Security Through Education: Recent Episodes

None

A free learning resource from Social-Engineer, LLC

View Details

Let me tell you about possibly my favorite onsite social engineering team engagement I have ever done! At this job, I was with 2 colleagues. We were tasked with gaining onsite access to a facility both during the day and at night. This story will focus on how we leveraged tribe mentality, which was vital to our success. So, before we start, what exactly is tribe mentality, and why is it important to social engineering?

Tribe MentalityTribe mentality can be defined as the tendency of people to seek out and connect with others who share similar interests, beliefs, or habits. Picture yourself walking into your high school cafeteria. What do you see? For me, I see kids sitting in groups. These groups are all defined by something unique. For example, I see the honor students, the band kids, the “cool” kids, the not so “cool” kids, and the artsy group. Of course, we could keep going with this but what is the point? These kids all flock together because they share either interests, beliefs, or habits. That interest may be something as surface as sharing a class, or something as deep as sharing the same religion. No matter what it is, they sit together because they feel comfortable. They, in essence, have formed a “tribe.”

Why is tribe mentality important in social engineering? Well, as a professional social engineer, when we write an email, make a call, or go onsite, we want to fit into their tribe as much as possible. This may mean using a similar email signature as those being tested, using the same language, or even dressing similarly.

Now, I am going to tell you the story. See if you can pick out the points where we used tribe mentality to our advantage.

The StoryWe begin the onsite engagement, like all others, with reconnaissance. This enabled us to plan our ingress and egress routes, map out the facility, and determine our path before we step onsite. Spying a fence that was open, we came back at night for some onsite recon and entered the property through it. Once we gained access, we found a lot devoid of people that contained work materials and work uniforms. Now, temporarily possessing certain items was within scope for this project, so we took one of the work uniforms. It just so happened to fit one of my colleagues perfectly! No doubt, you see where this is going…

The next night, we returned for the red team engagement. This is where we test the facility to see if we get caught trying to gain access to sensitive areas. We were able to gain access (let’s skip over the part where a vehicle drove 20 feet in front of us and employees almost spotted us…) and made it back to the previously discovered lot. There, one of my colleagues changed into the work uniform and proceeded to walk around the facility for nearly an hour. In this time, he was neither stopped nor questioned.

The next day, we wanted to see if we could test this angle even further. So, we snuck into the facility in broad daylight, let my colleague get dressed up and pretty, and scoped out the area for him. Using an earpiece, we directed him away from high traffic areas and let him walk around the site. He entered buildings, walked 10 feet in front of employees, and promptly exited the location about 30 minutes later. In all that time and sunshine, no one approached nor spoke to him!

The LessonThis story surely proves a point, but what is that point, and what can we learn from it? Well, it’s that none of us are immune to tribe mentality. The employees at this facility simply didn’t “see” my colleague, because he didn’t stand out. So, how can we combat this mentality? It starts with real-world and consistent training. Tests and trainings need to be as close to a real-world scenario as possible so that employees can “flex their muscles” in accurate and realistic situations. Next, this training must be consistent, just like working out, to see results. Importantly, this testing/training needs to be non-punitive. Punitive actions following testing do not support a learning culture and can create potential insider threats. Instead, focus on rewarding those that perform ideally. Finally, you need to narrow in and educate on how you want your employees to handle these scenarios where social engineering is leveraged. With these four steps you will be on your way to effective training!

This facility’s test really impressed upon me how even I, a professional social engineer, may still fall victim to its techniques. This means that all of us need to stay on top of our employees’ awareness of social engineering techniques, along with implementing the proper testing and training where appropriate. Together we can continue strengthening our human firewall.

Written by:
Shelby Dacko
Human Risk Analyst at Social-Engineer, LLC

View Details

As the clock ticks, we come to a new Cybersecurity Awareness Month (CAM)! This marks the 20th year of October being CAM. This year’s theme is “Secure Our World,” and how appropriate that is! With technology ever improving, we need to stay up to date on the best ways to stay safe online. This article will focus on you, and how you can “secure your world.”

The Cybersecurity & Infrastructure Security Agency (CISA) provided 4 ways to stay safe online. Let’s review them together!

Report PhishingAt Social-Engineer, LLC, we define phishing as “the practice of sending emails appearing to be from reputable sources with the goal of influencing or gaining personal information.” Astra states that “nearly 1.2% of all emails sent are malicious, which in numbers translated to 3.4 billion phishing emails daily.” Basically, this means that phishing emails are something that can affect all of us, if they haven’t already. So, how do we keep our families safe?

To start, we need to be cautious of unsolicited messages asking for personal information. CISA gives us 3 steps:

1. Recognize
Look for these common signs:

    • Urgent or emotionally appealing language, especially messages that claim dire consequences for not responding immediately.
    • Requests to send personal and financial information.
    • Untrusted shortened URLs.
    • Incorrect email addresses or links, like amazan.com.

They also share this important note: “A common sign used to be poor grammar or misspellings although in the era of artificial intelligence (AI) some emails will now have perfect grammar and spelling, so look out for the other signs.”

2. Resist and Report
Sometimes, our curiosity may try and get the better of us. Resist the urge to share sensitive information or credentials with unknown sources. Instead, report the phishing attempt via the “report spam” button!

3. Delete
Lastly, do not click on links from these unknown sources, unsubscribe, or reply. Instead, simply delete the message after reporting.

Use Strong PasswordsCISA says that a strong password follows all three of the following tips:

1. Make Them Long
At least 16 characters – longer is stronger!

2. Make Them Random
There are two suggestions on how to do this: Use a random string of mixed-case letters, numbers and symbols. The second option is to create a memorable phrase of 4-7 unrelated words.

3. Make Them Unique
Use a different strong password for each account. This can be made easier through the use of a password manager.

Turn on MFAMultifactor Authentication (MFA) is like a secondary defense for your accounts. It enables multiple points of verification to enter said account. For example, when trying to log in, a username and password may be required. When MFA is enabled, it would then require a code from an app on your phone in order to enter the site, or something similar. MFA can help ensure that it is really you who is logging in, when utilized properly.

It can sound overwhelming if you don’t know where to start, but CISA offers a step-by-step process to activating MFA:

1. Go To Settings
It may be called Account Settings, Settings & Privacy or similar.

2. Look for and turn on MFA
It may be called two-factor authentication, two-step authentication or similar.

3. Confirm
Select which MFA method to use from the options provided by each account or app. Examples are:

  • Receiving a numeric code by text or email.
  • Using an authenticator app: These phone apps generate a new code every 30 seconds. Use this code to complete logging in.
  • Biometrics: This uses facial recognition or fingerprints to confirm our identities.

Update SoftwareIt can be easy to click “remind me later” when a software update appears. However, updates are very important! They fix security risks and keep your information safe. Follow the following steps from CISA to keep your software up to date:

1. Watch for notifications
Our devices will usually notify us that we need to run updates. This includes our devices’ operating systems, programs and apps. It’s important to install ALL updates, especially for our web browsers and antivirus software.

2. Install updates as soon as possible
When notified about software updates, especially critical updates, we should be sure to install them as soon as possible.

3. Turn on automatic updates
With automatic updates, our devices will install updates without any input from us as soon as the update is available—Easy!

To turn on the automatic updates feature, look in the device’s settings, possibly under Software or Security. Search settings for “automatic updates” if needed.

Secure Our WorldWith the above tips, you can be sure that your world will be more secure than before. Remember to always report phishing messages, use strong passwords, turn on MFA, and update your software. Be sure to share these tips and this article with your loved ones so we can, together, secure our world.

Written by:
Shelby Dacko
Human Risk Analyst at Social-Engineer, LLC

View Details

October is Cybersecurity Awareness Month, a perfect time to brush up on ways to protect your digital life. One of the main topics emphasized during this month is Multi-Factor Authentication (MFA). You might have heard the term before, but what does it actually mean? And how can it help protect your personal information?

What is Multi-Factor Authentication (MFA)?Multi-Factor Authentication is a security measure that requires users to provide two or more verification factors to gain access to a resource—such as an application, online account, or VPN—rather than just a password. Think of it as adding an extra layer of protection. This way, even if someone manages to get hold of your password, they still have to pass additional security steps to access your account.

MFA operates on the principle of using different categories of information for verification, typically falling into three categories:

  1. Something you know (e.g., your password or a security question)
  2. Something you have (e.g., a smartphone, security token, or a smart card)
  3. Something you are (e.g., biometric verification like fingerprints, facial recognition, or voice recognition)

The idea is to mix these factors so that even if one is compromised (e.g., your password), the others remain a barrier to unauthorized access.

How MFA Adds Security to Your DataWithout MFA, a compromised password can spell disaster. But with MFA, even if a hacker guesses or steals your password, they will still need to complete another verification step. For instance, logging into your email might require you to enter a unique code sent to your phone. This extra step is often enough to stop cybercriminals in their tracks.

Think about locking the front door to your house. Using MFA is like locking not just the doorknob but also using a deadbolt with a different key. Even if someone gets past the first lock (your password), they have to face another lock (the second factor of authentication) before entering.

Common Forms of MFA1. SMS-Based Codes
After entering your password, you receive a one-time code via SMS that must be entered to gain access. This method is widely used but can be vulnerable if someone intercepts your messages. 2. Authentication Apps
Apps such as Google Authenticator, Microsoft Authenticator, or Authy generate time-sensitive codes for you to enter. These apps work offline, are not transmitted over the network as opposed to SMS. 3. Biometrics
Biometric data, such as fingerprint scans or facial recognition, adds an additional layer of physical security to the login process. Biometrics are especially useful because they are unique to the individual and difficult to duplicate. 4. Security Tokens or Hardware Keys
These are physical devices that you must insert into your computer or tap on your phone to authenticate your login. Some well-known examples are YubiKey and Google Titan Security Key.

Is MFA Foolproof?While MFA is a powerful tool, it’s not a silver bullet. Cybercriminals are always evolving their tactics, and some have found ways to bypass MFA using social engineering. A hacker might pose as a legitimate entity (like your bank or employer) and trick you into revealing your authentication code or clicking on a malicious link that captures it.

They may also employ a “MFA Fatigue Attack,” a social engineering tactic that involves bombarding a user with multiple multi-factor authentication requests. The aim of the attack being to overwhelm the user into approving the request and granting them access to the target’s account or device.

The Importance of Staying VigilantNo security measure, including MFA, is completely impenetrable. Hackers will always try to find weak points in human behavior, often trying to exploit the convenience and trust we place in everyday technology. Therefore, it’s crucial to remain vigilant. If you receive unexpected MFA prompts or messages asking for verification codes, take a moment to think critically. Don’t share your authentication details with anyone, and always verify the legitimacy of the request.

By understanding how MFA works and being cautious of social engineering attacks, you can significantly strengthen your defenses and stay one step ahead in the digital world. This Cybersecurity Awareness Month, take the time to ensure your accounts are protected with MFA—and remember, staying secure is not just about the tools you use, but how you use them!

Written by:
Josten Peña
Human Risk Analyst at Social-Engineer, LLC

View Details

An old adage says: if you don’t have anything nice to say, say nothing at all. As true as this is, it may not fully convey the power of silence. The Merrian-Webster Dictionary describes silence as “the absence of sound.” However, silence can be a powerful tool in communication, creating a space for others to express themselves freely. It is often used by human behavior experts, such as negotiators and social engineers, as a means to elicit information. The following are some ways in which silence can be used to improve your communication skills.

Build RapportMost people do not think that silence and rapport go hand in hand. One of the most powerful tools in rapport building is active listening. This involves giving full attention to the speaker and engaging with their thoughts and feelings. Of course, there’s more involved in active listening than keeping silent. Strategically using silence creates a non-verbal invitation for the other party to share more. Keeping silent allows the other person to fully expresses themselves. This encourages a deeper connection and understanding between individuals, helping to build trust.

Time to ThinkBeing silent also allows us time to think of the best response. Ethical social engineers involved in testing employees by vishing calls (voice phishing) will often be asked unexpected questions. A moment of silence can give the social engineer time to gather their thoughts and give a concise and realistic response. This results in more effective testing.

Compel Them to SpeakSilence can be a compelling force that prompts others to speak. This is because silence creates a subtle pressure to fill the void. When one person in a conversation pauses or refrains from responding, the other person may feel the need to continue to elaborate and break the tension silence creates. This technique is very effective in eliciting more information. It can also encourage someone to express thoughts they might otherwise withhold.

Balance is required when using silence as an elicitation technique. Though we want the other person to fully express themselves, waiting too long in silence can make the other person uncomfortable and even want to end the conversation. If we feel the silence is becoming uncomfortably prolonged, we can transition by asking an open-ended question or reiterating something they said. Sometimes a light-hearted remark or a genuine inquiry about the person can allow them to relax and engage in a more comfortable conversation. To delve deeper into effective elicitation strategies, join Chris Hadnagy at the Human Behavior Conference on October 30th.

Empower OthersSilence can be used to empower others. Instead of telling others what to do, It shows them you are interested in what they think. Silence can provide a space for others to express their thoughts and opinions which in turn can give you a better understanding of how to move forward with a project or what changes need to be implemented for their team to succeed.

Silence Has PowerWhether used to build rapport, create a moment of reflection, or compel others to speak, silence can deepen understanding and connection between individuals. It allows for pauses that encourage thoughtfulness and invite openness. Silence is far more than the absence of sound; it can be a strategic tool that improves communication. In a world inundated with noise, the deliberate use of silence can be one of the most powerful ways to communicate.

Written by:
Rosa Rowles
Human Risk Analyst at Social-Engineer, LLC

View Details

This year brings many advancements in the cyber realm. It also brings on an election year. While many opinions and stances exist, we should all be aware of the effect election years can have on our security. Rather than looking at the technical side of voter registration systems, IT infrastructure, or polling places, let us narrow in on the human side of security. I want to talk about how social engineering can be leveraged during this year specifically. Peering into this side enables us to focus on key strategies for organizations to safeguard against and educate employees about election-themed social engineering attacks. So, what should companies and employees be vigilant about?

Well, this topic is really an expansive one! Because of that, today we will look at how the election year can influence the creation/spread of misinformation, deepfakes, and social engineering attacks.

Misinformation, Disinformation, and DeepfakesMerriam-webster defines misinformation as incorrect or misleading information. Disinformation is the intentional spread of false information with a malicious intent. Certainly, we can agree that this type of information abounds today. This is partly due to the quick access we have to information as well as the ability to spread it. The spread of mis/disinformation continues to increase due to these and other factors. Mis/disinformation has certainly been seen surrounding elections in the past.

One form this information can take is deepfakes. Deepfakes are primarily fake videos or audio that appear to be legitimate. In 2023 there were elections in Slovakia, and they experienced this attack in a real way. An audio recording appeared on Facebook, “allegedly capturing a conversation between a candidate and a media representative discussing plans to manipulate the election, including buying votes.” The audio was quickly found to be a fake, yet the damage had already been done. This disinformation campaign quickly turned to misinformation, and swiftly affected people’s decisions.

This issue is not one that will be isolated or confined to other countries alone. It demonstrates how misinformation, disinformation, and deepfakes, can be a real threat. Because of this, employees should be educated to always verify sources, and especially during election seasons. Remember that not everything one sees or hears may be real, so do some verification before trusting it.

Social Engineering Attacks Leveraging Political ThemesIn the past we have seen many different social engineering attacks that leverage various political themes. Any time there is a large event, disaster, or holiday, the malicious actors come out to take advantage. Knowing this brings organizations and their employees one step closer to safety, as they know when to be extra cautious. Let us look to the past to see the what, and finally, we will give you the how.

Stay Secure: The What1. Voter Registration Attacks:
A common attack during election years are voter registration attacks. These involve an attacker emailing (phishing), calling (vishing), or texting (SMiShing) and sending you a link to a fake voter registration form. Those forms contain spaces for personally identifiable information, in the hopes you will fill it out and send it back. 2. Donation Attacks: Donation attacks can take many forms. In some instances, a fake audio message of a candidate may ask for a donation and instruct you to push a number on your phone, which would then direct you to a “representative.” Or you may receive a call from a real person, who is encouraging you to donate. You may also get an email with links to “donation sites.” 3. Fake Surveys, Petitions, and Polls: Surveys, petitions, and polls are common during the election season. Attackers may create fake ones in order to collect personally identifiable information. They may seek a contribution or offer a gift card or other incentive to encourage you to participate in the survey.

Stay Secure: The How With mis/disinformation, deepfakes, and social engineering attacks abounding, organizations must remain vigilant and educate their staff on how to stay safe. But what are some specific things your employees should be on the lookout for?? AARP gives the following tips:

Voter Registration Attacks* If someone claims you are not registered to vote and offers to register you by phone, hang up. You cannot register by phone, email, or text. In all 50 states, you can only register to vote online, by mail, or in person at a local election office. * “If you receive a suspicious call from someone trying to influence your vote, the best thing to do is just hang up,” notes a consumer alert from North Carolina Attorney General Josh Stein.

