Feature image credited to: Security National Bank – Everything Matters
Cyber criminals are no longer relying on complex technical exploits alone, increasingly, we’re seeing them targeting people. These “social engineering” attacks are specially designed to exploit trust, urgency, and human behaviour, and are proving to be one of the most effective ways to breach organisations.
For Managed Service Providers (MSPs) like us, we’re witnessing how this shift presents a clear challenge to our clients’ businesses. Much to our frustration, even the strongest technical security stack can be undermined by a member of staff falling for a single convincing message.
We’ve seen this first-hand. Gift card scams targeting new starters or busy employees with access to company funds remain a particularly persistent and costly issue. They’re often simple, fast attacks that are surprisingly effective in their success for the perpetrator, and leave the staff member red-faced and the business with very little they can do after the event of an attack.
The rise of impersonation and urgency
Gift card scams typically begin with an email or text message that appears to come from a senior colleague. These tricks are also known as a “boss scam” because the message will often be a director or CEO with a brief and urgent message like: “I need you to purchase £XXX in gift cards for the upcoming office party — can you do this quickly for me now?” The attacker may even follow up to maintain pressure. What they’re looking for is the voucher card PIN number(s) for them to redeem the money without there being any money trail to identify the scammer.
UK Finance reports that authorised push payment (APP) scams like this, driven largely by social engineering, resulted in over £485 million lost in 2022.
Astounding figures like this highlight a blunt reality — attackers do not need to hack systems if they can persuade people!
SIM jacking — when your phone becomes the weak link
SIM jacking (or SIM swapping) takes this further. Attackers convince a mobile provider to transfer a victim’s phone number to a new SIM card under their control. Once successful, they can intercept calls and SMS messages, including multi-factor authentication (MFA) codes.
The UK’s National Cyber Security Centre (NCSC) warns about SIM card fraud as a direct lead to account takeovers, financial theft, and access to corporate systems where MFA relies on SMS.
This is particularly concerning for businesses that still depend on SMS-based verification for critical services.
Social media — a reconnaissance goldmine
Social media platforms provide attackers with everything they need to make scams believable. Job changes, team structures, out-of-office posts, and even writing style can be harvested to craft highly convincing messages.
Remarkably, a 2025 Verizon Data Breach Investigations Report (DBIR) found that the human element was consistently involved in over 70% of breaches.
In practice, this means attackers are researching your business before they contact you — and they are getting better at it.
Practical steps to reduce risk
While these threats are evolving, they are not unavoidable. There are clear, proven ways to reduce exposure:
Any financial request, especially involving gift cards or transfers, should be verified through a second channel (e.g. phone call).
Avoid giving new or junior staff immediate, unrestricted access to company funds.
Where possible, adopt app-based or hardware authentication methods.
Employees should understand how these scams work and feel confident challenging unusual requests.
Phishing simulations can help reinforce learning in a controlled environment.
Be mindful of what is shared publicly on social platforms.
A human problem needs a human approach
Technology alone will not solve social engineering. The most effective defence combines strong systems with informed, confident people. That is why ongoing education — not just one-off training — is critical.
From our experience supporting clients, the organisations that fare best are those that recognise their staff as their first line of cybersecurity defence and build a culture where it is acceptable to pause, question, and verify. That small moment of hesitation is often the difference between stopping a scam and becoming a statistic.
If you are unsure how exposed your organisation might be, or whether your current controls are sufficient, it may be worth reviewing both your technical setup and your people-focused defences together.






