by Jon Lober | NOC Technology
As cybersecurity technology advances, hackers are forced to rework their methods. Security services, software, and hardware have become more complex and effective, and fewer cybercriminals have the patience to sort through software code and hardware specifications to identify possible vulnerabilities and entry points.
However, this does not mean that there are fewer hackers, quite the opposite in fact. They have simply reoriented their attacks towards a far softer target in our digital defenses—humans.
Now, instead of slipping through virtual cracks, hackers aim to bypass human suspicion. Hackers do not need to weave past digital defenses to install malware if someone within the target network will simply click the download link for them—or even better, make a sizeable deposit directly to their account!
Such attacks rely on methods known as social engineering. In this approach, a cybercriminal leverages human susceptibility instead of technological vulnerabilities. Hackers abuse authority, trust, and persuasion instead of malicious code and software to con their victims into compliance.
In today’s digital environment, such scammers use a wide diversity of ploys—ranging from painfully obvious pleas to insidious and nearly undetectable PaaS schemes.
In this post, we will review three of the most common social engineering techniques and the hallmarks that can alert you to an attempted attack.
The most common and venerable of social engineering techniques, everyone you know has likely been the target of a phishing scam.
Although phishing can use many possible vectors, each one attempts to trick victims into revealing their login credentials or private information through misleading communication. Most of this happens through email, though smishing (through SMS text), and vishing (through voice message or phone call), and social media methods are all on the rise as well.
Classic phishing usually takes the form of a misleading email that plays on the victim’s confidence. Clever scammers will even strategically time their attacks with the seasons to make the ploy more believable. Summer vacation season and Christmas phishing scams are perennial favorites.
The most sophisticated versions of these scams rely on phishing-as-a-service (PaaS) groups to outfit them with a full suite of tools that can facilitate targeted attacks on individuals or businesses.
A number of options exist to protect yourself against phishing. A great first step is to use an advanced threat prevention system for your email inbox, such as Spam Titan, that quarantines suspicious emails before they even reach your inbox. In addition to these third-party options, Microsoft Outlook and Gmail also offer advanced protections to flag or quarantine suspicious emails before you open them unaware. Anytime you see such an alert, exercise extreme caution before you proceed.
In addition to these technological options, consider ongoing cybersecurity awareness training. A quality training regimen will keep your employee abreast of new, developing, and widespread schemes on a continual basis. Over time, employees will become aware of the red flags associated with such attacks, and how to detect them through methods such as:
In this targeted social engineering scheme, scammers impersonate business executives to manipulate employees into compliance.
As the most costly form of social engineering, the FBI reported that business email compromise (BEC) attacks resulted in total losses of $2.7 billion in 2022 alone.
As the total amount suggests, BEC attacks can be devastating. Fraudsters usually achieve their goals by manipulating or diverting a one-time or recurring wire transfer, which can be difficult to recover. These transfers are usually hijacked through communications with a compromised email account, or one that spoofs a legitimate account.
Common BEC schemes often:
In addition to the above recommendation, we have published an eBook that addresses business email compromise in greater detail. You can get your free download of Email Fraud: How to keep hackers from hijacking your inbox on our website.
Sometimes the quickest path to your data is not through the internet, but on foot.
Though less common than digital means, physical methods of stealing data and credentials can be equally effective. Even if an organization has excellent firewalls, email monitoring, and endpoint protection, a well-prepared physical intruder can wreak havoc on your network.
Actual physical tactics vary widely. Though they might seem too obvious, this does not prevent them from being effective.
Intruders can piggyback through a locked door, holding the door for someone with credentials. Shoulder surfers patrol airports and cafes, watching or recording people as they log into their accounts. Determined hackers will not hesitate to dumpster dive in the waste of a careless business.
Although USB drives are slowly being replaced by the cloud and other touchless sharing methods, they can still represent a legitimate threat to any organization.
Hackers can simply drop infected USBs in a parking lot, bank lobby, office building or other public area and wait for a curious individual to check it out—unintentionally downloading malware onto their computer in the process. Some scammers go as far as to leave flash drives with tempting labels like “salary information” or “private” in conspicuous places.
Though simple, USB-based attacks are effective. US power plants and Iranian nuclear facilities have both fallen prey to infected flash drives.
Although there are many ways to protect your business from physical infiltration, here are a few simple steps that you can take right away that can dramatically improve your odds.
Contact us
Existing Customers
IT Support Near Me
IT Support based in Franklin County, MO | 1816 Hwy A, Washington, MO 63090