Social engineering manipulates people into revealing information or granting access. It targets human psychology, not technology. The attacker builds trust, creates urgency, and exploits the desire to be helpful. A phone call from someone claiming to be IT. An email from a fake executive asking for a wire transfer. A visitor with a clipboard who talks their way past reception. The techniques vary. The goal is the same: get the target to do something they should not.
Social engineering is effective because it bypasses technical controls. A firewall does not stop a help desk employee from resetting a password for someone who sounds legitimate. The 2020 Twitter hack used phone-based social engineering to convince employees to hand over credentials. The attackers then took over high-profile accounts and posted a Bitcoin scam. The FBI called it a coordinated social engineering attack. Defense starts with awareness, but awareness alone is not enough. Processes matter more. Verify identity through a separate channel. Require approval for sensitive actions. Limit what any single person can do. The goal is to make it harder for a convincing lie to succeed. Training helps, but a strong process catches what training misses.
Common social engineering techniques
- Phishing — email-based deception
- Vishing — voice call deception
- Pretexting — fabricated scenario
- Baiting — enticing offer, like a free USB drive
- Tailgating — following someone into a secure area
Social engineering exploits trust. The defense is verification, not suspicion.
Comments
No comments yet. Be the first to share a thought.
Leave a comment