Donation Attacks* Be skeptical of unexpected calls from someone claiming to be a politician or a celebrity. In recent months, scammers have released deepfake videos of famous people such as Tom Hanks, Elon Musk, and Dolly Parton, for fraudulent product endorsements. * If you want to donate to candidates, go to their certified site. “Don’t answer any phone calls, don’t click on any links in an email or text, even if it’s from somebody you recognize or you might think is reputable,” Bruemmer says. “Someone could have taken over their account and started spamming you.” * Do not rely on Caller ID: Scammers can impersonate a political campaign phone number through a tactic known as spoofing.

Fake Surveys, Petitions, and Polls* A legitimate survey may ask how you plan to vote along with your political affiliation, and surveyors may request demographic information, such as age or race, notes Equifax’s ID Watchdog. But do not share more specific information. Age is one thing; your birth date is another. Decline to provide your name, address, email address, Social Security number, or driver’s license number. * If someone conducting a survey or poll offers a prize, do not participate. “Real political polls rarely offer prizes for participation, and none would ask for a credit card number,” ID Watchdog states.

For more tips, visit AARP’s article directly, here. Applying these tips will help you protect your organization and your staff from election-themed social engineering attacks.

Written by
Shelby Dacko
Human Risk Analyst
Social-Engineer, LLC

View Details

Online shopping has revolutionized the way we purchase goods, offering convenience and accessibility like never before. However, with these benefits come risks, primarily in the form of cybercriminals who exploit unsuspecting shoppers. Practicing good cyber hygiene is essential to ensure a safe online shopping experience. Here, we’ll discuss the best practices for safe online shopping and highlight examples of bad actors to avoid.

Understanding the ThreatsIn the realm of online shopping, cybercriminals employ a variety of strategies to compromise sensitive information:

  • Phishing Emails: Deceptive emails designed to mislead a person into revealing sensitive information.
  • SMiShing Texts: Similar to phishing but conducted via SMS, these messages may direct a person to malicious websites or prompt them to download malware.
  • Fake Websites: Often used in conjunction with the 2 previously mentioned attacks, bad actors may create a website that mimics legitimate retailers to steal money and personal data.

These threats are not just limited to the direct interactions mentioned above. Cybercriminals are continuously developing new tactics to infiltrate one’s security, such as using compromised ads on legitimate sites or directing them to fraudulent payment gateways.

Why They WorkThe success of online shopping scams is largely due to their exploitation of human psychology and trust. For example:

The Too-Good-To-Be-True Flash Sale: Scammers use this tactic to create a sense of urgency, pushing you to make impulsive decisions spurred by the fear of missing out (FOMO) on a great deal. They may claim to offer a high-end product at an extremely low price.

The Holiday Phishing Scam: These scams increase during festive periods when shoppers are more active online. Emails that appear to come from well-known delivery companies or online retailers ask for personal details or advance payments, playing on the trust shoppers have in these familiar entities.

The Gift Card Scam: An unsuspecting individual may receive a message claiming they have won a gift card. This may even happen while browsing on known retail sites, an advertisement may pop-up congratulating the individual on their “fortune”. Here, the promise of freebies is used to lure shoppers into providing personal information to “claim their gift” or making purchases on fraudulent sites.

These tactics are particularly effective because they mirror the look and feel of legitimate promotional activities, making them harder to distinguish from real offers.

Safe PracticesTo defend yourself while engaging in online shopping, adopt the following practices:

  • Verify Website URLs: Always check the URL or address of websites. Secure websites start with “https://” and often include a padlock icon in the address bar. However, this should not be the only indicator…always be skeptical of URLs that contain slight spelling errors or unusual domains, as these are common indicators of fraudulent sites. If you are still unsure, you can use online link checkers like urlscan.io or urlvoid.com. These sites can scan and verify the link for you to protect you from malicious and illegitimate websites.
  • Scrutinize Deals: If an offer seems too good to be true, it likely is. Verify such deals by visiting the retailer’s official website directly rather than clicking on a potentially dangerous link.
  • Monitor Your Accounts: Regularly review your bank and credit card statements for any unauthorized charges. Quick detection can limit damage and facilitate the resolution process.
  • Be Wary of Public Wi-Fi: Avoid making purchases or accessing sensitive accounts over public Wi-Fi networks. If necessary, use a VPN to secure your connection.
  • Strengthen Your Security: Utilize strong, unique passwords for each online account and enable multi-factor authentication (MFA). MFA will make it much more difficult for cybercriminals to gain access even if they manage to obtain your password. If possible, the use of a Passkey may provide an even stronger layer of security.
  • Lock Your Accounts: In the USA you can lock down all 3 credit bureaus by freezing your accounts for free. This is a good practice to stop any thieves from using your identity for purchases or opening new lines of credit.

ConclusionBy understanding the strategies employed by cybercriminals and adhering to best practices in online security, you can significantly reduce the risks associated with online shopping. Stay informed about the latest scam tactics, remain vigilant about your online activities, and prioritize your cybersecurity. With these measures in place, you can enjoy the benefits of online shopping without falling prey to pitfalls.

Written by
Josten Peña
Human Risk Analyst
Social-Engineer, LLC

View Details

Have you ever received a message like this? “Your account has been compromised,” “your package could not be delivered,” “you received a credit of $2,000 on your Paypal.” How did that make you feel? Anxious? Excited? Maybe even a bit panicked? These types of SMiShing attacks are designed to trigger your emotions and prompt an immediate reaction. I’ve often heard people say, “You must be a fool to fall for something like this.” However, emotional triggers in social engineering attacks exploit a wide range of emotions – such as fear, greed, sympathy, curiosity, and authority. These emotions can temporarily suspend critical thinking and lead to impulsive actions. Let’s consider some of the most common emotional triggers in social engineering attacks.

FearFear is one of the most powerful tools in social engineering. It’s often used to manipulate individuals into divulging confidential information or perform an action that they otherwise would not. By evoking fear, attackers create a sense of urgency and panic, compelling their targets to act quickly without considering the consequences. For example, phishing emails might threaten severe consequences such as account suspension or data breaches, prompting the recipient to click on malicious links or share sensitive information to avert the perceived threat.

GreedGreed is frequently leveraged in social engineering attacks to exploit individuals’ desires for financial gain or material benefits. Attackers craft schemes that promise significant rewards, such as receiving a large inheritance or benefiting from an exclusive investment opportunity. By appealing to the target’s greed, attackers create an allure that overrides caution and critical thinking. Victims are then lured into providing personal information, transferring money or downloading malicious software in the hope of obtaining the promised reward.

SympathyWhile sympathy is not an emotion, it leads to feeling pity or sorrow for another person. Sympathy is often used to gain trust and elicit cooperation from targets. Attackers create scenarios that evoke empathy and compassion. For instance, a fraudulent email might depict a heartbreaking story and ask for financial assistance or sensitive information. This exploitation of human kindness can lead individuals to act against their better judgment, revealing information or resources they would normally protect.

CuriosityCuriosity is another component used by attackers to lure individuals into actions that compromise security. By presenting intriguing content, such as an unexpected email with a vague but captivating subject line, a hidden link, or an attachment labeled as confidential or urgent, attackers pique the target’s interest. The natural human desire to uncover unknown information leads individuals to click on links, download files, or explore suspicious messages, without fully considering the risks.

AuthorityAuthority is often used in social engineering to compel individuals to comply with requests or commands without question. Attackers impersonate figures of authority such as executives, IT administrators, law enforcement officers or government officials, to exploit the inherent respect and obedience people tend to show toward those in positions of power. Invoking authority makes targets feel pressured to act promptly, wanting to demonstrate compliance. For example, an email from a supposed CEO demanding urgent financial transfers, or IT administrator requesting login credentials for security purposes.

Protect YourselfOne of the most effective social engineering tactics is to get you to react without thinking things through. Therefore, the most powerful weapon against social engineering attacks is critical thinking. Given the emotional nature of these attacks, there may not be a specific tool or process that can prevent us from falling victim to human vulnerability. Being aware of such vulnerability enables you to pause and think of the request. Ask yourself, is this request reasonable? Why are they asking this of me? Should I do this? At times, a social engineering attack can sound “reasonable.” Even if that’s the case, you should still allow yourself time to pause. Take a few minutes to let your emotions cool off before taking action. Austrian neurologist and holocaust survivor Victor Frankl once said, “Between stimulus and response, man has the freedom to choose.”

Remember that the goal of a social engineering attack is to use your emotions against you, to elicit a reaction based on your emotional state. As you pause and allow space between “stimulus and response,” you can empower yourself to choose wisely.

Would you like to learn more about the complexities of human behavior and the impact of emotions on our decisions? Dive deep into these intriguing topics with insights from top experts at the Human Behavior Conference! Click here to learn more and register today!

Written by Rosa Rowles
Human Risk Analyst

View Details

Here at Social-Engineer, LLC we define social engineering (SE) as “the act of influencing someone to take an action that may or may not be in their best interest.” If you Google search “social engineering” you will find a much more negative definition. We prefer this more broad and open definition because, like most things, we feel social engineering can be used for good OR bad. So, how can YOU use ethical social engineering as a force for good in the world and your personal life? Let’s look at some examples, discuss why it can be beneficial, and find out how to learn these techniques.

SE Techniques: The Building Blocks of CommunicationSocial engineering techniques can really be the building blocks of good, solid communication, when utilized properly. How so? Consider techniques such as ego suspension, validation, and asking open ended questions. Who of us don’t want to be validated non-judgmentally, asked genuine questions that allow us to express ourselves, and feel like the other person is allowing us to give our opinions? Surely if we all practiced implementing those techniques, conversations around the world would proceed much more smoothly.

Let’s take the base unit of society, families, and applying ego suspension. Arguably, ego suspension is one of the most difficult social engineering techniques to implement. This is because, as humans, we like to be right. So, suspending our egos and letting the other person be right can be very difficult. If executed properly, though, it enables the other person to express themselves fully, without us interrupting them or overshadowing their thoughts with our own opinions. This, in turn, is validating and can encourage them to keep talking to you, strengthening your relationship.

For example, imagine your spouse excitedly starts telling you about a new topic they’re learning about. This is a topic you know quite a bit about, so you’re excited too! Suspending your own ego would look like you not sharing your “greater knowledge”, but instead employing active listening while your partner is speaking. This is the same with your children. Picture your 5-year-old coming up to you and excitedly sharing a newly learned fact about a bug! You may have known this fact for a decade or more, however you responding “Really? Where did you learn that?” will encourage your kid to share more information rather than a response like “I know.” Surely your conversations will go more smoothly if you are able to suspend your ego properly. What a powerful technique!

Techniques such as those above have similar effects on all those around us when utilized effectively. They can positively impact our relationships with our parents, friends, colleagues, therapists, and acquaintances alike. Surely, social engineering, when used ethically, can be a force for good in our life.

HuBe Con: Where the Experts AreHow, though, do you learn these beneficial social engineering techniques? You can start with the Social Engineering Framework, developed by Christopher Hadnagy, in 2009. Reading about these techniques can certainly help you learn more about them and improve your skills.

Wouldn’t you agree, though, that the best way to learn is by hearing and seeing these techniques in action? By learning more about human behavior from the experts? We are happy to announce that now, you can! The Human Behavior (HuBe) conference is back! Join us on October 30th, 2024, for live training and workshops by the experts of persuasion, body language, and elicitation; Joe Navarro, Christopher Hadnagy, and Dr. Abbie. You will learn how to use nonverbals, how to influence decision making, how to use cognitive bias, and practical application for everyday life. This exclusive, hands-on training will enable you to take your skills to the next level. We look forward to seeing you there!

Register now to join us at HuBe here: https://humanbehaviorcon.com/register/the-human-behavior-conference/

Written by
Shelby Dacko
Team Coordinator and Human Risk Analyst

View Details

In the digital age, as our reliance on technology deepens, so does the creativity of malicious actors seeking to exploit vulnerabilities. One of the many growing threats to our security is SMiShing, a blend of SMS (Short Message Service) and phishing. SMiShing attacks utilize text messages to deceive individuals into divulging sensitive information or performing actions that compromise their security. As these attacks become more sophisticated, understanding their nature, vulnerabilities, and preventive measures, is paramount.

The Escalation of SMiShing AttacksSMiShing has emerged as a favored tactic among cybercriminals for several reasons:

  1. Pervasiveness of Mobile Devices: With the proliferation of smartphones, people are more accessible via text messages than ever before. This accessibility presents a lucrative opportunity for attackers to exploit. For example, most individuals have their phone on them while going about their day. So, a bad actor has an increased chance of reaching them at a time that their guard may be lowered. Perhaps the text message reaches the target while they are busy running errands or trying to enjoy a vacation. These scenarios could lead to decreased vigilance.
  2. Increased Chance of Interaction: A report by Gartner stated that 45-98 percent of individuals interact with their text messages. In comparison, only 6-20 percent interact with their emails. This data alone makes the attack vector of SMiShing very appealing to bad actors, as they may have a higher chance of compromising an individual.
  3. Low Barrier to Entry: Launching a SMiShing attack requires minimal resources and technical expertise. Therefore, it’s an attractive option for both amateur and seasoned hackers.

Vulnerabilities Exposed by SMiShingSMiShing exploits various vulnerabilities, including:

  1. Human Trust: Attackers may leverage social engineering techniques to manipulate human psychology, exploiting trust and inducing victims to take actions against their best interests.
  2. Inadequate Awareness: Many individuals lack awareness of SMiShing tactics, making them susceptible to falling victim to these attacks. Individuals may also underestimate the severity of such attacks in comparison to Vishing and Phishing, which may leave them in a vulnerable state if a SMiShing attack is executed effectively.
  3. Device Security: SMiShing often leads recipients to malicious websites or prompts them to download malware-infested applications, compromising the security of their devices.

Common SMiShing ScamsThere are a variety of SMiShing scams that may be used in the real world, either in a corporate environment or in our personal lives. It is imperative that we are up to date on the latest avenues that attackers may take to compromise our secure data. Here are a few:

  • Credential Theft: In a corporate setting, employees may receive texts impersonating IT departments, prompting them to reset passwords on fake login pages. A similar approach might be taken against individuals outside a company. American Express customers saw this tactic firsthand when bad actors sent out fraud alert text messages that looked very similar to ones they would normally get, evoking a sense of fear. The text included a link to a spoofed login page where a concerned customer would “login” to their account, compromising it in the process.
  • Individual Impersonation: Along with impersonating companies, attackers may impersonate specific individuals in relation to their targets. Such individuals could be coworkers, managers, and even friends or family. By impersonating someone the target knows, the bad actor may attempt to coerce their target into lending financial aid. Often bad actors will attempt to do this through social media or over third-party apps such as WhatsApp.
  • Package Delivery Scams: Fake delivery notifications are all too common today. Bad actors may trick recipients into providing personal information or clicking on malicious links. By sending these texts out to a wide group, they may reach an individual that is expecting a package. Similar to the American Express attack, a link is usually provided with this SMS messages, leading the victim to a spoofed login page for the delivery service.

Lessons Learned and Moving ForwardAs we navigate the evolving landscape of cyber threats in 2024 and beyond, several key lessons emerge:

  1. Education and Awareness: Continuous education on identifying and mitigating SMiShing attacks is crucial for individuals and organizations alike. Verifying a sender’s identity independently and avoiding clicking on links directly from messages are practices all should be familiar with.
  2. Vigilance and Skepticism: Adopting a skeptical mindset towards unsolicited messages and verifying the authenticity of requests can mitigate the risk of falling victim to SMiShing scams. Exercising this caution will aid an individual, especially if the nature of the SMiSh is one that attempts to override their critical thinking and evoke an emotional response.
  3. Technology Solutions: Implementing advanced security measures, such as mobile threat defense solutions and multi-factor authentication, can bolster defenses against SMiShing attacks.

Increase Your Employees’ Security AwarenessSMiShing poses a significant threat to both corporate entities and individuals, exploiting vulnerabilities in human psychology and technology. By understanding the nature of these attacks, implementing preventive measures, and fostering a culture of cybersecurity awareness, we can fortify our defenses against SMiShing and other emerging threats in the years to come.

At Social-Engineer LLC, we perform SMiShing simulations for our clients to help increase their employees’ security awareness. Our SMiShing program is highly customizable to fit the needs of your company and provides excellent datasets that help to establish areas of concern or promise among your staff.

