Need urgent help?

Call our team on 0207 099 0740

Need urgent help?
0207 099 0740
Client Portal
Satellite picture of the Earth as seen from space

13 August 2024

4 minutes read time

Phishing vs blagging: What’s the difference? 

Author

As Chief Information Security Officer at CloudTech24, I lead security strategy, governance and operational delivery. I help our clients’ executive teams make informed decisions about cyber risk. My role involves understanding how a customer’s business actually works, where the real risks sit, and what it takes to reduce them in a way that lasts, using existing capabilities wherever possible.

My background spans hands-on technical delivery and board-level advisory to clients across fintech, financial services, legal and other regulated industries. I also own our ISO 27001 programme and the ISMS behind it. As AI moves into everyday business use, I also ensure that our usage of AI aligns to best practise through governance and policy, and advise leadership and customers on safe adoption, aligning toward emerging standards such as ISO 42001 and the EU AI Act.

Outside of work, I’m a proud dad to two brilliant daughters and a lifelong LEGO enthusiast – if we’ve had a video call, chances are you’ve seen a few of my builds in the background. I’m also a passionate gamer and PC builder, a hobby I picked up in the early 2000s with my dad, who first sparked my interest in computers. Fun fact: back in the day, I was Europe’s #1 ranked Battlefield 1942 player – proof that my competitive streak goes way back!

Read blogs in other categories

Phishing and blagging are both social engineering techniques designed to steal a confidential or sensitive information and to potentially extort money. Would you recognise the signs if you were at the end of a blagging or phishing attempt? 

This blog post explores the differences between blagging and phishing. What are the signs to look for and how to respond. 

What is phishing? 

Phishing is an attempt to trick you into revealing information like passwords, bank details or bank card numbers etc. This might be by getting you to click on a malicious link via email or via another form of messaging, like SMS. These messages claim to be from a trusted source, such as your bank or a government organisation. 

The link takes you to an official-looking website where you’re asked to enter your details.
Once you enter your information, it can be used for fraudulent purposes, such as identity theft or unauthorised access to your accounts. Clicking the link can also download malware onto your computer. 


Example phishing email:

Dear Valued Customer,

We have detected unusual activity on your account. Please click the link below to verify your account information and secure your account immediately:

Verify Your Account

Failure to do so within 24 hours will result in a temporary suspension of your account.

Thank you for your prompt attention to this matter.

Sincerely,

[Your Bank’s Name] Support Team

What is blagging? 

Blagging is a kind of social engineering technique used by criminals to extort money from their victims. A message is sent via email, social media, or SMS that claims to be from a friend or family member asking for help. The aim is to pull on your heartstrings and request money from you.

These attacks are thoroughly researched beforehand, so they have enough information to make the message look realistic.  


Example blagging email: 

Hi [Your Name],

I’m in trouble and I need your help. I’m travelling, and I lost my wallet and phone. Can you please transfer ÂŁ500 to me as soon as possible? I’ll pay you back as soon as I get home.

Here’s the link to send the money: [Fake money transfer link]

Thank you so much, I really appreciate it.

[Fake Friend’s Name]

What are the key differences? 

Phishing emails usually target a large number of recipients with the aim of tricking victims into revealing confidential information (eg. financial details) or downloading malware and are primarily technology enabled.

Blagging attacks are frequently targeted against specific individuals or organisations. An attacker pretends to be someone known to the target, or someone trustworthy, in order to obtain money, personal information or access to accounts etc. This type of attack is usually conversation-enabled.

Phishing vs blagging – what to look out for 

Phishing emails target a large number of recipients and may have generic greetings like “Dear Valued Customer,” whereas blagging scams focus on individuals, using their names for a more direct approach.

Avoid becoming the next victim of an online scam by looking out for these signs: 

How to spot a phishing scam 

  • Spelling and grammar errors: Watch out for mistakes in the content, although the use of AI means many phishing emails are now in perfect English
  • Unusual web address: Are there any obvious errors in the URL? Do you associate this web address with the sender?   
  • A generic greeting such as ‘Dear Account Holder’ 
  • Unexpected message: Were you expecting a message from the organisation claiming to be the sender? 

How to spot a blagging email 

  • Unusual tone of voice: Does the tone of voice fit the sender of the message? Are they using language they wouldn’t usually?
  • A message out of the blue: Is it usual for your friend or family member to contact you this way? Were you expecting their message? 
  • Suspicious code: Is there any suspicious code in the email? 
  • An urgent request: Are they in a rush for you to transfer the money? Do they create a sense of immediate need?

If in doubt, follow up with the sender using a different form of communication. You should never click on a link in an email unless you are sure it’s from a legitimate source, and never reveal your password to anyone. 

Education is the best line of defence in an organisation’s security posture. Ensure your employees know how to spot a fake email with cyber security training.  

Why blagging is a threat and how to protect your business 

Blagging is a serious threat because it targets people, meaning it sidesteps your security stack. It can lead to financial loss, open the door to a wider security breach, damage your company reputation and lead to regulatory or legal exposure.

Because blagging targets people rather than technology, your organisation’s best defence is to have a culture of verification. Staff should be trained to put any request that feels urgent or unusual on hold and then confirm it through a known contact number NOT through any details supplied in the message.

Protect your organisation by implementing clear approval processes for any payments or changes to bank details, limit how much information is shared publicly about roles and suppliers, and back it up with multi-factor authentication and stringent access controls, so that one person’s mistake doesn’t hand over the keys to your systems.

Back to blog

Recent blogs from CT24

view of earth from space which shows some areas with lights on as it is night time

The steep rise in ‘ClickFix’ style phishing attacks  

What is ClickFix? ClickFix is a social engineering technique that the Security Operations team at CloudTech24 are seeing cybercriminals use to trick users into infecting their own devices. Typically, we find that a user is redirected to a fake verification page that impersonates a trusted service such as Cloudflare, Google reCAPTCHA, or a website security…

Read more

What is a virtual CISO (vCISO)?

Cybersecurity issues don’t pop up one at a time. They’re often frequent, urgent, and complex. When issues build up and the level of complexity increases to the point where your team needs an extra hand, having a vCISO can lighten the load. A vCISO (Virtual Chief Information Security Officer) is a security leader who serves…

Read more

Which one is better – AWS, Azure, or Google Cloud?

Choosing the right cloud infrastructure is a decision you can’t take lightly. Today, businesses must decide whether to build their applications on AWS, Azure, or Google Cloud. While these platforms offer similar core features like storage and computing power, each vendor approaches infrastructure, security, and developer experience with a completely different philosophy. This blog breaks…

Read more