing link or gives up their password?

Act immediately, change the compromised password and revoke all active sessions on that account straight away. If a payment was involved, contact your bank as soon as possible since there's sometimes a narrow window to reverse a transfer, and notify your IT provider so they can check for any further compromise.

Is technology alone enough to stop social engineering attacks?

Not on its own. Email security tools that flag anomalous sender behaviour or suspicious links are a useful backstop, but social engineering specifically targets human judgement rather than technical weaknesses, so staff training and a clear payment verification process tend to catch what the technology misses.

Security training and phishing simulation for Perth businesses

We help Perth businesses run staff security training and simulated phishing exercises - and fix the technical gaps that let attacks through. Book a free assessment to see where your business stands.

For related reading, see our guides to Cybersecurity Checklist for Perth Small Businesses and EDR vs Antivirus: What Perth Businesses Need to Know.

Share this article