Ever received a phone call urgently asking you to confirm your bank account details or debit/credit card information to prevent your bank account from being closed or even an email or a message claiming you have won a lottery that you never even participated in?
What is social engineering?
Well, Social engineering is the term that is used to refer to a broad range of such malicious activities. It involves psychologically manipulating potential unsuspecting users/victims to reveal sensitive information such as bank account details, username and password, credit card information, etc. It is usually initiated through emails or messages and even calls that will likely invoke a sense of fear or panic, thus consequently causing the target individuals to swiftly hand over confidential data or click on a malicious link or even download a malicious file. As social engineering involves a human element, that is, it relies on human weakness rather than vulnerabilities in software and operating systems, prevention becomes much more difficult, due to which these attacks can often be tricky and dangerous.
Types of Social engineering attacks
While all social engineering attacks are accomplished through some form of human interactions, it can be achieved in different ways. Here are some of the most common types of social engineering attacks:
Phishing
Phishing is the most common type of social engineering attack. In this case, the attacker creates a fake website or support portal similar to that of a renowned company and sends the link to the targets via email or social media platforms. These attempts are usually made with an effort to instil fear and urgency and therefore, draw the targets in with an alarming subject line, such as, ‘Unusual account activity detected’, ‘Urgent Action Required, etc. Some gullible users become alarmed or curious and may click the links that are provided in the fraudulent mail, therefore, compromising sensitive information.
Spear Phishing
Spear phishing is another social engineering technique which can be assumed as a subset of Phishing. However, while mails are sent out to hundreds or even thousands of users in case of phishing, spear phishing is a more limited and defined version that targets specific individuals or organisations. Thus the attackers need to put in much more effort as there is a need to tailor the mail based on the characteristics and information they have gathered on their victims such as their names, addresses, job positions, etc. Although it is much harder to pull off, at the same time, the chances of users falling for the false emails are considerably higher.
Vishing
While most phishing attacks are carried out through mails, some prefer to use phone calls to carry out the work. This type of social engineering attack is known as vishing. In such cases, the attackers usually recreate the IVR (Interactive Voice Response) system of a company and attach it to a toll-free number in order to trick people into calling the phone number and entering their details.
Baiting
A the name suggests, baiting involves offering items or goods or something enticing to an end user, in exchange for sensitive data such as login credentials or other private data. One method used by attackers is to leave infected USB drives at public places with a hope of someone picking it up out of curiosity and using it on their devices thereby inadvertently infect their computers with malware. Another example of baiting found online is the various download links for free music or movies, mostly containing malicious software, hoping someone would click on them, handing their login information.
Quid Pro Quo
Similar to baiting, quid pro quo attack also promises a benefit in exchange for data. However, in this case, the attacker requests for critical data in exchange for a service, rather than goods as can be seen in cases of baiting. For example, the attacker may pose as a tech expert and offer free IT assistance through phone calls in exchange for login credentials.
Pretexting
Pretexting refers to when an attacker attempts to create a false sense of trust between themselves and the end user for the purpose of stealing the victim’s information. While most phishing attacks mainly use fear and urgency to their advantage, pretexting relies on building a false sense of trust with the victim by building a credible story that leaves little room for doubt on the part of their target. In this type of attack, the attacker may impersonate a
co-worker or a figure of authority well known to an end user in order to gain access to login information, for example, the attacker may send an email to an employee that appears to be from the head of IT Support. In actuality, they steal that data and use it to commit identity theft or stage secondary attacks.
Piggybacking
Piggybacking, also known as tailgating, is when an unauthorised person physically follows an employee into a restricted corporate area or system. One method of piggybacking is when the impersonator calls out to an employee to hold the door open for them as they have forgotten their key card, thereby gaining access to the building or the attackers may also strike up conversations with employees and use this show of familiarity as a way to get past the front desk. Another method involves the attacker asking an employee to borrow his or her laptop for a few minutes, during which the criminal is able to quickly install malicious software.
Leave a Reply