Phishing and social engineering against traders
- Severity
- Moderate
- Status
- Published
- Affected area
- Social Engineering
- Published
- Last reviewed

Attackers are economically rational. Faced with a hardened system and a hurried human, they choose the human almost every time. Social engineering, phishing, pretexting, the well-timed phone call, remains the most reliable way into a trading operation precisely because it targets the layer no firewall covers. It does not exploit a bug in the software; it exploits a moment of trust, urgency, or distraction in a person.
§01Why traders are worth targeting
A trading desk is a concentrated target: a small number of people hold credentials that can move real money quickly. Attackers research them. A convincing lure references a real broker, a real counterparty, a plausible operational event, a margin call, a settlement query, an urgent request from someone senior. The more the message resembles the traffic a trader sees every day, the fewer defences it has to defeat.
§02Urgency is the tell
Almost every social-engineering attempt shares one ingredient: manufactured urgency. Act now, confirm immediately, the position is at risk, the deadline is minutes away. Urgency is the tool because it short-circuits the pause in which a person would otherwise notice the mismatched domain or the slightly wrong tone. The single most protective habit is cultural: legitimate operational processes can survive a two-minute verification, so a demand that cannot is itself the warning.
§03Design the human path to be safe
The durable defences are procedural, not just educational. Sensitive actions should require a phishing-resistant second factor that a fake page cannot replay. Any change to payout destinations should route through an out-of-band confirmation and a whitelist with a deliberate delay. Credential entry should live behind a password manager that simply will not autofill on a lookalike domain, turning a human judgement call into a silent, reliable machine check.
§04Blameless by design
The goal is not to make people infallible; it is to make a single human mistake survivable. A firm where clicking one bad link cannot, by itself, drain an account has designed its process correctly. Assume the click will eventually happen, and ensure the controls behind it hold. This advisory is educational and illustrative and is not security advice for any specific organisation.