Written by
Josten Peña
Human Risk Analyst

View Details

Would you hire an employee based solely on Intuition? Probably not. You would consider factors such as their education and previous work experience. But what if a candidate looks great on paper, answers all the right questions during the interview yet you have a gut feeling that they won’t be a good fit for your team? Would you ignore that feeling and still hire them? That’s where intuition comes in. What is intuition and can we trust it?

Intuition is a fascinating aspect of human cognition, often described as a gut feeling or sixth sense. Intuition involves more than just a feeling, it’s the result of an unconscious process that helps us make decisions. This seemingly mystical knowledge arises from a combination of past experiences, emotional inputs, and perceptual cues, which enable us to process information.

IntuitionThe National Library of Medicine describes intuition as “the ability to understand immediately without conscious reasoning and is sometimes explained as a ‘gut feeling’ about the rightness or wrongness of a person, place, situation…” This ability to know something without analytic reasoning is often perceived as imaginary and intangible. However, its technical term interoceptive sensations makes it quite tangible. The concept of interoception was first introduced by Nobel Prize winning scientist, Dr. Charles Sherrington. He defined interoception as “sensations from the interior of the body, especially the viscera.” During the past century, scientific advances have expanded the knowledge regarding interoceptive processing. A more recent definition of Interoception from The National Library of Medicine is the “process of how the nervous system senses, interprets, and integrates signals originating from within the body.” What role does this play in decision making?

Intuition and Decision MakingResearchers from the universities of Cambridge, Sussex and the Queensland University of Technology found in a study that financial traders’ ability to sense their own heartbeats was directly associated to their success in the financial markets. The study subjects consisted of 18 male financial traders from a hedge fund that specialize in high frequency trading. This type of trading entails buying and selling future contracts in minutes, sometimes seconds. This requires processing large amounts of information from news sources, as well as swiftly recognizing price patterns, and making risky decisions in split seconds.

The researchers tested the traders to see how accurately they could count their own heartbeats, and if they could recognize subtle changes in their physiological state. They were compared against 48 University of Sussex students (the control group), who were also tasked with counting their own heartbeats. The researchers discovered that among the traders themselves, those who excelled at heart rate detection also excelled at trading and generated higher profits.

It’s Not All in Your HeadMany times, people perceive intuition as having a physical sensation like a flutter in the stomach, tightness in the chest, or chills. It’s not all in your head, the term ‘gut feeling’ is no coincidence as the gut has a direct connection with the brain through the gut-brain axis. Neurotransmitters (chemical messengers) in your gut communicate with your brain and are part of the gut-brain connection. Johnhopkinsmedicine.org had this to say about the gut-brain connection: “If you’ve ever gone with your gut to make a decision or felt butterflies in your stomach when nervous, you’re likely getting signals from an unexpected source: your second brain.”

Acknowledge Your EmotionsIn this digital age of analytical and rational thinking, intuition or gut feelings seem to have little value. Of course, big decisions require careful thought and rationality. However, your emotions are not useless responses that you should ignore. Emotions are, in part, produced by evaluations of what you’ve been thinking or experiencing. Intuition plays an important role in everyday life, from making quick judgements of people we meet, to how we feel about our surroundings and certain situations. Understanding how our intuition works and being in tune with our feelings can become a useful tool in our decision making.

Written by
Rosa Rowles
Human Risk Analyst

View Details

Throughout my years at Social-Engineer, LLC, I have had the pleasure of giving speeches for many different companies. This has enabled me to view cybersecurity through each of their lenses and learn from them. It has also enabled me to help aid in their educational development. Today, we will discuss what I learned and why these speaking engagements and discussions are so important. Along with helping your company strengthen its security posture, this will help all of us gear up for the coming Cybersecurity Awareness Month (CAM).

Awareness of InformationBeneficial security awareness seems to start with the awareness that you can always be more secure. In addition, it includes the awareness of the information that exists about your company online. Acknowledgement of the former benefits your companies and employees. This is because it acts as a motivator to continue increasing your security posture through training, testing, and standard reporting methods. The latter acts as your baseline. Knowing what online information is available about your company and employees online enables you to shift your perspective to how an attacker might utilize that information. This allows you to remove potentially sensitive details, such as vendors you work with, investors, and client names, from publicly available sources. It also enables you to remember how attackers may leverage the information available to them. As a result, you can now be on the guard against pretexts that utilize such information.

Sometimes, though, it can be difficult to shift from the marketing or advertising perspective into the attacker’s perspective, viewing information the way an attacker would. In my speech, Understanding Vishing from the Attackers Perspective, I spend time with clients viewing open-source intelligence (OSINT) on a selected target, and crafting an attack specifically for said target. This helps them to practice the attacker’s perspective. In other words, learning to view information the way the malicious actors do. Because of this, they can then design their personal or companies’ social media to reflect information that they are comfortable with these malicious actors having access to. Again, it all starts with the awareness of what information is available about themselves or their company on the open web.

Reporting MethodsHaving standard reporting methods is arguably one of the most important things you can do to keep your company secure.

Imagine the following scenario: Ted gets an email that seems legitimate. He decides to click on the link and log in to the familiar looking company portal with his credentials. After logging in, the page errors out. This feels off to him, so he decides to report this email and his actions to the IT department. Because of this, they can follow up on this threat, change Ted’s credentials, and warn all other employees of this attack. Imagine if Ted had not reported this email, nor even known how to report this email! This threat could have persisted, spreading across the company. This demonstrates how important it is for all employees to not only know when to report a phishing email, vishing call, or smishing attack, but to know the company’s method for reporting such threats.

In speeches given by Social-Engineer, LLC, we work with you to include your company’s reporting methods in our information. This familiarizes employees even further with your standard reporting practices. In the past, I have heard of employees seeing these reporting methods for the first time in my speech! How important it is to ensure that these methods are known and delineated to the proper places.

Positive Reinforcement ModelRecently, I was in a client meeting where a discussion came up regarding reinforcement models, and if positive or negative programs work better. At Social-Engineer, LLC, we strongly believe that positive reinforcement models are the only ones effective for your security programs. Our CEO, Christopher Hadnagy, had the following to say surrounding this:

“Any good parent knows that you are not going to get compliance from your child by humiliating them or speaking down to them. The same goes for our employees. But by using a positive reinforcement model, you create a culture of cybersecurity and foster a powerful team dynamic.”

As an example, imagine if Ted, from our story above, had been reprimanded every time he failed his phishing tests, rather than commended when he passed or reported these tests. Do you think he would have had the confidence to report the phishing email, especially when he had clicked? Likely not. This would only have succeeded in increasing risk for the company. This is one reason why we stress positive reinforcement models to all our clients and readers.

TestingOne thing I have observed across some of what I would consider the more “secure” companies, was that they all had required testing for their employees. This testing was not simply “watch this video” and check a box that you’re “trained.” No, the best testing is hands-on and simulates real phishing and vishing attacks. This is essential for employees to know how to respond to these attacks in real time. You can read and watch videos on vishing all day, for example, without really learning what a real attack may sound and feel like. The benefit of having the experience of shutting down a caller cannot be understated.

I have had the pleasure of firsthand seeing people react when they hear what a professional vishing call sounds like. They are generally surprised, and there is always some awkward laughing in the audience. Why are they surprised? Because these calls sound like normal conversations. It’s incredible to hear what information can be elicited when enough rapport is built!

In ConclusionIn preparation for CAM, be sure to keep the points we discussed today in mind. Knowing what information exists about not only yourself, but also your company, online is vital. Testing and standard reporting methods reinforce the training that you provide or go through. Don’t forget to keep a positive reinforcement model, as this really brings home all the work that you have put in.

Above all, work with employees and your company to prepare for the most productive CAM you can have. Our team can work with you to tailor speeches to your methods, to do OSINT on your company and employees, test employees, or educate on what methods attackers have recently been leveraging. Each of these options can aid in bringing you one step closer to a strong human firewall. Let’s work together to make this the most productive CAM yet!

Written by
Shelby Dacko
Human Risk Analyst
Social-Engineer, LLC

View Details

As the temperatures rise and summer approaches, so do the schemes of cybercriminals looking to exploit unsuspecting individuals. Whether you’re planning a vacation, gearing up for outdoor activities, or simply enjoying some downtime, it’s crucial to remain vigilant against the wide array of scams that tend to surge during this time of the year. In this article, we’ll uncover three of these common scams, shed some light on their deceptive tactics and discuss practical ways to safeguard ourselves.

Vacation Rental Scams:One prevalent scam during summer break involves fake vacation rentals advertised on popular platforms. These scams typically involve malicious actors creating convincing listings for vacation properties, complete with stolen photos and enticing descriptions. Unsuspecting vacationers may book these rentals, only to find upon arrival that the property either doesn’t exist or isn’t as advertised. The allure of discounted rates and picturesque accommodations often blinds individuals to the red flags. The urgency to secure a booking before the summer rush can also cloud judgment, making this scam particularly effective. Scams like these may be especially dangerous if the bad actor is attempting to lure an individual to an unsafe location. Extreme caution should be used when booking advertised vacation rentals, especially if it is not through accredited forums, hospitality industries, or travel agencies.

Phishing Emails Offering Summer Deals:Another tactic employed by cybercriminals during summer break is phishing emails promising irresistible summer deals. These emails may appear to come from legitimate travel agencies, airlines, or online retailers, offering exclusive discounts or promotions. The sense of urgency created by limited time offers can lure unsuspecting victims into being scammed. Without verifying the sender, they may miss the fact that it is not coming from the actual company, but rather a bad actor impersonating them. Clicking on any links or downloading attachments within these emails can lead to malware infections, identity theft, or financial loss. Scammers may even send these types of fraudulent offers through text message.

Fake Event Tickets and Excursions:Summer brings a plethora of events, concerts, and outdoor excursions, making it prime time for scammers to peddle counterfeit tickets or fraudulent tour packages. Whether it’s tickets to a popular music festival, a guided tour of a tourist destination, or passes to an amusement park, fraudsters capitalize on the excitement surrounding these events to dupe unsuspecting buyers. These scams often thrive on the secondary market that resell tickets, or through unverified online sellers, promising discounted tickets, or exclusive access. In the case of a targeted attack, scammers may send a phishing email to a specific target that they have researched, promoting tickets to an event they might enjoy. The eagerness to secure tickets for sought-after events or experiences can override skepticism, making consumers vulnerable to exploitation.

Protective Measures: Verify Listings and Sellers: Before booking a vacation rental or purchasing event tickets online, conduct thorough research. Verify the legitimacy of the rental property or ticket seller by checking reviews, contacting the owner or organizer directly, and confirming details through reputable sources. * Exercise Caution with Email Offers: Be wary of unsolicited emails offering summer deals or promotions. Avoid clicking on links or downloading attachments from unfamiliar senders. Instead, visit the official website of the purported sender directly to validate the offer. If an offer seems too good to be true, it probably isn’t. * Use Secure Payment Methods:* When making online purchases, use secure payment methods such as credit cards or reputable third-party payment services. Avoid wiring money or using unconventional payment methods that offer little recourse in the case of fraud.

ConclusionAs you embark on your summer adventures, remember to stay vigilant against the various scams lurking in the digital landscape. By familiarizing yourself with common tactics used by cybercriminals and implementing proactive security measures, you can safeguard yourself and your loved ones from falling victim to summer break scams. Remain cautious, stay informed, and enjoy a safe, scam-free summer season.

View Details

I take a sip of my coffee and put on my headset, I’m ready to start my workday. A large portion of my work consists of making vishing (voice phishing) calls, where we test our clients’ employees. I look at my pretext notes and take a deep breath as I get into character to play the alias for that particular client. As I dial the number, I hear the familiar hold music. This time however, I was surprised when the agent answered the phone for they answered in Spanish…the language of my heart. What you may not know is, I was born in Spain. Even though I am Spanish, for just a split second I was speechless when the pretext met reality.

Say SomethingDuring the milliseconds of silence, I kept telling myself “Just say something.” I continued with my pretext in English, thankfully the agent swiftly responded in English. After a sigh of relief, I was back to feeling empowered again. After the call I asked myself: what happened? Why did I stall? Afterall, Spanish is my first language, why did I not feel comfortable switching to Spanish? I let those questions float in the back of my mind unanswered. I figured, somehow, I may have pressed the Spanish option by mistake, no big deal.

I continued to the next call. There was the hold music again, another sip of coffee and then the agent answered again in Spanish! I thought “What is going on? Did I press the “para Español” option?” By the third call, I realized that we were calling a Spanish speaking customer service desk. Although the agents I had spoken to were able to switch to English, it was difficult for them to fully understand the entire conversation. I had quite a few of these calls to make. I had to decide to either continue to do all of them in English or switch to Spanish.

Embrace DiscomfortIronically, the easiest thing for me to do would be to continue making the calls in English. I say “ironically” because I didn’t learn English until I was 13 years old and struggled to master the language. Now I use English for work every day so it’s second nature to do vishing in English. Spanish is reserved for my family and close friends. I realized that speaking Spanish for me is closely related to feelings of warmth and emotional intimacy whereas English is my “business” language. While operating in English, I can distance my feelings at any given time thus making it easier to get in and out of character for each pretext. Additionally, it would feel uncomfortable to make these calls in Spanish because I only know the industry’s jargon in English. I wondered, “como se dice ‘update’ in Spanish?”

I decided to embrace the discomfort and make the rest of the calls in Spanish. To that end, I looked up all the unfamiliar terms and translated the pretext. It took me a couple of calls to get comfortable. I thought as soon as the agents heard me speaking their language that I would have automatic rapport. That was not the case.

A Learning ExperienceThe Spanish speaking employees seemed friendlier when I spoke their language, however that did not change their verification procedure. Most of the employees that I spoke to that day were very diligent in verifying me before giving out any information. The lesson: well-trained employees that know how to follow their corporation’s verification procedures are more likely to be secure. Having the opportunity to vish in Spanish was a definitely learning experience.

At Social-Engineer LLC All our vishing calls are made by professionally trained, certified social engineers. We pivot and adjust our conversations like a real attacker while sticking to our code of ethics. By doing this, we create a lasting learning experience to benefit our client company and their employees when they learn to protect their sensitive information from malicious attackers.

Written by Rosa Rowles
Human Risk Analyst
Social-Engineer, LLC

View Details

You’re sitting at home when you receive a call from a charity you’ve donated to in the past. They explain that they appreciate your previous donation and have been calling your neighbors who have been donating an average of $200. “Oh, I can’t afford that!” you respond. “We understand,” they say, “how about $20?” This, you think, you can do.

Unknowingly, you have just succumbed to a technique we in social engineering refer to as “concession.” What exactly is concession? How is it used? What are ways we can be more aware of concession being used against us? Let’s dive in.

What is Concession?Concession, or “the act of conceding,” is defined as:

  1. The act or an instance of conceding (as by granting something as a right, accepting something as true, or acknowledging defeat).
  2. The admitting of a point claimed in argument.

How Concession WorksThe basics of concession can be broken down into four steps. Once we understand these, we have a better probability of resisting this tactic. So, what are the basics of concession and reciprocity? Let’s look at them from the viewpoint of a malicious actor.

    1. Labeling the concessions. Malicious actors will make concessions to create feelings of indebtedness in their targets. In doing so, the target will have a very hard time, psychologically, ignoring the urge to reciprocate.
    2. Pressure to reciprocate. Now that the concession has been given by the attacker, there is a higher likelihood that the target will feel pressure to reciprocate with a similar act of giving.
    3. Make contingent concessions. These are “risk-free” concessions. These are used when trust is low or when the attacker needs to signal that they are ready to make other concessions.
    4. Make concessions in installments. The idea of reciprocity is deeply ingrained in our minds. Most people feel that if someone does them a favor, they should return that favor. Similarly, if someone is to make a concession, say in a negotiation or bargaining agreement, then the other party will instinctively feel obligated to “budge” a little bit too.Example of Concession ProcessAs an example of this process, we can think about the famous con man Victor Lustig, he “sold” the Eiffel tower a number of times in his life.
  1. He used the following process:
    1. Labeling the concession. Once he had a target on the hook, he told them that he would tell them a secret, but they couldn’t share it with anyone else. It was of such high importance that he would concede to telling only them.
    2. Pressure to reciprocate. Once the target heard the secret news (the Eiffel tower was going to be scrapped and the cost of the metal was going to make someone very rich), they felt indebted to continue the discussion further and ask for more information. Many times, the targets would volunteer information like how wealthy they were or how much money they were able to invest.
    3. Make contingent requests. Victor would then make statements alluding to how he can only let a few people into the investment pool, and that he wasn’t sure if it could be them. By using concession aligned with scarcity, he really reeled in the target.
    4. Make concessions in installments. He would continually make concessions through meetings with his targets, until he successfully parted them from a very large sum of their money.Clearly a bad actor, but an effective use of concession.

