Last reviewed: Next review due:
Why social engineering targets journalists
Journalists are an attractive target for social engineering for several reasons: they receive unsolicited documents from strangers (making phishing harder to distinguish from legitimate tips); their public profiles provide attackers with detailed research material; they often have access to high-value contacts (politicians, executives, officials); and they operate under deadline pressure, which reduces caution. Social engineering attacks on journalists have been used to expose sources, steal unpublished stories, and access email accounts.
Common attack patterns
An email apparently from your editor or a senior colleague asks you to click a link, provide credentials, or share source information urgently. The sender address looks legitimate but uses a spoofed domain or a lookalike.
An attacker impersonates a known source, using their name and contact details scraped from public information. They make an approach that seems in character but contains a malicious attachment or link.
A credible-looking tip arrives with an attached "document" — a PDF or Word file — that contains malware when opened. The tip references a real, credible story angle to lower your guard.
An attacker creates a fictional scenario (a "colleague" needing urgent access to your account, a "IT team" requiring your password for a system migration) to extract information or access.
The attacker convinces your mobile operator to transfer your number, gaining access to SMS 2FA codes for your most sensitive accounts.
Red flags
- An email that creates urgency — "act now", "you must respond within the hour" — is a manipulation tactic.
- A request that bypasses normal process — "don't tell anyone else about this."
- A sender address that looks right at a glance but is slightly wrong (guardian.co.uk vs guardian.co.uk.phishing.com).
- An attachment in an email from an unknown source, especially .docx, .pdf, .zip.
- A "source" who can only communicate via a single, new channel and refuses to verify their identity.
- An unexpected password reset or 2FA code sent to your phone — you did not request this.
Anti-social-engineering checklist
- For any unusual request from an editor or colleague: verify by calling a number I already have, not one in the email.
- I process documents received from unknown sources through Dangerzone before opening them.
- I do not click links in emails from sources I have not previously verified by another channel.
- I use TOTP or a hardware key for 2FA on my most critical accounts — not SMS.
- I do not store source names in my phone contacts in ways that reveal their identity or role.
- I have reported any suspected phishing or social engineering attempt to my editor and IT team.
Source protection tools
Review your source protection and verification workflow.
Source Protection ChecklistCommon mistakes
- Opening attachments from unknown sources on your primary device without sanitising them first.
- Trusting display name in an email rather than checking the full sender address.
- Responding to urgency — attackers use time pressure deliberately to bypass careful thinking.
- Using SMS 2FA on your primary email account — SIM-swap bypasses this.
- Storing source names with revealing labels in your phone contacts.
Related guides
Primary sources
Frequently asked questions
What is spear phishing and how is it different from regular phishing?
What is a SIM-swap attack and why should journalists care?
How do I verify that an unusual email from my editor is genuine?
Can my address book be used to target my sources?
Related guides
Primary sources
- Phishing Guidance— National Cyber Security Centre
- How to Avoid Phishing Attacks— Electronic Frontier Foundation
- Dangerzone — Safe Document Handling— Freedom of the Press Foundation
- Security Training for Journalists— Freedom of the Press Foundation
- Social Engineering: Awareness Guidance— National Cyber Security Centre
- Journalist Security Guide— Committee to Protect Journalists