Phishing and blagging are both social engineering techniques designed to steal a confidential or sensitive information and to potentially extort money. Would you recognise the signs if you were at the end of a blagging or phishing attempt?Â
This blog post explores the differences between blagging and phishing. What are the signs to look for and how to respond.Â
What is phishing?
Phishing is an attempt to trick you into revealing information like passwords, bank details or bank card numbers etc. This might be by getting you to click on a malicious link via email or via another form of messaging, like SMS. These messages claim to be from a trusted source, such as your bank or a government organisation.Â
The link takes you to an official-looking website where youâre asked to enter your details.
Once you enter your information, it can be used for fraudulent purposes, such as identity theft or unauthorised access to your accounts. Clicking the link can also download malware onto your computer.Â
Example phishing email:
Dear Valued Customer,
We have detected unusual activity on your account. Please click the link below to verify your account information and secure your account immediately:
Verify Your Account
Failure to do so within 24 hours will result in a temporary suspension of your account.
Thank you for your prompt attention to this matter.
Sincerely,
[Your Bank’s Name] Support Team
What is blagging?
Blagging is a kind of social engineering technique used by criminals to extort money from their victims. A message is sent via email, social media, or SMS that claims to be from a friend or family member asking for help. The aim is to pull on your heartstrings and request money from you.
These attacks are thoroughly researched beforehand, so they have enough information to make the message look realistic. Â
Example blagging email:
Hi [Your Name],
I’m in trouble and I need your help. I’m travelling, and I lost my wallet and phone. Can you please transfer ÂŁ500 to me as soon as possible? I’ll pay you back as soon as I get home.
Here’s the link to send the money: [Fake money transfer link]
Thank you so much, I really appreciate it.
[Fake Friend’s Name]
What are the key differences?Â
Phishing emails usually target a large number of recipients with the aim of tricking victims into revealing confidential information (eg. financial details) or downloading malware and are primarily technology enabled.
Blagging attacks are frequently targeted against specific individuals or organisations. An attacker pretends to be someone known to the target, or someone trustworthy, in order to obtain money, personal information or access to accounts etc. This type of attack is usually conversation-enabled.
Phishing vs blagging – what to look out forÂ
Phishing emails target a large number of recipients and may have generic greetings like “Dear Valued Customer,” whereas blagging scams focus on individuals, using their names for a more direct approach.
Avoid becoming the next victim of an online scam by looking out for these signs:Â
How to spot a phishing scam
- Spelling and grammar errors: Watch out for mistakes in the content, although the use of AI means many phishing emails are now in perfect English
- Unusual web address: Are there any obvious errors in the URL? Do you associate this web address with the sender?
- A generic greeting such as âDear Account Holderâ
- Unexpected message: Were you expecting a message from the organisation claiming to be the sender?
How to spot a blagging email
- Unusual tone of voice: Does the tone of voice fit the sender of the message? Are they using language they wouldnât usually?
- A message out of the blue: Is it usual for your friend or family member to contact you this way? Were you expecting their message?
- Suspicious code: Is there any suspicious code in the email?
- An urgent request: Are they in a rush for you to transfer the money? Do they create a sense of immediate need?
If in doubt, follow up with the sender using a different form of communication. You should never click on a link in an email unless you are sure itâs from a legitimate source, and never reveal your password to anyone.
Education is the best line of defence in an organisationâs security posture. Ensure your employees know how to spot a fake email with cyber security training.
Why blagging is a threat and how to protect your businessÂ
Blagging is a serious threat because it targets people, meaning it sidesteps your security stack. It can lead to financial loss, open the door to a wider security breach, damage your company reputation and lead to regulatory or legal exposure.
Because blagging targets people rather than technology, your organisation’s best defence is to have a culture of verification. Staff should be trained to put any request that feels urgent or unusual on hold and then confirm it through a known contact number NOT through any details supplied in the message.
Protect your organisation by implementing clear approval processes for any payments or changes to bank details, limit how much information is shared publicly about roles and suppliers, and back it up with multi-factor authentication and stringent access controls, so that one person’s mistake doesn’t hand over the keys to your systems.