How Concession is UsedIn addition to the above examples, we see concession tactics used everywhere from telemarketers to car salesmen. They leverage the steps discussed above to entice you to feel like you’re getting a good deal or making a fiscally responsible decision. While good to be aware of, uses of concession are not necessarily malicious. However, concession can absolutely be used maliciously, as seen in the example of Victor Lustig.

Professionally, vishers can use concession in many ways. For example, let’s say they are using the pretext of a virtual desktop infrastructure (VDI) upgrade. They may say something like “your VDI needs to be updated, but there are multiple ways we can go about this, so it is up to you. I can email you the instructions and you can run the upgrade yourself; it should take about 2 hours. Or I can do it for you.” By giving options, the other person feels like they are in control. Then, by giving one complicated option, and one simple option, they may concede to the simple option because it is so much easier. Now imagine how powerful this would be when leveraged maliciously by a professional social engineer! Clearly, concession tactics are worth learning about.

Resisting Concession TacticsThe first thing we need to do in order to resist concession tactics is to be aware of what they are. Reading this article is already the first step! Now that you understand just how concession works, you will be more likely to identify these techniques in real time. What if you can’t consciously identify these techniques, though? Remember to always trust your gut instincts. Often, once we know of something, we can subconsciously identify it even if we can’t quite name what is happening. This is true for social engineering tactics as well, including concession. Knowing this, we can trust ourselves when something feels off during a conversation. Do not be afraid to pause and give yourself a moment to process what is happening. Many times, this is the key to us protecting our information and ourselves from social engineering techniques.

Stay SecureAwareness is the first step in any security program. It is imperative to know and understand the tactics the threat actors will use to social engineer us. Remember to trust your gut instincts and always give yourself a moment to gather your thoughts and check in with your feelings. Being aware of the concession tactic and checking in with yourself will help you to keep you and your information secure.

Written by Shelby Dacko
Human Risk Analyst at Social-Engineer, LLC

View Details

I’ll be honest, I never expected to see myself here… I’ve looked for well over a year at positions within the ever-expanding cybersecurity field – but nothing stood out. Were the offers for salary high? Were there well-known companies hiring within the industry? Most definitely. But no positions really spoke to my interests. Positions that truly attracted that deep, inner curiosity.

Until now.

I write this to highlight a key breakthrough I’ve encountered so far at Social-Engineer, LLC (SECOM), that until now, I hadn’t truly grasped at a fundamental level. Gaining the perspective of a beginner within the field wouldn’t have been achievable at this speed through simple study and self-practice. I am not here to claim deep expertise. I am here to convey the initial breakthrough, not dismissing the fact that countless more are coming down the pipeline as I continue forward within the field. That said, I ask one trivial question: do you know how to leave someone feeling better for having met you?

I sure thought I understood this, until now.

THE MANTRAUpon arrival, the team at SECOM was working in full force to end the year on a high note. All around me seemingly impossible call quotas for vishing (voice phishing) clients provided no lull in action from day one. Looking back on this timeline of events, I realize I began at the most opportune time. No other time of the year would’ve provided me the opportunity to continuously refine my strategies and enhance my creative muscles throughout every vishing engagement, day in and day out. A continuous feedback loop, fueled by both my personal analysis and from professional team member critiques along the way.

Quite literally, it took no more than a few calls to begin seeing patterns emerge. By utilizing foundational rapport building and influence techniques, I was able to elicit information from individuals within the first few vishing engagements I’ve ever performed in my life. With that, the previously mentioned feedback loop kicked into overdrive… I was working through vishing calls and getting floods of dopamine every time I elicited information from an engagement. Notably, this dopamine rollercoaster was hard to step away from. But, as my first day of work began to wind down, an intense feeling washed over me.

Now What?After taking a moment to decompress and analyze my entire first day; filled with meetings and vishing engagements, I noticed that feeling was still there. Confused, I dug deeper. Only after time spent listening back through my engagements throughout the day, was I able to find what was truly brewing in the background.

I had found amazement in the effectiveness of the seemingly basic influence techniques used throughout the day’s calls. That feeling was a realization of the power behind even the most basic understanding of human behavior. I had witnessed firsthand that by leaving people feeling better for having met me, not only was I able to elicit unimaginable amounts of data over the phone, but also collect valuable intel on how to best educate and protect our clients.

The New UnderstandingBefore this perspective shift, or realization of sorts, I could regurgitate information I’ve read from books like ‘Human Hacking’ by Christopher Hadnagy, or ‘It’s not all about “ME”’ by Robin Dreeke regarding rapport building, pretexting, nonverbal accommodation, validation and more. And yes, I had some experience practicing the techniques on family members and close friends to build closer relationships and make the environment more positive. But when I would hear the phrase “Leave them better for having met you,” I can now take a step back and realize that I never comprehended the true meaning of that phrase.

Only now, with the sheer volume of practice within a singular day, could I truly begin to understand the importance of empathy and leaving the other individual feeling better for having met us. The importance, in the testing and training environment at SECOM, of creating an atmosphere for learning and improvement cannot be understated. One can only begin to imagine what realizations will pop up as I continue my journey forward within this field.

Above all, my limited time thus far at SECOM has allowed me to experience in a condensed timeframe what would’ve taken me months (if not years) to learn by myself. Without a doubt, more beliefs will continue to be challenged, broken, changed or reinforced, at an increasingly exponential rate moving forward.

With Great Power Comes Great ResponsibilityWith great power comes great responsibility. How will I leverage this power to deepen both my relationship with myself, as well as those around me? Well, only time will tell, as I continue to approach every interaction with the goal of leaving them better for having met me.

Written by:
Carter Zupancich
Human Risk Analyst at Social-Engineer, LLC

View Details

For some, lack of confidence could mean they’re not very sociable. For others, it could be crippling and could hold them back from reaching their full potential, either personally or professionally. Lacking confidence is usually rooted in personal experiences, such as upbringing, comparison to others, and even personality traits. Some may feel that there’s no way to overcome a lack of self-confidence. But can impersonating confidence actually lead to feeling self-confidence?

ImpersonationMerriam’s dictionary defines impersonation as “to assume or act the character of.” Professional actors often delve deep into the characters they portray. They mimic their posture, tone of voice, even facial expressions. This allows them to not only deliver convincing performances but also to embody the personalities of the characters they are portraying. Many successful performers were able to find a way to turn a situation they feared into success. According to Castingfrontier.com, actor Al Pacino said, “My first language was shy. It’s only by having been thrust into the limelight that I have learned to cope with my shyness.”

The thought of being “thrust into the limelight” may put some off completely. But you may be able to develop the ability to tweak or adjust your behavior in a slight but meaningful way. For example, you may wish to be more outgoing, but your idea of mingling at a party is waving hello from a distant corner. While it may be unnatural for you to approach everyone at the party with jokes and laughs, you could set a goal to approach one person whom you have not met and introduce yourself. Then, next time you find yourself in another gathering, expand the number of people you approach and talk to. Incrementally adopting a desired behavior will help you to feel more comfortable as you reach your goal.

Body Language of ConfidenceBehavior expert Joe Navarro says, “Confidence begins in the brain, but it’s the body that convinces ourselves and others.” Here are some tips to that:

  • Walk Confidently – When you walk into a room or on a stage, do so as if you were on a mission. With your shoulders rolled back and your chin slightly lifted. Don’t be afraid to look around the room.
  • Make Eye Contact – Make and sustain the appropriate eye contact.
  • Use Gestures – As you speak make smooth and broad hand gestures. Try steepling, which is done by placing the fingertips of both hands together, spreading them. This is a universal display of confidence.

Model ConfidenceCan you think of a leader, speaker, or artist, whose confidence you admire? Try impersonating their behavior. How do they walk into a room? What’s their tone of voice? How do they look at their audience? What type of gestures do they make? By modeling their confident behavior, we can adopt it as our own.

Faking confidence is an artform that some individuals master in different areas of their lives. It involves projecting a self-assured demeanor, even when we have internal doubts or insecurities. Remember, the next time you walk into a room, go in with eyes wide open, roll your shoulders back, and scan the room and the people in it. By impersonating qualities of confident people, you can become a confident person.

Written by Rosa Rowles
Human Risk Analyst at Social-Engineer, LLC

View Details

Public speaking is something that many people struggle with. In fact, 75% of the population has a fear of public speaking. Just the mere mention of it may start to make your heart race, if it is a fear of yours! Truth be told, I most definitely fall into the 75% category.

Don’t get me wrong, I enjoy talking to people! In fact, it is something I do almost every day as a Human Risk Analyst. However, speaking to an audience is a whole different beast. I recently gave my first company speech entitled, “The Factor of Human Error.” In prepping for my speech, I realized that the techniques I daily use as a certified social engineer equipped me more than I realized. Combined with the practical tips from my fellow team members, I was able to power through my speech and provide the information in a way that would hopefully prompt my listeners to act.

In this article I’ll go over some of the techniques we use in vishing simulations and how they can help us to influence the audience we may be speaking to.

Influence TechniquesAt Social-Engineer, you may often hear or read about us referring to “Influence Techniques.” These are methods of influence that we use on live vishing calls with our clients and are part of our framework. When speaking to a live audience, especially on a topic as important as cybersecurity, it is important to motivate and influence your listeners to want to make a change or act. Here are some influence techniques that help, both as a professional social engineer and a public speaker.

LikingPeople are more prone to be influenced by things or people that they like. Therefore, Liking is such a powerful tool for a social engineer both on the phone and on the stage. In a vishing call, Liking often takes the form of cracking a joke, making lighthearted conversion, or even adjusting the pitch/tone of our voice to be more inviting. This helps move our target to 1) continue the conversation with us, and 2) take an action we want them to take.

These same methods can be used on a stage! If trying to motivate your audience, speaking in a monotone voice or seeming very apathetic about your own subject matter can often dissuade people. While remaining professional, incorporating humor and speaking passionately about your subject will help your listeners to be more receptive to the information you are delivering. When trying to influence a crowd to take some sort of action, be the proponent that they want to follow!

Social ProofThis psychological phenomenon occurs in social situations when people cannot determine the appropriate mode of behavior. People will often follow the momentum of the crowd, if the consensus of the majority seems acceptable. In a Vishing call, we often use Social Proof to feed our target information on what we want them to believe is socially acceptable. For example, if presenting our target with the idea of an HR Survey, we may refer that they are one of many on our list of employees to reach out to. We might allude to others taking the survey too.

Using Social Proof during a speech is much easier than in an adversarial simulation…though the results are just as effective! Whatever your topic is, try and find ways it benefits others, and use that to highlight its importance. For example, let’s say you’re trying to motivate your audience to use Multifactor Authentication. Instead of just focusing on why it is beneficial, why not show how it has benefited multiple companies and protected them from potential threats? Give examples on the positive impact in everyday life in protecting one’s identity. By highlighting the topic as something positive and acceptable among others, it might be the nudge your audience needs to act as well.

NOTE: Do not fabricate information for your topic in a desperate attempt to motivate your audience. Using real-life statistics and examples is very important in case your audience does their own research into what you have shared. Put in the time to give examples of real social proof.

ObligationObligation is an influence technique that needs to be handled carefully. It involves actions one feels they need to take due to some sort of social, legal, or moral requirement, duty, or promise. It is closely related to reciprocation but is not limited to it. Think of holding an outer door open for someone entering a building, often the individual might hold the inner door open for you in return. If you treat people kindly and give them something they may need, even in the case of a compliment, it can create a sense of obligation to you.

In a vishing call, complimenting can create a source of obligation, but we can also create a sense of duty for our target. We might say that they were “on a list of employees that needed to update their system so we can proceed with a mass software patch.” This not only creates a sense of urgency, but also influences the target into feeling like it is their responsibility to make sure everything else flows smoothly.

Obligation – a powerful toolUsing obligation in a speech is a powerful tool, especially if the topic you are speaking about is a responsibility that falls on everyone else. For example, let’s say your topic is motivating an audience to be more security conscious. You may highlight how each employee has been given a heavy responsibility by their company to help protect their fellow employees. This sense of duty may motivate the individual to take security more seriously as now they feel it is their obligation to do so.

We could also try complementing our audience on how well they have been with security awareness training. We can then follow up on this commendation with a request for them to do even more. Of course, we should never aim to “guilt” or “force” our audience into taking a specific action, rather through positive inspiration will we often find the best results.

ConclusionOverall, Influence Tactics strike common ground between its use in a social engineering engagement and public speaking. It may also be beneficial to combine different Influence Tactics to effectively influence your audience.

Of course, we need to adapt to the crowd as well. These techniques are not a 100% guarantee or cheat code to be an effective speaker. We must still put in the time to familiarize ourselves with our own source material. Influence tactics can only do so much for us if we don’t know our material well, as is the case in a vishing call if we don’t have our pretext properly formulated.

However, combining these efforts and practical tips, such as proper pacing, practice, and organization, will help you be an effective speaker. You will be able to break through to your audience and motivate them in a positive way. At Social-Engineer, our motto is, “leave them feeling better for having met us”. Aim to do the same for your audience!

Written by:
Josten Peña
Human Risk Analyst at Social-Engineer, LLC

View Details

In the ever-evolving landscape of cybersecurity, social engineering has undergone significant transformations over the years, propelled by advancements in technology. From traditional methods to the integration of artificial intelligence (AI), malicious actors continually adapt and leverage emerging tools to exploit vulnerabilities. This article delves into the historical shifts in social engineering tactics and explores how adversaries embrace new technologies to achieve their objectives.

Historical Shifts:Social engineering has a rich history that reflects the evolution of technology from the pre-internet era to the rise of social media. Understanding these historical shifts provides valuable insights into the evolving nature of social engineering.

Pre-Internet Era:In the pre-internet era, social engineering primarily relied on interpersonal communication and physical access. Techniques included impersonation, dumpster diving for sensitive information, and manipulating individuals through phone calls (also known as vishing). Malicious actors exploited trust and human psychology to gain unauthorized access. Many of these tactics would still be used as time went on.

Phishing and the Internet Boom:With the rise of the internet, phishing became a prevalent social engineering tactic. Attackers utilized emails to deceive individuals into revealing sensitive information. As technology advanced, phishing techniques evolved to include more sophisticated email designs and persuasive content. As seen in the modern day, phishing is still a viable option for malicious actors. At times, attackers have even combined the likes of phishing and vishing for a hybrid attack.

Social Media Exploitation:The widespread adoption of social media platforms opened new avenues for social engineering attacks. Malicious actors leveraged personal information shared on social media to craft targeted attacks. Spear phishing emerged as a more refined technique; tailoring messages based on detailed knowledge about the target. In effect, social media allowed many attackers to build a more thorough profile of their target.

Adapting to AI:Social engineering continues to evolve with the integration of AI, presenting new challenges for corporations. Automation and AI-assisted attacks have become prevalent, and the emergence of deepfake technology poses unique threats. Organizations must adapt their defenses to counter these advanced tactics.

Automation and AI-Assisted Attacks:Malicious actors have embraced AI to automate and enhance social engineering attacks. AI algorithms analyze vast datasets to craft convincing phishing messages and simulate human-like communication. This level of sophistication poses new challenges for traditional defense mechanisms.

Deepfake Technology:The advent of deepfake technology allows attackers to impersonate individuals convincingly. Malicious actors can create realistic audio and video content, making it challenging to distinguish between genuine and manipulated communication. This poses a serious threat to organizations relying on voice and video for authentication.

Exploiting Chatbots and Virtual Assistants:AI-driven chatbots and virtual assistants are exploited to impersonate trusted figures within organizations. Attackers use these tools to deceive employees into disclosing sensitive information, highlighting the need for heightened awareness and identity verification.

Adapting Corporate Defenses:To effectively counter the evolving landscape of social engineering, corporations must implement adaptive defense strategies. Continuous employee training, simulated testing, integration of advanced AI security solutions, and regular security audits are crucial components of a comprehensive cybersecurity posture.

Continuous Employee Training:Corporations must evolve their training programs to address the changing tactics of social engineering. Employees need to be educated on recognizing AI-driven attacks, deepfakes, and other emerging threats. They should be tested to ensure the training they have received is effective and on top of this, educated in the proper reporting procedures. Reporting is essential, as at times employees may find themselves as the first line of defense against attackers. Teaching them to always be on guard will help build that security-minded culture in a company.

Integration of Advanced AI Security Solutions:To counter AI-powered social engineering, many organizations have invested in advanced AI security solutions. These systems can analyze patterns, detect anomalies, and provide real-time threat intelligence, enhancing the ability to respond effectively. This not only helps protect against external attacks, but even the likes of insider threats.

