Skip to main content

Social Engineering & Phishing for UK Journalists

Technical security is only as strong as its human element. Social engineering — manipulating people rather than hacking systems — is often the most effective attack on journalists.

General guidance, not professional security advice. For high-risk threat models involving state actors or organised crime targeting, consult a qualified security professional or the Access Now Digital Security Helpline.

Last reviewed: Next review due:

Why social engineering targets journalists

Journalists are an attractive target for social engineering for several reasons: they receive unsolicited documents from strangers (making phishing harder to distinguish from legitimate tips); their public profiles provide attackers with detailed research material; they often have access to high-value contacts (politicians, executives, officials); and they operate under deadline pressure, which reduces caution. Social engineering attacks on journalists have been used to expose sources, steal unpublished stories, and access email accounts.

Common attack patterns

Fake editor / colleague email

An email apparently from your editor or a senior colleague asks you to click a link, provide credentials, or share source information urgently. The sender address looks legitimate but uses a spoofed domain or a lookalike.

Spoofed source contact

An attacker impersonates a known source, using their name and contact details scraped from public information. They make an approach that seems in character but contains a malicious attachment or link.

Fake story tip with malicious attachment

A credible-looking tip arrives with an attached "document" — a PDF or Word file — that contains malware when opened. The tip references a real, credible story angle to lower your guard.

Pretexting

An attacker creates a fictional scenario (a "colleague" needing urgent access to your account, a "IT team" requiring your password for a system migration) to extract information or access.

SIM-swap

The attacker convinces your mobile operator to transfer your number, gaining access to SMS 2FA codes for your most sensitive accounts.

Red flags

  • An email that creates urgency — "act now", "you must respond within the hour" — is a manipulation tactic.
  • A request that bypasses normal process — "don't tell anyone else about this."
  • A sender address that looks right at a glance but is slightly wrong (guardian.co.uk vs guardian.co.uk.phishing.com).
  • An attachment in an email from an unknown source, especially .docx, .pdf, .zip.
  • A "source" who can only communicate via a single, new channel and refuses to verify their identity.
  • An unexpected password reset or 2FA code sent to your phone — you did not request this.

Anti-social-engineering checklist

  • For any unusual request from an editor or colleague: verify by calling a number I already have, not one in the email.
  • I process documents received from unknown sources through Dangerzone before opening them.
  • I do not click links in emails from sources I have not previously verified by another channel.
  • I use TOTP or a hardware key for 2FA on my most critical accounts — not SMS.
  • I do not store source names in my phone contacts in ways that reveal their identity or role.
  • I have reported any suspected phishing or social engineering attempt to my editor and IT team.

Source protection tools

Review your source protection and verification workflow.

Source Protection Checklist

Common mistakes

  • Opening attachments from unknown sources on your primary device without sanitising them first.
  • Trusting display name in an email rather than checking the full sender address.
  • Responding to urgency — attackers use time pressure deliberately to bypass careful thinking.
  • Using SMS 2FA on your primary email account — SIM-swap bypasses this.
  • Storing source names with revealing labels in your phone contacts.

Related guides

Primary sources

Frequently asked questions

What is spear phishing and how is it different from regular phishing?
Regular phishing is mass-market: attackers send the same malicious email to millions of people. Spear phishing is targeted: the attacker researches their victim and crafts a convincing, personalised email. For journalists, a spear phishing email might appear to come from a colleague, editor, or known source, reference a real story you are working on, and contain a malicious link or attachment. Because it looks credible, it is much more dangerous than generic phishing.
What is a SIM-swap attack and why should journalists care?
A SIM-swap is when an attacker convinces your mobile operator to transfer your phone number to a SIM they control. They then receive your SMS messages — including 2FA codes. Journalists are sometimes targeted because their accounts (email, social media) are high-value. The attacker uses publicly available information (from your journalism, social media, or hacked databases) to impersonate you to your operator. Avoid SMS 2FA for your most critical accounts and use a TOTP app or hardware key instead.
How do I verify that an unusual email from my editor is genuine?
Call them on a number you already have — not one provided in the suspicious email. Alternatively, send a Slack message or use another out-of-band channel you know to be genuine. Do not click any links or attachments in the suspicious email before you verify. Look at the sender's full email address (not just the display name) — phishing emails often use slightly misspelled domains or free email providers spoofing a legitimate address.
Can my address book be used to target my sources?
Yes. If your device is compromised, your contacts can reveal who your sources are. Some attackers target journalists specifically to harvest their contact lists. Your phone contacts may include names that are revealing even without direct identifiers — 'source at [ministry]' is self-explanatory. Use Signal, which encrypts your contact list, and consider using contact names that do not reveal the source's identity or role.