“Social engineering is using manipulation, influence and deception to get a person, a trusted insider within an organisation, to comply with a request, and the request is usually to release information or to perform some sort of action item that benefits that attacker.”
Those are the words of Kevin Mitnick, former security consultant and convicted hacker. In a world where technology is deeply woven, and existential, for both personal and professional spheres, cybersecurity threats have become more complex and varied. Among the increasing array of cyber security threats, social engineering is a unique and particularly deceptive and effective one. Unlike more conventional, or prevalent, cyber attacks that exploit technical vulnerabilities, social engineering preys on human psychology, making it a uniquely challenging threat to counter.
What is social engineering?
Social engineering could be described as the practice of manipulating individuals into divulging confidential information or performing actions that compromise security, be that personal IT security or company IT security. Instead of breaking into systems using sophisticated hacking tools, social engineers target the human element, leveraging trust, fear, curiosity, or greed in order to achieve their goals. The aim is to deceive people into revealing sensitive data like passwords, transactions, financial details, or proprietary company information, or to lure them into actions such as clicking on malicious links or installing malware to compromise their IT security.
Different forms of social engineering attacks
Almost all of us have been subjected to a social engineering attack already, although we may not have known to describe it as such. Let’s take a look at what forms some of these attacks take.
Quid Pro Quo:
In a quid pro quo attack, the attacker offers something of value in exchange for information or access. For instance, an attacker might pose as a technical support representative and offer to fix a supposed issue in exchange for login credentials. The victim, believing they are receiving legitimate help, may unwittingly provide the requested information. Some of these individuals are highly skilled at what they do and even experienced IT users have been duped. So don’t think ‘that could never happen to me’!
Phishing:
Phishing is a very common type of social engineering attack, where attackers send fraudulent emails or messages that appear to be from legitimate sources, such as banks, online services, or trusted colleagues. These communications often create a sense of urgency, encouraging the recipient to click on a link, download an attachment, or provide personal information. Once the victim responds, the attacker can gain access to sensitive data or infiltrate systems. Phishing has a low success rate, so it is a high volume tactic, working off a low success rate, but it is still a very common tactic, which means it does pay off. In 2021 for example, in a survey by tech consultancy Proofpoint, 79% of US businesses were revealed to have been the victims of a successful phishing attack.
Spear Phishing
Spear phishing is a more targeted variant of phishing. The attacker customises the message to a specific individual or organisation, using details about the victim’s interests, job role, or recent activities to craft a believable narrative. For instance, a spear-phishing email might appear to come from a trusted business partner or a senior colleague, making it much harder for the recipient to detect the deception.
Pretexting
In pretexting, the attacker fabricates a scenario to obtain information or convince the victim to take a particular action. This could involve impersonating an authority figure, such as law enforcement, an IT support technician, or company executive, to gain the victim’s trust. The attacker may request details like login credentials or other sensitive information under the guise of a legitimate need.
The Methodology of social engineering
Social engineering attacks are successful because they tap into basic human psychological tendencies. Attackers often exploit the following triggers:
Authority:
People are generally more inclined to comply with requests from perceived authority figures. Attackers use this by impersonating someone in a position of power, such as a supervisor or law enforcement officer.
Urgency:
A sense of urgency compels victims to act quickly without thoroughly considering the situation. Phrases like “Act now or your account will be locked” are common in phishing emails, prompting recipients to make rushed decisions.
Fear:
Fear is a powerful motivator. Social engineers frequently use scare tactics, such as threats of legal action, potential embarrassment or financial loss, to manipulate victims into compliance.
Reciprocity:
The principle of reciprocity suggests that people feel obligated to return favours. Attackers might offer a free service or gift, expecting the victim to reciprocate by providing information or access.
Strategies against social engineering attacks
Despite the established effectiveness of social engineering attacks, all are preventable, and almost all of us have evaded an attack by not opening a particular email or replying to a suspect message. Some strategies to help defend against social engineering attacks include:
Education and Awareness
The first line of defence against any form of social engineering attack is education. Regular training should be conducted to inform employees about the different types of social engineering attacks, how to recognise them, and what actions to take if they suspect they are being targeted. Real-world examples and simulated attacks can be particularly effective in reinforcing these lessons.
Always verify
Never provide sensitive information or take action based on a request from an unknown or unverified source. If an email or phone call seems suspicious, verify the request by contacting the individual or organisation directly using known and trusted contact information. Avoid using contact details provided in the suspicious communication. The zero trust model of multi factor authentication must be employed.
Multi-Factor Authentication (MFA):
Multi-factor authentication adds an extra layer of security by requiring two or more forms of verification before granting access to an account. Even if an attacker obtains login credentials, MFA can prevent them from gaining access without the second factor.
Implement Strong Access Controls
Limit access to sensitive areas and information to only those who need it. This reduces the potential damage an attacker can cause if they succeed in tricking an employee into providing access.
Report Suspicious Activity
Encourage employees to report any suspicious activity or communication to the IT department or security team. Early detection can prevent an attack from escalating. Additionally, implementing monitoring systems that detect unusual patterns of behaviour can help identify and mitigate threats before they cause significant harm.
Update security
As social engineering tactics evolve, so should your organisation’s security protocols. Regularly updating and reviewing these protocols ensures they remain effective against the latest threats. This includes updating software, revising access controls, and reinforcing best practices for handling sensitive information.
Security Conscious Culture
Cultivate a culture where security is everyone’s responsibility. Encourage open communication about security practices and ensure that all employees understand their role in protecting the organisation. Regular security audits can help identify proactive approach to security. Audit your systems for potential vulnerabilities that could be exploited in a social engineering attack. These audits should assess both technical defences and human factors, such as employee awareness and adherence to security policies.
Social engineering attacks are among the most challenging cybersecurity threats to defend against because they exploit human nature rather than technical flaws. However, with a combination of education, vigilance, and robust security practices, individuals and organisations can significantly reduce their risk. As we’ve said previously, most of us have already experienced one of these attacks, so there is already a level of resilience that we need to build up on at an organisational level. What makes these tactics unique is the human factor. The most advanced security systems in the world can be undermined by a single successful social engineering attack, by targeting the right person. That’s why it is crucial to build a strong human firewall as your first line of defence against social engineering attacks.