Regular Security Audits and Updates:Routine security audits are crucial to identifying and patching technical vulnerabilities. Organizations should stay vigilant, keeping software, applications, and security measures up to date to withstand evolving threat actor techniques. A detailed security response procedure should be in place in the event an attack is successful, as this will help prevent further damage and neutralize the threat.

Conclusion:As technology continues to advance, social engineering tactics will inevitably evolve. Artificial Intelligence is no longer something from science fiction movies. Understanding the historical shifts in social engineering and staying ahead of emerging threats is crucial for corporations. By fostering a culture of cybersecurity awareness, leveraging advanced technologies, and adapting defensive strategies, organizations can fortify themselves against the ever-changing landscape of social engineering threats.

Written by:
Josten Peña
Human Risk Analyst at Social-Engineer, LLC

View Details

When people hear that I get to write phishing emails and make vishing calls for a living, the first question they generally ask is, “How did you get into that field?” For some, the next question is, “How do I get into that field?” If you’re part of the latter group, this newsletter is for you. Let’s explore the tips and tricks to getting into the trade. Hopefully, this perspective will help you start or continue your journey to becoming a Human Risk Analyst.

Start Building Your Industry KnowledgeFirst and foremost, you must begin by building your industry knowledge. There are many free resources you can use to get started. The first thing I like to point people to is the social engineering framework created by Christopher Hadnagy. This framework outlines the ethical guidelines for using social engineering as a professional. This is very important because as an aspiring professional, you want to ensure that you are applying the things you will learn in ethical ways. We want to leave people better for having met us, and more secure for it as well.

Another great and free resource is podcasts. There are many industry podcasts that exist that can help you build the right kind of knowledge. Two that I recommend are Darknet Diaries and The Human Element series. Both podcasts give insight into the industry and can help you get a feel for the community. I have linked 2 specific podcast episodes below that deal with exactly what we are discussing today. Hopefully you find them useful!

– Training to be a social engineer

– The SE Framework

Finally, read up! Reading industry books will help you learn from the experts. Check out this book list to help you find what you’re looking for!

Get Outside of Your Comfort ZoneAdditionally, you need to be willing to try new things and step outside of your comfort zone. Most of us, MOST of us, don’t spend our days hopping barbed wire fence, using aliases when calling people, and trying to get clients to click on suspicious links. These things should be new to you. Because of this, we need to be willing to try things that could be uncomfortable at first.

I’ll tell you a secret… When I started at Social-Engineer, LLC, I HATED being on the phone. I knew that if I was hired, a large portion of my job would be making vishing phone calls. I decided to see if I could overcome my discomfort, though, and give it a shot. I was able to adapt, and today I even enjoy many of my vishing conversations. This is good, because I’ve had thousands of them! The point? Sometimes we need to get used to being uncomfortable.

Courses and CertificationsA common question I get from those looking to enter the industry is, “What courses and certifications should I take/obtain?” Since we’ve established you will be trying new things and learning new skills, it makes sense that you would want a course that is going to expose you to some of those things. The courses that I took and the ones I recommend are those offered through Social-Engineer, LLC. Without giving too much away, these various courses apply social engineering to real work-related scenarios and help you practice the various skills needed to be a Human Risk Analyst. My personal favorite class, the Foundational Application of Social Engineering (FASE) class, focuses on the aspects of human decision making, and why it is important to understand these mechanisms.

As far as certifications go, there are a million to choose from. There is only one, though, that certifies you to become a professional social engineer. That is the Certified Ethical Social Engineer (CESE) course, provided through Social-Engineer, LLC. The recommended way to access this certification test is by taking one or both of our two classes, FASE or the Practical Application of Social Engineering (PASE). After completing at least one of these classes, you will get a free attempt to test for the certification, or you can pay to take the test directly if you feel you have the skills to pass already. This one-of-a-kind certification will ensure that you have the necessary skills for becoming a Human Risk Analyst.

NetworkingThe last key we will discuss to getting into the industry today is to surround yourself with the right people. This may sound easier said than done, but it is worth the effort. I recommend attending as many industry conferences as you can and networking with people in person. There is no better way to make the right connections. Social media sites such as LinkedIn can help you in your efforts as well. Search for those whose ethics align with yours and who will build you up and help you reach your goals.

Becoming a Human Risk AnalystWhen all is said and done, there is no one right way to go about becoming a Human Risk Analyst. On my team alone, we have people from all different backgrounds. No two of us got into the industry in the same way. Hopefully, though, the tips in this article can assist you in getting started or continuing on your path. Remember to get out of your comfort zone, take applicable courses, and network within the industry. If you do these things, you’ll be on the right track to becoming a Human Risk Analyst.

Written by:
Shelby Dacko
Human Risk Analyst at Social-Engineer, LLC

View Details

“How do I keep my child safe on the internet?” This question is hard to answer in a few minutes because it is one that is so complex. And since this topic is so vast, let’s focus on one sector, Social Media.

Did you know that 95% of youth today report using social media? “Youth” is somewhat vague, so let’s narrow that down. Forty percent of 8 to 12-year-olds use social media, reports the 2023 Social Media and Youth Mental Health – The U.S. Surgeon General’s Advisory. Keep in mind that social media is not inherently good or bad. However, there are some things we should remember if our child or teen is active on social media today. This article will address some areas of concern, as well as dive into steps we can take to keep our kids safe on the internet.

Benefits and DangersA quote from the previously mentioned report reads “There is broad agreement among the scientific community that social media has the potential to both benefit and harm children and adolescents.” What are some of these potential benefits and dangers? Let’s start with the obvious. Social media provides a sense of connection and community. It also gives us access to information. Additionally, it enables us to form and maintain friendships.

Although there are some positives, we also need to take a look at the negatives. According to the report, spending more than three hours a day doubles the risk of poor mental health (including anxiety and depression). In 2021, eighth and tenth grade students spent an average of 3.5 hours a day on social media. While social media does give us access to information, it can be hard to determine what is real and what is misinformation. Also, we don’t always know if the friends we or our kids meet on social media are really who they say they are. Additionally, malicious users of the internet can use social engineering techniques against our children. Clearly, we need to take action to keep our children safe on the internet. How?

TRIGGER WARNING: The following paragraphs address a topic that may be triggering for some.

GroomingBefore we get into the “how,” we need to understand the “who” and “what.” “Who” are we protecting our children from? Namely, predators. And “what” are we protecting them from? Grooming. What IS grooming? The dictionary defines grooming as “the practice of preparing or training someone for a particular purpose or activity.” Predators will use the grooming method to target and exploit their victims, and unfortunately, many of these victims are children.

To be able to combat grooming, we need to understand it. Let’s take a brief view at how it starts and ends. It starts with a predator targeting a victim. Then they will gain the trust of and information on that victim. This could be obtained by using various social engineering tactics, such as liking, mutual self-disclosure (where the information they provide is false), and sympathy or assistance themes. (To learn more about these techniques, please view the following information: Instant Rapport.) Next, the predator fills a need in the victim’s life, making themselves significant to the victim in some way. Then, they begin to isolate the victim, after which the abuse begins. They will then do everything in their power to maintain control.

By understanding the steps a predator takes to groom their victims, we are more likely to see the signs and jump in where needed. By understanding the social engineering and influence techniques that these predators use, we will be able to spot the dangerous language and actions of said predators. However, one thing is needed if we are to do this, open communication with our children.

Open CommunicationOpen communication has saved child after child from dangerous situations on the internet. If your child or teen feels uncomfortable with a friendship, their coming to you about it could be what protects them. Because of this, we always encourage open communication and age-appropriate discussions about the dangers of the internet and social media. This is a continuous process as your child grows up, not just one conversation. These conversations can seem daunting if you’re not sure where to start. The Innocent Lives Foundation (ILF) and The National Center for Missing & Exploited Children (NCMEC) both provide guides and free resources for parents looking to have these conversations.

The ILF recommends establishing internet use guidelines with your children. They suggest the following as a starting point:

  • A list of approved apps/websites.
  • Their device privileges are dependent upon your right to view anything on the device at anytime.
  • A list of acceptable content (What types of photos are allowed, no posting hurtful or explicit comments, appropriate types of videos or music) to post or exchange.
  • Guidelines of who they can interact with online.
  • Never share personal details such as school, phone numbers, real names or addresses with anyone online. If they know you personally, they will be able to get a hold of a verified guardian for those details.

Monitoring Your Child’s DevicesMany ask, SHOULD I monitor my child’s devices? Experts recommend yes, with some caveats. Think back to our first point, open communication. This goes two ways, from child to parent AND from parent to child. We feel that discussing AGE APPROPIATE monitoring options with your child can build trust, while monitoring in secret can do much the opposite. After that step is taken, there are some tools that you may find useful.

iKeyMonitor is one such tool that some have found success with. It allows you to monitor text messages, record phone calls, check websites visited, and track current GPS location.

Kidslox is another such app that many have found useful. This app allows you to set daily time limits and lock specific apps.

For a more in-depth look at monitoring, please read the following guide: Guide to Monitoring .

Help Young Ones ThriveThe internet can be a place where children and teens either thrive or find themselves in harm’s way. By keeping your communication open with your young one, setting clear boundaries, and monitoring their devices in an open and age-appropriate way, you can help them remain secure and safe.

Written by:
Shelby Dacko
Human Risk Analyst at Social-Engineer, LLC

View Details

What would you say are some traits of someone who is empathic? I would say some of those attributes would include being patient, attentive, understanding and a good listener. Now, think back to when a teacher who was empathic and went the extra mile to help you or other students that may have been struggling in that class. Surely, that contributed to a better learning environment and encouraged you to do better in that class. As adults we tend to lose some of that empathy when teaching other adults as we may reason “they should know better.” How can an empathic approach improve security education?

The Importance of Security EducationAccording to Proofpoint’s 2023’s Human Factor report, more than 99% of threats require human interaction to execute, such as enabling a macro, opening a file, following a link, or opening a malicious document. This means social engineering plays a crucial role in a successful attack. With this said, more companies than ever before are implementing cyber/information security training and testing. Ongoing training and testing enable employees to recognize social engineering attacks, as well as how to respond and properly report them. Part of this training would include realistic testing such as phishing, vishing, and smishing. Ethical social engineers perform these tests using realistic pretexts while implementing empathy.

Providing a Teachable MomentSome may wonder, “How can you perform realistic and effective testing while having empathy? Afterall, an attacker would not have such empathy.” While it is true that criminals will do just about anything to achieve their goal, ethical social engineers are not criminals. We want the testing to be realistic and at the same time provide a teachable moment. I often make the comparison of a fire drill; you want it to be realistic, but you wouldn’t actually set the building on fire. Ultimately, we want the person that’s being tested to learn how to interact and report the attack. More importantly we want them to adapt that behavior in the long term while in a safe environment.

We use principles of influence such as authority, scarcity, sympathy, and slight fear, but we will never use a pretext that will elicit extreme fear or create a false expectation such as promising things that the employee will never get. Imagine your company sends you a realistic email promising a bonus and all you have to do is confirm your information in an “HR Portal.” Everything seems legit in the email and you’re excited to get a little extra cash so you click on the link. It then redirects you to a pop-up screen that lets you know it was a test. Promising something that employees will never get can lead to feelings of disappointment and even resentment. This would not be conducive to a positive teachable moment.

The Empathetic ApproachHaving realistic but empathic pretexts allows us to perform our test in an ethical way which allows the tested population to remember the lesson learned without feeling resentment. In turn that will motivate them to want to comply and cooperate with their company’s security procedures. When we humanize the tested population and treat them as our fellow employees (instead of just targets), they can view the training and/or testing as a tool for them, not as an adversarial attack. Security awareness training should focus not just on “clicks,” but also on how it will affect the people that serve that business. Employees need to see their IT departments as advocates, not adversaries.

When influential information security practitioner Kate Mullin was a guest on the Social-Engineer podcast, she said, “Part of employee engagement is, you need to care about them, and it can’t be fake. It has to be real.” Implementing a security awareness program that considers not just the business’ needs but that of the employees, can create a partnership that results in everyone being more secure.

Social-Engineer provides custom managed services to assist organizations in the assessment and education of their human network. We take a personalized approach to training and testing. Our team of expert social engineers focus on the tactics hostile attackers use to influence and manipulate people via phishing, vishing, and impersonation. We will assess your organization’s vulnerability to a social engineering attack. Then we will provide customized training and guidance to make your company more secure. You can learn more about the services we offer at our website Social-Engineer.com/managed services/.

Written by:
Rosa Rowles
Human Risk Analyst at Social-Engineer, LLC

View Details

As 2023 comes to an end, it brings along with it a time many people look forward to: the holiday season. With this time of year coming around, however, we see an increasing amount of holiday related scams. Because of this, we want to review common end-of-year scams and how to guard against them. The FBI states that one of the most common scams is non-delivery crimes. Phishing emails with holiday themes will also increase during this time of year. You may even come across scams on social media! Let’s look together at these scams and learn how to protect ourselves from them.

Non-delivery ScamsThe first scam we will discuss is a non-delivery scam. In a non-delivery scam, a customer pays for items or services found online, but those items or services are never received. Unfortunately, according to the Internet Crime Complaint Center’s (IC3) 2021 report, non-payment or non-delivery scams cost people more than $337 million. To read more about non-payment scams, view the FBI’s statements here. To avoid non-delivery scams, adhere to the following tips:

  • Be sure to do your own research when purchasing from a company for the first time and give special attention to reviews.
  • Be wary of sellers who respond to questions by saying that they are unavailable due to business, family emergency, or similar reasons.
  • Never wire money directly to a seller.
  • The Federal Trade Commission states that only scammers will insist you pay them with a gift card and give them the numbers off the back of the card. No real business or government agency will ever tell you to buy a gift card to pay them. If paying with a gift card of your own volition, always keep a copy of your gift card and store receipt.

Phishing EmailsIn addition to non-delivery scams, we will likely see a rise in holiday related email scams. You may see emails surface that are themed around coupon discounts or order confirmations. To avoid these scams, keep an eye out for the following things:

  • Be wary of emails from senders not affiliated with the brand it is claiming to be from.
  • Don’t click links in emails from that are asking you to take some action.
  • If you have an account with the vendor, use a previous known good link or bookmark to access your account and not the one in the email.
  • Be aware when emails are trying to evoke an emotional response and take a moment to think about if the request in the email makes sense.

Social Media ScamsSocial media scams can be especially effective because they take advantage of something that most of us utilize. You may come across holiday themed promotions or contests on social media that offer gift cards or vouchers simply in exchange for completing an online survey. Usually, these surveys are not legitimate. Rather, they are a way of capturing your personal information. To avoid these types of scams, resist the urge to complete forms that ask for personal information, even if that information may appear harmless! For example, you may come across quizzes that will match you with a movie character or celebrity. Even these types of quizzes may request personal information such as your favorite color, which may be a security question on some of your accounts.

As the end of the year rolls around, keep an eye out for these three kinds of scams. If you follow the tips outlined in this article, you’ll be on a great track to protect yourself. Help us in spreading these tips to your families, friends, and colleagues. Phishing testing is the best way to get used to responding and reporting phishing scams in the most ideal way. We highly recommend this testing for all companies. For more information, please view our services here:

https://www.social-engineer.com/managed-services/managed-phishing-service/

Written by: Shelby Dacko

View Details

The world is no stranger to tragedy. From natural disasters to global pandemics and geopolitical conflicts, we have all witnessed events that shake us to our core. Unfortunately, in the midst of these crises, there are those who seek to exploit our emotions and vulnerabilities for their own gain. Malicious actors and scammers, commonly referred to as “bad actors,” are adept at seizing the opportunity presented by these tragedies to carry out their deceitful schemes. In this article, we’ll explore how these bad actors exploit world tragedy, using real-life examples from 2023 and previous years.

COVID-19 PandemicThe COVID-19 pandemic was a global tragedy that affected millions of lives. Bad actors wasted no time in exploiting the public’s anxieties and fears for financial gain. They sent phishing emails impersonating health organizations and government agencies. These emails contained malicious links or attachments that, when clicked, could infect a victim’s device with malware or steal sensitive information. The personal information collected could then be used to fraudulently bill federal health care programs and commit medical identity theft. The information could also be used for other nefarious gain. The pandemic also saw a surge in employment scams, bad actors posing as companies offering remote work, only to run off with sensitive information from hopeful applicants.

Spotting Scams Like This:* + Be cautious of unsolicited emails and verify the sender’s legitimacy. + Check the email addresses and domains carefully for any misspellings or irregularities. + Avoid clicking on links or downloading attachments from unknown sources. + Be wary of job opportunities or offers that may seem “too good to be true” and do proper research to verify the corporation’s legitimacy.

