What is Social Engineering

Gareth Moore
10th May 2021

Social engineering is the art of exploiting human psychology, rather than technical hacking techniques, to gain access to buildings, systems or data.

Essentially, by appealing to an element of human psychology, (curiosity, incentive, fear of getting into trouble, desire to be helpful etc.) a malicious actor gains access to personal, private or business information, through what is termed “Social Engineering”.

“Social engineering is the term used for a broad range of malicious activities accomplished through human interactions. It uses psychological manipulation to trick users into making security mistakes or giving away sensitive information”

While social manipulation is not a new concept, new technologies have enabled cyber-criminals to create sophisticated digital tricks to perform this manipulation online. Cyber-criminals can gain access to all your digitally stored information, simply by convincing you to give it to them. This is sometimes known as ‘Human-Hacking’. Social Engineering relies on the basic tactics of trust, manipulation and deception. However, the increasingly sophisticated digital criminal has an arsenal of different tactics used in social engineering attacks such as: baiting, phishing, whaling and more. Most of these scams fall under the same theme: the pretence of being a legitimate person or resource. This blog post will show you what to look out for, why it is done and how your organisation can combat the threat.

 

Why do cyber-criminals use social engineering?

Over the past few years, social engineering has become a cyber criminal’s favourite method of attack. It has been proven to be the most successful way for a criminal to get “inside” an organisation. Cyber criminals are using increasingly sophisticated tactics for human hacking scams. A social engineer will find out everything they about an individual or a business. This could be through the means of social media or finding the target’s data online. Avoiding the perils of Social Engineers requires constant attention, education and awareness of the methods that these hackers use. A business email compromise could have a dramatic impact on your business.

 

The Different Types of Social Engineering Attacks

While Social Engineering often relies on a targeted and specific attack, these fall under a few common tactics. These are the types of social engineering attacks for all employees to be aware of:

 

Phishing

Phishing is perhaps the most well-known cyber crime, yet it is in fact becoming increasingly successful. Phishing is the use of email to get a target to enter their private information, or click a link exposing them to malware. 2018 Figures show that 30% of phishing emails were opened by their intended target and 12% of users proceeded to click on malicious attachments that allowed attackers the opportunity to breach an organisation. The effectiveness of this social engineering tactic relies in the criminal researching their targets that they wish to impersonate or attack.

The constant advancements of phishing are one of the many reasons why they’re still successful and will continue to be until everyone understands how to spot them. Three of the more sophisticated phishing attacks are listed below:

 

Spear-phishing: This type of social engineering threat targets a specific individual, such as a CEO or IT manager. They then use their information to personalise the email attack, adding to its legitimacy. More often than not victims think nothing of it and will give the criminal access to their data. As spear-phishers only target an individual they can spend their time conducting research on the victim, utilising their digital presence against them.

 Whaling: Unlike your traditional phishing, Whaling, is a much more targeted form of attack it has a more specific target. Whaling targets senior level employees such as executives and CEOs, pretty much anyone who has access to valuable data. By targeting the high-value member of an organisation, the hacker is likely to gain access to the entire company information, as well as the ability to impersonate the most legitimate members of the company.

 Voicemail phishing and SMS phishing: This is another type of phishing, however, the scam takes place over the phone. A scammer will call the target up on the phone pretending to be from their bank or even from a government agency. They will fish for information, with the aim of retrieving your personal information to steal money or data. Typical red-flags for phishing attacks, will be an email with a suspicious link, an email looking for bank or log-in information, an email from an ’employee’ who you are not aware of. Knowing the tell-tale signs and flagging suspicious emails as soon as possible will help reduce the immediate risk to the company.

 

Baiting

Take a look through your endless inbox of marketing emails and you’ll find a host of free stuff or ‘special offer’ discounts. While many of us are sceptical of just how ‘special’ these offers are, most employees can’t resist the temptation of freebies. Problem is – nothing is ever truly free. That’s exactly why we’re still seeing the old social engineering trick of ‘Free Software’ being wielded around, and employees still falling for it. The software being downloaded could actually be something that is out there for free. The risks, however, come with visiting the harmful website, which could result in a user downloading infected or compromised software.

Your employees can be even more at risk when visiting sites that are offering ‘bundling’ software, which means that they may have to download added software that they don’t even need, just to acquire the one they want.

Encourage your employees to check if your company has already licensed the software. If not, then visiting the software vendor’s website is a simple yet effective way of making sure that they are indeed offering this software, and that you’re downloading from a legitimate source.

 

Quid Pro Quo

Similar to baiting, the quid pro quo technique relies on an exchange, however, this also involves an element of false impersonation. One of the most common types of quid pro quo, involves a criminal impersonating an IT service employee. They will spam call as many direct numbers that belong to the company they are wanting to target. The attacker will offer IT assistance to every victim, once the victim agrees, they will be requested to disable their AV program. This is so the “IT assistant” now has administrative access to install whatever malicious software they choose.

As TripWire found “office workers are more than willing to give away their passwords for a cheap pen or even a bar of chocolate.” In this study, a staggering 90% of employees gave away their password for the promise of a cheap pen, demonstrating the clear need for greater cyber-security awareness!

Watering hole

This is a more unusual method of social engineering, which involves a legitimate or well-known website. The criminal will firstly pick out its targets such as employees of the business they want to attack. They then determine which websites these employees visit often, the ‘watering hole’ visited by the targeted employees.

The hacker will infect the ‘watering hole’ with malware. This code will redirect their chosen target to a separate website, where the malware is being hosted, the compromised website is now ready to infect the targets with malware upon their access.

 

Pretexting

Pretexting is perhaps the most blatant ‘confidence trick’ of Social Engineering. It is a form of impersonation which relies on the end user’s lack of ability to distinguish whether they are a legitimate source. This usually takes the form of over the phone impersonation, where a malicious actor may for example pretend to be a client who requires access to the end user’s private information.

Utilising a fake identity has become much easier for these malicious actors with the advent of more digital mediums of communication, it becomes harder to recognise a legitimate social profile, caller or email address. It is therefore always important to establish make sure you know who you are communicating with, before sending any sensitive information.

 

Tactics to help prevent social engineering attacks

If you are concerned about your company becoming the victim of a Social Engineering attack, don’t worry! There are many solutions you can use to build a comprehensive social engineering mitigation strategy.

 

Security Awareness Training

The most simple and most effective way to combat the threat of social engineering in your business is employee awareness. If employees are trained and aware of the types of social engineering scams discussed above, they are far less susceptible to falling for them.

Cyber-security awareness training for your team will dramatically reduce your company’s susceptibility to Social Engineering. By promoting a culture of awareness and training, your risk of manipulation and the consequences are dramatically reduced.

 

Regular phishing simulations

Phishing is the most successful and common type of cyber crime. It has been around for a very long time and still fools people everyday. Conducting regular phishing simulations in the workplace educates employees without the risk of losing valuable data. It allows you to see if there are any trends, and which employees are falling for the phishing attacks.

CyberPhish offers intelligently-automated security awareness trainingsimulated phishing and policy management to help you build a comprehensive strategy to mitigate social engineering in your business.