The War in UkraineGeopolitical conflicts, such as the war in Ukraine, provide fertile ground for bad actors to thrive. During the ongoing conflict, bad actors took advantage of the situation by impersonating humanitarian organizations and exploiting the public’s desire to help those in need. They set up fake donation websites, which siphoned money away from legitimate relief efforts and left victims with a false sense of goodwill.

Spotting Scams Like This: + Perform thorough research on organizations before making a donation. Verify their authenticity and legitimacy. + Be wary of unsolicited emails seeking* donations. If looking to fund a specific charity, visit the website directly rather than clicking on links found in emails. + Watch out for “charities” asking you to pay with cash, gift cards, wire transfers, or cryptocurrency. This can be a red flag, and it should be handled with discretion.

The Maui FiresNatural disasters like the Maui fires evoke intense emotions and vulnerability among affected communities. Bad actors capitalize on this vulnerability, exploiting the desperation of affected individuals. Scammers often impersonate disaster relief organizations using social media, fake websites, and emails, to solicit donations or offer fake assistance. Even worse, scammers may claim to offer insurance or financial aid to victims in order to obtain personal information or a payment for some fee, then disappear.

Spotting Scams Like This:* + When moved to offer aid during a time of need, always do the proper research on relief funds and organizations before providing monetary assistance. This not only helps keeps us from getting scammed by impersonators but is also helpful in making sure the funds really go to those in need. + If you are the victim of a natural disaster, be wary of bad actors looking to take advantage of your distressing situation and seek assistance from reputable relief organizations.

The War in IsraelThe war in Israel has not been immune to such exploitation either. Misinformation campaigns have not only spread fear and discord but have also been used as bait to lure victims into donation scams, as in the case of the previous examples above. They have also been used to spread divisive propaganda with the aim to cause discord among the masses. When tensions run high, people are more likely to make mistakes. Scammers are aware of this, as in the case of the pandemic and other global conflicts.

Spotting Scams Like This:* + Verify the sources of information before sharing or reacting to it on any platform. Cross-reference news and information from multiple reliable sources. + Be wary of messages/posts from social media accounts with no history or a suspicious agenda. + Be cautious of urgent requests from suspicious social media accounts. If the sender is seemingly someone you know, but the nature of the message seems odd, always err on the side of caution. Reaching out to the person directly could also alert the individual that their account has been spoofed or hacked.

Exploiting Emotional VulnerabilityBad actors exploit world tragedies because emotions run high during such events. Fear, empathy, and a desire to help, can cloud judgment. In these moments, critical thinking is often compromised. Scammers prey on these vulnerabilities, using tactics that create a sense of urgency or exploit the fear and uncertainty associated with the crisis.

It is important that we educate ourselves and stay informed about the recent attack vectors that scammers may be using. Often it will include something in the headlines of today’s news to evoke an emotional response from us. By remaining vigilant, we can successfully protect ourselves and those close to us from the likes of bad actors now and as we move into a new year. As seen in the previous examples, bad actors will stop at nothing to compromise their targets. We should never underestimate the lengths they will go to get what they want.

Written by:
Josten Peña
Human Risk Analyst for Social-Engineer, LLC

View Details

At Social-Engineer, we define impersonation as “the practice of pretexting as another person with the goal of obtaining information or access to a person, company, or computer system.”

In today’s digitally driven world, impersonation scams have become a growing concern, leaving countless individuals and organizations vulnerable to financial loss, identity theft, and reputational damage. Impersonation scams are deceptive tactics used by cybercriminals to pose as trusted entities or individuals to exploit victims. This blog will delve into the various types of impersonation scams, shed light on their insidious nature, and provide practical tips on how to protect yourself from falling prey to them.

Types of Impersonation ScamsImpersonation scams come in various forms, each designed to trick unsuspecting targets into divulging sensitive information or parting with their hard-earned money. Here are some common types:

1. Phishing EmailsWhat They Look Like:These emails appear to come from legitimate sources, such as banks, social media platforms, or government agencies, requesting personal information like passwords or financial details. They may contain links to websites or login portals that mimic the real source, however they are designed to fool unsuspecting victims. They may also have attachments that contain malware.

Information They Try to Get:Cybercriminals may aim to steal login credentials, credit card numbers, or personal identification information. The links they attach in the email may take the victim to a webpage that infects their system with malware.

How to Spot Them:Phishing emails could contain spelling and grammatical errors. They could also have generic greetings, along with suspicious email addresses or links that have odd characters in them. They may contain artificial time constraints that evoke a sense of urgency or use fake social proof to give off the impression that “others” have participated and benefited.

2. CEO Fraud or Business Email Compromise (BEC)What They Look Like:Scammers impersonate high-ranking executives within a company to trick employees into making financial transactions or revealing confidential information. These emails can present a fake sense of authority that can very easily pressure an individual to take actions they normally wouldn’t. In some cases, an actual high-ranking employee’s account may have been compromised already. An attacker could then use the account to make out-of-the-ordinary requests from other staff members.

Information They Try to Get:Cybercriminals may seek financial gains by convincing employees to transfer money or provide sensitive corporate data.

How to Spot Them:Look for subtle changes in email addresses or domain names, unusual requests for wire transfers or sensitive data, and inconsistent communication style. It may also be an email coming from a legitimate internal source…however a bad actor may have compromised the account.

3. Tech Support ScamsWhat They Look Like:Impersonators pose as tech support agents from reputable companies and request access to your computer, claiming to fix non-existent problems. They may even be impersonating internal tech support at your work, claiming they need to fix problems on your workstation.

Information They Try to Get:These impersonators may aim to install malware, steal personal data, or extort money for alleged technical services.

How to Spot Them:Be cautious of unsolicited calls or pop-up messages claiming technical issues on your device. Of course, there are legitimate system notifications we may get on our machines when problems do arise. However, illegitimate notifications or pop-ups typically pressure the user to call a number for “assistance.” They may also request the input of sensitive information. Remaining vigilant is the key here.

4. Social Media ImpersonationWhat They Look Like:Scammers mimic the profiles of friends or acquaintances to solicit personal information or engage in fraudulent activities. They may attempt to evoke an emotional response, claiming that they are under difficult circumstances or that they require your assistance.

Information They Try to Get:Cybercriminals may attempt to gather personal data, gain access to accounts, or spread malware. They may attempt to gain monetary “assistance” from relatives of the person they are impersonating.

How to Spot Them:Check for fake profiles with limited activity, few connections, and suspicious content. Be wary of unsolicited messages from followers requesting personal information, especially if you rarely interact with these individuals.

The Best DefenseProtecting yourself from impersonation scams is crucial in today’s interconnected world. Here are some practical tips to safeguard against these threats both in the workplace and everyday life:

  1. Verify the Source: Always verify the identity of the person or organization requesting sensitive information. Contact them through trusted channels to confirm the request’s legitimacy. Simply using a different channel than the one you were reached through may also be effective.
  2. Exercise Caution with Emails: Be cautious when receiving unsolicited emails, especially those requesting personal information or financial transactions. Double-check the sender’s address for spelling errors, strange characters, or unrelated domains. Scrutinize email content for inconsistencies such as unofficial watermarks, mismatched sender, and signature names, etc.
  3. Educate Yourself: Stay informed about the latest impersonation scams and tactics. Awareness is a powerful tool in recognizing and avoiding these threats.
  4. Use Strong Passwords: Create strong, unique passwords for your online accounts and enable multi-factor authentication whenever possible to add an extra layer of security.
  5. Implement Security Software: Install reputable antivirus and anti-malware software on your devices and keep them updated regularly.
  6. Train Employees: In a corporate setting, provide cybersecurity training for employees to recognize and report impersonation attempts, especially BEC scams. The training should also involve testing the company’s population regularly to ensure that the education sticks. This provides a cyber-security conscious environment amongst all staff.
  7. Report Suspicious Activity: If you suspect an impersonation scam, report it to the relevant authorities, such as the Federal Trade Commission (FTC) in the United States, or your local law enforcement agency. In a corporate setting, immediately report suspicious activity to your security team.

The TakeawayImpersonation scams are not merely nuisances; they pose significant risks to individuals and organizations alike. Ignoring or underestimating these threats can result in financial losses, reputational damage, and personal hardship. By understanding the various types of impersonation scams, learning to spot them, and implementing robust security measures, you can protect yourself and your loved ones from falling victim to these dangerous schemes. Always remember that vigilance and education are your best defenses against impersonation scams and taking them seriously is paramount in our digitally connected world.

Written by:
Josten Peña
Human Risk Analyst at Social-Engineer, LLC

View Details

Every year, thousands of people fall victim to vishing attacks conducted by malicious actors. In fact, the TrueCaller Insights 2022 U.S. Spam & Scam Report stated that 1 in 3 Americans (33%) report having ever fallen victim to phone scams. Along with this, as many as 68.4 million Americans (26%) reported losing money from phone scams. Up from 59.4 million (23%) in the year prior.

These statistics are no doubt very concerning and may lead to some questions; What do these kinds of scams look like, what can I do to protect myself? In this article, we will be discussing 4 different forms of vishing attacks that we see most commonly nowadays. We will discuss the approach scammers may take with these, along with how to protect ourselves from their attacks.

RobocallsRobocalls are the most well-known form of a vishing attack. They are often a pre-recorded call played back to every single person that is dialed or to the voicemail it reaches. The voice asks for personal information or may claim to be representing a business or government agency.

These types of scams are becoming increasingly common to spot that most people simply hang up when they receive them. However, statistics show that in 2022, the amount of people that fell victim to a robocall and lost money increased to 61.1% from 60% in 2021. This goes to show that even robocalls are still a viable means that scammers use to prey on the public.

To protect yourself from robocalls, consider the following steps:

  • Avoid providing personal information or making payments over the phone unless you initiate the call to a trusted entity.
  • Know that government agencies will never call, email, or text you to ask for money or personal information unsolicited.
  • Know that services such as the National Do Not Call Registry, can only block legitimate sales calls from real companies, but cannot stop calls from scammers. You can try installing call-blocking apps or enable call-blocking features provided by your mobile service provider that can identify and block suspicious calls. However, note this may not a be a fool-proof method, so always remain vigilant.

Tech Support CallsTech Support calls usually involve scammers posing as representatives from reputable companies, such as internet service providers or software providers. They may call claiming that your computer or device has a technical issue and request remote access or payment to fix the problem. If the caller is aware of products that you may use such as streaming services and subscriptions, they may choose to call regarding “changes to your account”.

When it comes to corporations, Tech Support calls are some of the most common. In attempt to compromise an employee of a company, a scammer may pose as someone from an internal IT help desk to “fix” some problems on the employee’s computer. They may even impersonate the real help desk line by using spoofed numbers or even the names of individuals affiliated with it.

To protect yourself from tech support calls:

  • Always be skeptical of unsolicited calls claiming to provide technical assistance. Companies such as Microsoft or Amazon will never reach out to consumers for technical issues unsolicited.
  • Never grant remote access to your computer or device to unknown individuals.
  • Contact the company directly using official contact information to verify the legitimacy of the call.
  • If you are an employee and the caller is posing as a fellow colleague, verify their identity first through your company’s proper channels.

Caller ID SpoofingCaller ID Spoofing, as mentioned briefly above, is a technique that is used by scammers to manipulate the caller ID displayed on your phone’s screen, making it appear as if the call is coming from a trusted source. The trusted source may be a tax agency, police department, hospital or even a relative that you may have saved in your contacts. This tactic can create a sense of urgency to deceive individuals into sharing sensitive information or making payments.

For example, scammers have used Caller ID Spoofing to impersonate a police department calling about a family member needing a payment to be bailed out of jail. They can even make it look like the call is coming from a family member’s phone. Perhaps they call claiming the relative has been in a bad accident, and that they need information to give to the hospital or paramedics. Nowadays, it is very easy to find phone numbers associated with someone, especially with websites such as TruePeopleSearch, WhitePages, and 411.com.

To protect yourself from caller ID spoofing:

  • Be cautious when receiving calls from unfamiliar numbers.
  • If the call seems to come from a trusted source in your contacts and you feel as though something is off, ask if you can call them back after hanging up. By calling back the person in your contacts, the call will go to their number, not a spoofed one.
  • Avoid sharing personal information or financial details over the phone without verifying the caller’s identity independently.
  • Consider using apps or services that authenticate callers or display warnings for potential spoofed calls.

AI-Based VishingAs technology advances, so do the techniques employed by scammers. AI-based vishing, a sophisticated form of voice phishing, poses a significant threat in the digital landscape. By leveraging artificial intelligence technology, scammers are able to manipulate human-like voices to deceive unsuspecting individuals. With the ability to mimic accents, speech patterns, and emotions, scammers can create convincing scenarios that manipulate victims into divulging personal information, providing access to accounts, or initiating financial transactions.

This method of vishing typically triggers an emotional response in the victim, hijacking their power of reason. Combining the use of an AI-generated voice and a spoofed caller ID, an attacker could even pose as someone the victim may know very well. This has been used to convince a target that their family member or close friend may be in danger. Never underestimate the lengths a truly malicious actor may go to get what they want.

To protect yourself from AI-based vishing:

  • Remain vigilant and be aware that scammers can use AI technology to simulate human voices. Do not solely rely on the caller’s voice as a verification factor.
  • Verify the caller’s identity through independent means, such as contacting the organization directly. Avoid using the phone number provided by the caller as it may be part of the scam.
  • Always think critically before letting emotions take over. Often, AI-based vishing attacks will attempt to evoke an emotional response from us, especially if they are mimicking someone that we may know. Even in a time of a supposed crisis, take the time to think things through and act in a rational manner before giving up sensitive information.

The Bottom LineIndeed, vishing scams are not to be taken lightly. From robocalls to AI-based vishing, scammers have found effective avenues of successfully compromising their unsuspecting victims. Which is why knowing about the tactics they use and the avenues they take is so important. As times change, different kinds of malicious scams evolve. Awareness of these scams helps us to prepare before such an attack is launched against us, so we’re not caught off-guard. Remembering the steps we learned in this article will help us to stay vigilant, think critically, and avoid being duped by malicious actors.

Written by: Josten Peña

Images:
https://bestlifeonline.com/wp-content/uploads/sites/3/2022/09/automated-police-phone-call-scam-news.jpg?quality=82&strip=1&resize=640%2C360
https://image.cnbcfm.com/api/v1/image/102141273-450751107.jpg?v=1532564399&w=929&h=523&vtcrop=y
https://cdn.i-scmp.com/sites/default/files/d8/images/canvas/2023/05/03/a3f25503-0a23-4b5e-bd2d-59b2175335a6_2b927fe9.jpg

View Details

As a professional social engineer, it’s always interesting when I get asked, “What do you do for work?” When I […]

View Details

In 2021, AARP found that identify theft had affected more than 42 million U.S. consumers. This resulted in a loss […]

View Details

If you’ve read our past joint newsletter, you know that Curt and I (Shelby) approach vishing in a way that […]

View Details

Once upon a time, there was a young lady that worked as a receptionist for a prestigious hotel. She was […]

View Details

Over the span of 23 years and 44 seasons, the reality television show Survivor is perhaps one of the greatest […]

View Details

Two scammers are currently being prosecuted for deploying a romance scam against at least two victims, successfully stealing over £200,000. These criminals launched their attacks on Facebook and eventually worked up to asking their victims for money. They chose people whom they assumed would not come forward and report them. Fortunately, they were wrong.

Cybersecurity professionals talk a lot about malicious actors and the things that they do to leverage information against you. What’s discussed somewhat less is where the malicious actors gather this information. Social media is one of the biggest repositories of personally identifiable information (PII). In the example above, the attackers started on Facebook. They targeted single, older women who shared personal information online. Their story demonstrates how careful we need to be of what we share about ourselves online. Let’s look at a few popular social media platforms and discuss what things you should be cautious about sharing there.

FacebookIn the bio alone, Facebook has sections to share your hometown, current city, workplace, relationship status, hobbies, and more. Facebook can also show your family and friend connections. Of course, this is all before you share posts with photos. Be cautious when filling out your profile. Do people really need to know your hometown? Sharing that information is your right, but if you choose to do so be aware of how it could potentially be used against you. Keep in mind that Facebook changes their policies often. This means that things which were once private may no longer be private. So, your Facebook account will require ongoing security monitoring.

InstagramInstagram is one of the most famous photo sharing platforms currently. People often post pictures of their children, newly bought homes, and events they’ve attended. Sharing photos like these can be dangerous because it gives malicious actors a glimpse into your life, sometimes even identifying where you live and the places you frequent. Taking advantage of safety features such as making your profile private could be to your advantage.

LinkedInLinkedIn is one of the more popular social media platforms for professionals. You are almost expected to share your location, current and pasts jobs, and educational history. Before you fill out your profile, take a moment to imagine how malicious actors could use the information you are about to share. For example, if you share where you graduated from, a malicious actor could use that information to send you a targeted phishing email “from that school.” It’s up to you whether you share this information or not. The key is being aware of how it could be used against you and staying alert.

TikTokTik Tok is sweeping the world with dance videos, educational snippets, and more. Users of all ages share videos of themselves discussing their day to day lives, showing their homes, and their favorite things. According to Fox News, Tik Tok collects information like device location, calendars, and contacts. Be cautious when uploading videos of yourself that you don’t share too much information while following a seemingly innocent trend.

TwitterTwitter remains a popular social media platform for users of all backgrounds to connect with those they share interests with. It is common to post about events in your life, as well as put personal information, such as your birthday in your biography. Take a moment to consider what information you want to provide to strangers.

Remain SafeWith sharing personal information being the norm in our day and age, and so easy to do, how can you remain safe? To start, think “safety first” when posting or adding information to your account. Think about what other users can learn about you from the information you share. Try this: perform a google search of your name and see what information comes up. What accounts are connected with your name? What information can you collect about yourself? Ask yourself: How much of what I see am I comfortable with strangers knowing about me? Take advantage of sites security settings when using your accounts. Lock down the information you don’t want others having. Consider making your accounts private instead of public. Before accepting social media connection requests, validate the user’s authenticity. These are just a few tips to get you started on your security journey. Keep learning about online safety and sharing what you know with your friends and family. This way, we can all remain safe together.

Shelby Dacko

At Social Engineer LLC, our purpose is to bring education and awareness to all users of technology. For a detailed list of our services and how we can help you achieve your information/cybersecurity goals please visit:

https://www.Social-Engineer.com/Managed-Services/

Images:
https://designwizard.com/blog/types-of-social-media/
https://www.searchenginejournal.com/new-social-media-marketing-opportunities/394987/

View Details

Possibly one of the most concerning, yet common, phrases you could hear a leader say is, “if it ain’t broke don’t fix it.” On the surface this thinking makes sense, if something already works then why mess with it. But, if we go below surface level, what we are really seeing is change resistance. The problem here is that the cybersecurity landscape is dynamic and ever-changing, meaning that the nature of a potential threat will inevitably fluctuate and evolve over time.

Staying ahead of the latest security threat is likely to require a change in common business practices for all levels of the organization. This may be as simple as updating email reporting procedures, or as drastic as internal audits and the introduction of a new keycode or badge access system. These require committed and continued change to day-to-day workings and are often perceived as an unnecessary nuisance.

But, if you are not able to embrace the changes required to do so, you are not only going to be left behind as your competitors outgrow you, but you are also leaving the doors open for security breaches.

If adaptability is key, why are we so resistant to change?Human beings are comfort seekers. We like things that make us feel safe, and thus we like that which is familiar, because it is predictable. When acting habitually, we can be certain of the outcome because we can predict it based on previous experience, but change requires some level of uncertainty. Subsequently, “human beings are creatures of habit” because familiarity is safe whilst change is risky.

When we think about this from an evolutionary perspective, it makes perfect sense. Erring on the side of caution would be beneficial for survival because it would facilitate the avoidance of potential threats. If such is the case, the inclination to avoid uncertainty would be passed down via our genes and we would expect to see a biological marker of stress when faced with uncertainty. This is in fact exactly what researchers have found. Such that, the stress response (commonly known as the fight or flight response) is the default response to uncertainty, which is reflected physiologically in high vagally mediated heart rate variability. Subsequently, this leads to difficulties with emotional regulation. Thus, it’s not just that we prefer familiarity, but that we are hardwired to avoid uncertainty and change.

The concept of change itself can also be problematic for growth because change is typically associated with something being broken or poorly maintained. I am sure all of us at some point have said to ourselves, or to someone close to us, “this is not working; something has to change.” Therefore, it is understandable that the idea of change might be met with an emotionally charged reaction.

Making changesWhen it comes to cybersecurity, change is inevitable. You may have the most up-to date systems and policies around, but all it takes is one attacker to come out with a new exploit and those systems may no longer be secure. Additionally, human beings are the biggest risk to security and each individual comes with their own unique set of vulnerabilities. This means that as your workforce evolves and changes, so do your security risk factors.
Try to slowly introduce appropriate changes to give yourself and your team time to adjust to each change before implementing stricter measure. However, sometimes this is just not a possibility.

If the thought of adapting your systems and protocols seems daunting, I hope it is somewhat comforting to know that it’s not just you. Change IS daunting. But there is no way to sugar coat it, if you want to keep your company secure, sometimes change cannot be avoided. As a leader, it is your duty to self-reflect, and if you recognize change resistance in yourself it might be time to adjust your behaviour.

This is a good time to stop and think about the last time you updated your security measures.

The experts at Social-Engineer can helpDon’t know where to start? The experts at Social-Engineer, LLC can help you understand where your security may be falling short and support you on your journey to change your resistance.

For a detailed list of our services and how we can help you achieve your information/cybersecurity goals please visit:

https://www.Social-Engineer.com/Managed-Services/.

Written by: Dr. Abbie Maroño

References

Brosschot, J. F., Verkuil, B., & Thayer, J. F. (2016). The default response to uncertainty and the importance of perceived safety in anxiety and stress: An evolution-theoretical perspective. Journal of Anxiety Disorders, 41, 22-34.

Carleton, R. N. (2016). Fear of the unknown: One fear to rule them all?. Journal of anxiety disorders, 41, 5-21.

View Details

Social engineering and collections may seem like two vastly different professions. However, they share many similarities when it comes to using influence tactics to achieve their respective goals. Before my work as a Human Risk Analyst for Social-Engineer, I had previously worked in this field of collections. This involved talking to people on the phone and collecting past due payments on retail credit cards. Looking back on my previous occupation, I can see first-hand just how similar these two jobs of mine are! Especially when it comes to the influence tactics used in both professions on a daily basis. In this blog, we will explore three of those common influence tactics and how they apply to both social engineering and collections.

ConcessionConcession is the act of making a compromise or giving something up to the other party. It typically begins by making an initial request or demand that is intentionally high or unrealistic. When the initial request is rejected, a smaller, more reasonable request is made.

A social engineer may use this influence tactic to gain the trust of their target and influence them to divulge sensitive information. As an example, after building rapport, a social engineer may start by asking for highly sensitive data like login credentials with the knowledge that the request will likely be denied by their target. Then, the social engineer can “compromise” and follow up with a request for less sensitive information, such as their target’s email address or phone number. The target may now be more inclined to comply since they feel the caller addressed their needs and is looking out for their interests.

Similarly, in collections, a collector may use concession to negotiate payment terms with someone that is resistant to making payments. For example, a collections agent may initially request that the debtor pay the full amount or past due balance immediately. If the debtor refuses as the collector expects, they can then follow up with a more reasonable payment plan to resolve their debt. This type of concession helps the debtor feel as though they have gained a small victory and may be more willing to comply with the collection’s agent further.

LikingThis influence tactic is the concept that people are more likely to comply with requests from someone they like or are moved to like. This can come about by way of liking what is familiar to them, positive reinforcement, or appreciation. A social engineer may use liking to build rapport with the target and gain their trust. For example, they might use small talk to find common ground with the target, such as shared interests or hobbies. They could crack jokes and try to get their target to laugh, dropping their defenses. Once a positive relationship is established, a social engineer can use this to influence their target to provide sensitive information, or grant access to a secure area.

In collections, this technique is also used to build a positive relationship with the debtor with the goal of increasing the chance of collecting a payment. From my personal experience this may be difficult at times, as many might not exactly want you to be their best friend. Throughout the call though, a collector may also try and build rapport by creating small talk or finding common ground. However, an even more effective way is by truly listening to the debtor and acknowledging their current situation. Making sure they feel heard is a great form of Liking. The collector may then use this rapport to negotiate a payment plan or convince the debtor to make a partial payment.

Social ProofSocial proof is based off the idea that people are more likely to follow the actions of others, especially those they perceive as similar or authoritative. The bandwagon effect of “everyone else is doing it” is a very effective way a social engineer can influence someone to take a specific action or make a decision. For example, a social engineer might use social proof to convince their target that they are calling from their IT (Information Technology) Department, changing out login credentials as they’ve done with “the rest of the staff.” By making it seem like everyone else has already complied, and by posing as an authority figure, the target may feel obligated to share sensitive information.

In collections, the debtor already knows that you are essentially an “authority figure” of sorts, in that you represent a company asking for their money back. To use social proof effectively here, a collector might use this tactic to highlight effective payment plans that have worked for others or testimonials from satisfied customers. They may even highlight the number of people who have been in a similar position, and how they were able to resolve their debts with the collection agency’s help. By demonstrating that others have already taken the desired action, the collections agent can leverage the power of social proof to persuade the debtor to pay their debts as well.

ConclusionAs we noted in the above tactics of Concession, Liking, and Social Proof, the common overlap found in both Social Engineering and Collections is in building trust with the other party. If we can establish enough rapport, it increases the likelihood of a positive result for the social engineer or collections agent. By understanding these influence tactics, professionals in both fields can become even more effective in their work. In fact, many other professions can use these techniques as well.

However, it is important to note that these tactics should always be used in an ethical manner and with the utmost respect for the other party, regardless of profession. The influence tactics used in both social engineering and collections can have the potential to do harm, if they are not used ethically. So, it is crucial that practitioners in both of these fields prioritize the well-being of their targets or debtors above all else.

Josten Peña

At Social Engineer LLC, our purpose is to bring education and awareness to all users of technology. For a detailed list of our services and how we can help you achieve your information/cybersecurity goals please visit:

https://www.Social-Engineer.com/Managed-Services/

Images:
https://nexrep.com/wp-content/uploads/2020/03/tips-for-customer-service-agents.jpg
https://www.callcentrehelper.com/images/stories/2019/09/smiling-on-phone-with-coffee-760.jpg
https://localiq.com/wp-content/uploads/2019/03/social-proof-what-is-social-proof.jpg

View Details

When I first started in the social engineering field, I had no idea how much it would impact my everyday life. Namely, my communication skills. What exactly is social engineering? How does it change my day to day? And how can you benefit from the same techniques I’ve learned in your own life? Let’s dive in together.

Social Engineering: What is it?What is social engineering? We define it this way “Any act that influences a person to take an action that may or may not be in their best interest.” Like most things, it can be used for good or bad. Today we will discuss how to use social engineering techniques for good in your everyday life.

Why Should I Care About Social Engineering?When used for good, social engineering can have profound effects on your communication skills and your relationships. How so? Many of the techniques we use in social engineering are used to build up common interests and trust, both of which are vital to building rapport and thriving relationships. So, what are some of these techniques?

Social Engineering TechniquesLet’s discuss three social engineering techniques that stand out to me:

  • Ego suspension
  • Quid Pro Quo
  • Validating Others

Ego suspensionA reliable human trait is that people like to be right. One technique you can use for helping someone to be more open to your requests is to suspend your own ego, so they do not view you as a threat to theirs. This could mean anything from not correcting someone to not proceeding to share your own “greater” knowledge. This is arguably one of the hardest techniques to put into practice. We naturally like being right and sharing our knowledge with others. And ego suspension doesn’t mean always being wrong or not sharing your knowledge, it just means greater awareness of when it is appropriate to do so.

Have you ever been in a discussion where someone keeps correcting you, even if you’re just sharing an opinion? How did it make you feel? Likely, you felt annoyed and maybe even slightly defeated. We surely don’t want to make others feel that way. I have noticed that when I implement ego suspension, even when difficult, my interactions with people go more smoothly.

Quid Pro QuoQuid Pro Quo is Latin for “something for something.” It means you give a little to get something back. Think of throwing a ball back in forth. Each time it exchanges hands, a little information is given. Another way to picture it is by imagining the feeling of buyer’s remorse.

I recently attempted to save money on my hair appointment by cancelling it and ordering a color depositing conditioner. I ended up using it incorrectly and dyeing my hair the completely wrong color! Now I not only have to go back to my stylist but am stuck with this conditioner that I will never use again. Buyer’s remorse! You can make the person you’re talking to feel that same way if you end the conversation and they know nothing about you. This doesn’t mean you have to tell them your life story. Rather, think about what you want to know and offer them something of equal value. For example, if you want to learn someone’s middle name, offer them yours first, and so on.

Validating OthersYou may be wondering how validation is a social engineering technique. Think through the effects of validation, though. If you make someone feel heard, seen, understood, they are going to trust you more.

Just the other day I made a vishing call where the lady I was speaking to was frustrated about some computer issues. As I was pretexting that I was calling from her IT department, I was supposed to be able to help her fix these issues. In reality, I know nothing about IT work. So instead, I apologized for her trouble and told her how frustrating I know it must be. She responded so well to this that she didn’t even mind I didn’t know how to fix her computer! I was able to gain her trust to the point where it made her feel better for having talked to me. In my everyday life I enjoy using this technique for one simple reason: I like to feel validated as well. When used with good intent, validation will only yield positive results.

Why Use These TechniquesWhy should we make the effort to utilize these techniques? They all have one thing in common; they help ensure the person we are speaking to feels good. That’s a powerful thing! Using these techniques intentionally at first will help you to put them into practice. Eventually, it will become your natural way of conversing. If we all focus on suspending our egos, quid pro quo, and validating others, communications all around would improve. Let’s be a part of that.

Written by: Shelby Dacko

At Social Engineer LLC, our purpose is to bring education and awareness to all users of technology. For a detailed list of our services and how we can help you achieve your information/cybersecurity goals please visit:

https://www.Social-Engineer.com/Managed-Services/.

Images:
https://cxm.co.uk/communication-with-customers-five-essential-factors/
https://www.alltekholdings.com/communicate-consistently-with-customers-about-their-technology-needs-and-your-value/

View Details

What does a government scam, an IT support scam and a romance scam have in common? They all use psychology and social engineering skills to convince their victims to take an action that is detrimental to them. It’s easy to think “I know better” or “that will never happen to me.” The truth is, being human is enough for anyone to fall victim to a scammer’s tactics. One way to mitigate the effect of such tactics is by being aware of the techniques that scammers use. Let’s see what lessons we can learn from scam artists to better protect ourselves.

ImpersonationFrank Abagnale is widely recognized as the best con artist in American history. According to him, one of the ways he could successfully con people was through impersonation. In his book “The Art of the Steal” Frank Abagnale said: “Hotel clerks and merchants didn’t question pilots and doctors too closely.” He soon realized that when he impersonated doctors and pilots, people viewed him as someone with authority and would rarely question him if at all. This enabled him to cash nearly $2.5 million worth of checks. Con artists play on our own unconscious bias that people in authority are trustworthy.

Thanks to technology and social media, impersonation scams have grown exponentially. Impersonators create fake social media accounts that include the names, images, logos, or other identifying information, of a person, brand, or organization. This is one of the easiest forms of impersonation for scammers, which explains the drastic increase in the number of fake social media accounts. Facebook alone removed nearly 1.8 billion fake accounts in 2021. Impersonation is often used in phishing, SMiShing, and vishing. This means that most of us have already been exposed to impersonators via one of these methods.

UrgencyYou’re done with your workday, about to log off. But at that very moment your boss emails you telling you to buy some Apple gift cards from a nearby store for a presentation they have. At first glance the email looks legit, but then you stop and realize he’s asking you to do something unusual. You realize the email is a scam. This scenario illustrates how scammers use urgency to trick people into giving them money or personal information. They may claim that you need to act immediately to collect a prize, pay a bill, or protect your identity. They may also say that there is only limited time to take advantage of a special offer. These tactics can be very effective in pressuring people into making a decision before they have time to think or verify if the offer is legitimate.

Prey on EmotionsScammers have become experts in using social engineering techniques to their advantage. While not all social engineering is bad, scammers specialize in triggering emotions to exploit our weaknesses. They use emotions such as fear, curiosity, and greed, in order to get people to comply with their demands. At times, they may use sympathy and claim that they need money for an emergency situation. In other cases, they may appeal to your sense of generosity or kindness asking for donations for a good cause.

Lessons LearnedWe can learn much by getting to know the tactics of our impostors. Some of the tactics they use include impersonation, creating a sense of urgency, and manipulating our feelings. Knowledge is power. Staying up to date regarding these attacks will increase our awareness and help to avoid falling victim to them. The Federal Trade Commission gives the following tips to avoid falling victim to scammers:

  1. They PRETEND to be from an organization you know.Scammers often pretend to be contacting you on behalf of the government. They might use a real name, like the Social Security Administration, the IRS, or Medicare, or make up a name that sounds official. Some pretend to be from a business you know, like a utility company, a tech company, or even a charity asking for donations.

They use technology to change the phone number that appears on your caller ID. So the name and number you see might not be real.

  1. Scammers say there’s a PROBLEM or a PRIZE.They might say you’re in trouble with the government. They may also say you owe money, or that someone in your family had an emergency, or that there’s a virus on your computer.

Some scammers say there’s a problem with one of your accounts and that you need to verify some information.

  1. They PRESSURE you to act immediately.Scammers want you to act before you have time to think. If you’re on the phone, they might tell you not to hang up so you can’t check out their story. They might threaten to arrest you, sue you, take away your driver’s or business license, or deport you. They might say your computer is about to be corrupted.

  2. Scammers tell you to PAY in a specific way.They often insist that you pay by using cryptocurrency, by wiring money through a company like MoneyGram or Western Union, or by putting money on a gift card and then giving them the number on the back.

The More You KnowThe goal of a criminal is to keep you from thinking critically. They generally do this by targeting emotions, as discussed above. Because of this, the most powerful weapon against social engineering attacks is critical thinking. Given the emotional nature of these attacks, there may not be a specific tool or process that can prevent us from falling victim to human vulnerability. However, being aware of such vulnerability enables you to pause and think of the request. Ask yourself, is this request reasonable? Why are they asking this of me? Should I do this?

Corporations and individuals are becoming more aware of social engineering attacks and are looking for ways to protect themselves. One way to do this is by learning as much as possible about the tactics that malicious actors use, as well as implementing best security practices. Whether you want to protect yourself against social engineering attacks or learn more about human behavior, the Foundational Application of Social Engineering class is a 4-day immersive course that specializes in the field of social engineering offering practical exercises which provide a lasting learning experience.

Rosa Rowles

At Social-Engineer LLC, our purpose is to bring education and awareness to all users of technology. For a detailed list of our services and how we can help you achieve your information/cybersecurity goals please visit:

https://www.Social-Engineer.com/Managed-Services/.

View Details

People in many different professions use social engineering as a tool in everyday life. In the case of sales, social engineering plays a significant role in persuading potential customers to buy a product or service. This is done using a social engineering technique known as Influence Tactics. These tactics build trust, establish a connection, and provide value, to the customer or client. In this article, we will consider some of these tactics.

Liking TechniqueThis technique involves the salesperson building a relationship with the potential customer by creating a friendly and warm atmosphere. People like what is familiar to them. So, an effective salesperson actively listens to their customers and validates their feelings. They find common ground to connect with them on any level they can. For example, even things as little as a shared shoe brand or favorite coffee can bridge the gap. A salesperson may even offer innocent compliments to the customer themselves or about the company to keep them engaged and provide positive reinforcement. By doing so they create a sense of familiarity. The customer feels like they are talking to a friend, not just an employee or rep. As a result, the salesperson gains the customer’s trust, making it more likely that they will make a purchase or seal the deal.

Scarcity TacticsThis is an all-time classic when it comes to sales techniques. Scarcity tactics create a sense of urgency around a product or service, making it more appealing to the potential customer. This is done by highlighting the limited availability of the product using artificial time constraints, and how much time is left to take advantage of a promotion or offer. Doing so emphasizes the exclusivity of the product. This technique creates a sense of FOMO (fear of missing out) in the customer. Which in turn increases their likelihood of making a purchase.

Authority TacticsThis technique involves the salesperson presenting themselves as an expert. They may explain how long they have been in the business field, display certifications to show their experience, or prove their familiarity with the product. This is done to gain the customer’s trust and make them more likely to make a purchase. Of course, the salesperson may indeed be an expert with knowledge about a product. However, in a competitive environment, the salesperson uses authority to help them stand out from the rest. This makes the customer believe that they are the ”go-to person” for all their needs. A salesperson can also use authority to bolster the credibility of the company she or he works for. For example, giving reasons why they are the “leaders in the industry.”

A Good Salesperson has a Pretext!Pretexting is used in multiple professions such as public speaking, lawyers, etc. Pretexting is especially helpful in the world of sales. Regardless of the profession though, pretexting requires research and good information gathering techniques. A salesperson may gather information on competitors such as price points. They may also gather information on the client or their business that they are selling to. This information helps the salesperson decide what they will say, and how they will say it. It also helps them to plan out their influence techniques wisely, and the best course of action to get their customer to seal the deal. A good pretext is also an essential part of building trust.

Sales with EthicsIt is important to note that salespeople should use these tactics ethically while making deals. In fact, we do well to remember that the tactics we just discussed are Influence techniques, NOT Manipulation. An ethical salesperson will never use these tactics to make a customer feel uncomfortable or threatened…even if it means a “more successful” outcome. If you leave your potential customer or client feeling worse for having met you, they may leave negative reviews, or not sign on or re-sign, if they’ve been tricked initially.

Our motto at Social-Engineer LLC is “Leave them feeling better for having met you.” Regardless of what role social engineering plays in your profession, it is important to stay true to a code of ethics however we choose to use it. In the sales world, the best outcome is when both the salesperson and the customer benefit.

At Social Engineer LLC, our purpose is to bring education and awareness to all users of technology. For a detailed list of our services and how we can help you achieve your information/cybersecurity goals please visit:

https://www.Social-Engineer.com/Managed-Services/.

Written by: Josten Peña

Images:
https://c.pxhere.com/images/08/ee/f999a260bbe146f92b07c6123f3d-1456393.jpg!s2
https://blog.hubspot.com/hubfs/scarcity-principle.jpg
https://www.journalofsalestransformation.com/wp-content/uploads/ethics.png

View Details

If you google the definition for social engineering, you’ll probably find something like “the use of deception to manipulate individuals into divulging confidential or personal information that may be used for fraudulent purposes.” While it’s true that social engineering is used to manipulate people, it can also be used to motivate people. At SECOM we define social engineering as “the act of influencing someone to take an action that may or may not be in their best interest.” For example, by using social engineering principles such as reframing, commitment, and authority, a high school counselor can influence a student to improve their grades and thus have a better chance of attending college.

Social engineering is about influencing others, but what if I told you that you can social engineer yourself? Let me share with you some ways that I’ve used social engineering on myself and how it has benefitted me.

Know ThyselfThe first thing I learned when I attended the Advanced Practical Social Engineering course (APSE) was identifying my communication style. In class I took the DISC assessment. DISC is an acronym that stands for the four main personality profiles described in the DISC model: (D)ominance, (I)nfluence, (S)teadiness and (C)onscientiousness. It is not a personality test, rather it’s an assessment to discern your predominant way of communicating. Some may be short and direct communicators whereas others will include many details in their explanation. There is no superior or inferior communication style. However, a very direct communicator may find details annoying. On the other hand, a person that needs details to make a decision may find a direct way of communication abrasive.

In social engineering adapting the way we communicate with others is crucial. During an engagement when we can quickly assess the communication style of our target, we have a much better chance of success by adapting how we communicate with them. We can apply the same principle in our personal lives. Have you found yourself arguing with your significant other, just to realize you were both saying the same thing all along? Being self-aware of our communication style and that of the other person can help us reduce conflict and improve relationships, both professional and personal.

PretextingAs social engineers we use pretexts in our everyday work. In essence, a pretext is a simple but believable story that we create to influence the target’s behavior. For example, during a vishing campaign I will call employees pretending to be from their IT department seeking to confirm information about their computers. I adjust my pretext and the way I speak to play the role of the IT specialist and sound as realistic as possible. However, I am not the most technically savvy person. So, believing the pretext myself conveys the needed trust in order to succeed with the vishing calls.

I have found myself creating pretexts in my mind to help me accomplish personal goals or to behave in a desired manner to fit a situation. There was an instance where I was asked to be part of a video shoot for an upcoming company project. This involved reading a teleprompter and appearing natural and at ease in front of professional cameras and blinding lights. To make matters worse, the whole production would take place with my peers. As an introvert, I found the whole ordeal very intimidating. Then it occurred to me: “If I can become another person during my vishing calls using a pretext, could I do the same now?” So, I created a story (or pretext) for myself that I was an experienced news anchor for the day. This gave me the motivation to complete my part of the project with confidence.

Nonverbals
A large portion of our communication is not conveyed with words, but through our nonverbal communications. In the book Emotions Revealed, Dr. Ekman explains that we can convey emotions such as anger, fear, disgust, sadness, and happiness, just by how they show across our faces. This not only provides signals for others to identify our feelings, but it can also alter the emotions of the other person. Social engineers must become masters at understanding, reading, and influencing, people. During an in-person engagement a colleague spilled coffee on his shirt and resume, then walked into the office building with a sad look of disappointment. He then told the receptionist how important this job interview was and asked if he could hand her his flash drive so she could print a copy of his resume. The receptionist moved with pity complied. The SE accomplished the goal of exploiting human vulnerability.

Try a SmileIf we can affect the feelings of others by using our nonverbals, could we change the way we feel by changing our facial expressions? A recent study published in the journal Experimental Psychology, states that smiling (even a fake smile) can have a positive impact on mood. We trigger certain facial muscles by smiling and can “trick” our brain into thinking we’re happy. It may seem silly to just smile at yourself by yourself with no apparent reason. Instead, try thinking of something that can evoke a true smile. It’s surprising how well it works.

Power PosesAnother way we can use nonverbals to our advantage is by our posture. Amy Cuddy became well known for a 2010 study about the effects of “power poses.” The study found that by posing, standing, or sitting in certain positions — legs astride, or feet up on a desk — subjects experienced stronger “feelings of power” than they did before.

I was somewhat skeptical that the way I stand (or sit) can change how I feel, until I put it to the test. My natural disposition in social events used to be sitting with my arms crossed and shoulders down, so as to not draw attention to myself. Although this felt comfortable, I did not benefit from having meaningful conversations with others. I started to become self-aware during social interactions and would adjust my posture; standing tall, shoulders straight (maybe a hand on my hip) and a smile. I must admit, it did not feel natural at the time but the more I practiced this, the more confident and comfortable I was making conversations with new people.

Continue to Learn, Continue to GrowSocial engineering is deeply rooted in psychology. The more we can understand our psychology and that of others, the more we can grow as professionals as well as individuals. For the sake of time this article considers just three aspects of social engineering that we can self-apply, however there are so many more. If you are interested in learning more about how social engineering can help improve your life, you may want to consider attending our Foundational Application of Social Engineering course. This course delves deep into subjects such as communications profiling, rapport, elicitation, and influence. Make it a goal to continue to learn and continue to grow.

Written by: Rosa Rowles

Images:
https://www.vox.com/2015/4/3/11561116/whats-your-biggest-it-security-risk-look-in-the-mirror
https://sourceessay.com/types-of-nonverbal-communication-social-psychology/

View Details

Painted hearts on restaurant doors, red roses in hand, candies and chocolates on display. These are just some of the signs that the month of love is coming upon us again. As February approaches, many are excited for what it promises; romance. Among hopefuls searching for a true connection though, are those who take advantage of our need for human interaction, namely scammers. Millions each year use dating apps to meet new people. Unfortunately, malicious parties exist who leverage our innate need for human connection to their advantage, leaving many disappointed and with less money in their wallets than before. We call what these criminals do “romance scams.” What exactly are romance scams? How can we identify and avoid them? Let’s find out.

Leveraging Affection and TrustThe Federal Bureau of Investigation (FBI) states that “romance scams occur when a criminal adopts a fake online identity to gain a victim’s affection and trust.” The malicious actor then uses the victim’s affection and trust to steal money from them. Many times, the victim isn’t even aware that this is happening. For example, imagine you have been talking online to someone for months. At this point you feel like you know them. Then they tell you their sister was in a horrible accident and needs help with her medical bills. You kindly offer to assist and send them some money for their sister. No doubt this was a kind and loving act on your part, but this person has just successfully obtained money from you for whatever purpose they desire. This is not to say that all online interactions go this way or are malicious. So, what are the telltale signs of romance scams in particular? And how can you avoid them?’

Things to Watch Out ForScammers will not meet you in person. They will come up with many reasons for this. Perhaps they are in the army, traveling overseas, or working with an international organization. Go slowly and keep in mind that if you have not met someone in person, you have reason to be wary.

They will ask you for money. Beware of anyone you haven’t met in person asking you for money. They could request finances for things like:

  • Plane tickets to visit you
  • Family or personal emergencies
  • Gambling debts
  • Medical expenses

The timeline for these requests could be days, months, or even years. If it’s a scam, though, the request will come.

They ask for specific payment methods. Some common and hard to track methods of payment include:

  • Wire transfers
  • Gift cards

If your online interest asks for money, especially using difficult to trace methods such as the two above, take this as a sign of a scam and do not send anything to them.

How to Protect Yourself from Romance ScamsNow that you know some of the signs of romance scams, here are some tips from the FBI to protect yourself from them in the future:

    • Be careful what you post and make public online. Scammers can use details shared on social media and dating sites to better understand and target you.
    • Research the person’s photo and profile using online searches to see if the image, name, or details have been used elsewhere.
    • Go slowly and ask lots of questions.
    • Beware if the individual seems too perfect or quickly asks you to leave a dating service or social media site to communicate directly.
    • Beware if the individual attempts to isolate you from friends and family or requests inappropriate photos or financial information that could later be used to extort you.
    • Beware if the individual promises to meet in person but then always comes up with an excuse why he or she can’t. If you haven’t met the person after a few months, for whatever reason, you have good reason to be suspicious.
    • Never send money to anyone you have only communicated with online or by phone.

Stay SafeThis February and all the months to follow, keep your eyes peeled for the signs of a scam we have discussed today. By doing that and following the FBI’s tips to protect yourself from these romance scams, you will be sure to keep your heart, and your wallet, safe.

Shelby Dacko

At Social Engineer LLC, our purpose is to bring education and awareness to all users of technology. For a detailed list of our services and how we can help you achieve your information/cybersecurity goals please visit:

https://www.Social-Engineer.com/Managed-Services/

Images:
https://feedzai.com/blog/romance-scams/
https://corridorbusiness.com/consumer-connection-romance-scams/

View Details

Not too long ago, many of us thought that cybersecurity was something for corporations to worry about. Perhaps we thought, who would want to hack a completely unknow person like me? The truth is technology has grown at an exponential rate and so has cybercrime. Cybercrime doesn’t just affect big businesses and national governments. Cybercriminals target individuals just as relentlessly as they do large companies and organizations. What are some personal cybersecurity concerns for 2023? And what are some ways we can protect ourselves?

The Internet of ThingsIt sounds like the title of a sci-fi novel, but it’s very much a reality. IBM describes the internet of things (IoT) as the “the concept of connecting any device … to the Internet and to other connected devices.” It is “a giant network of connected things and people – all of which collect and share data about the way they are used and about the environment around them.” Basically, the IoT encompasses anything from smart microwaves and fridges to self-driving cars and fitness devices (to name a few).

The expanse of the IoT has permeated every aspect of society. Because these devices are not often used to store sensitive data, IoT devices hardly have any inbuilt security. However, even if they are not used to store data, attackers will often use them as ways to access other networked devices. IoT devices have made our lives convenient, and we use them daily without much thought. We can benefit from these the most if we are aware of the possible risks and take measures to use them wisely.

Impersonation ScamsCybercriminals usually impersonate well-known businesses or organizations. These range from simple to sophisticated scams to convince you they are genuine, in hopes that you feel comfortable sharing personal or financial information whether on the phone, via email, or text. Business email compromise (BEC) attacks have been predicted to soar in 2023 according to Forbes Advisor.

BEC attacks tend to have a high success rate since they involve spoofed emails that look like they’re coming from a trusted source such as a company executive, employee, or vendor. Scammers use authority and urgency to get their victims to suspend their critical thinking and act quickly. Although BEC attacks may be targeted at business, they can also be used to scam individual people. For example, an email that seems to come from your boss asking you to urgently review a document before a meeting, or to provide some personal information, can easily catch us unaware.

‘Pig Butchering’No, cybercriminals have not taken to hurting pigs as a hobby (that we know of). ‘Pig Butchering’ in this sense refers to a crypto scam where the scammers message someone’s phone, usually via WhatsApp. The message will initially say something like: “Hey, are we still on for lunch on Friday?” The objective is to get a response and build a friendship online. At a later point, they will ask the victim if they know anything about crypto. With promises of making a lot of money fast, they will lure the victim to a sham website. Once the victim invests, they will keep pressuring them to pour in more money. This is how the scammers “fatten the pig” until the right time to “butcher it,” when they take all the money out of the account.

What You Can DoWe have considered just a few of the most relevant personal cyber security concerns. The rate of growth and evolution of new scams is unpredictable, and there’s no method that will keep you 100% safe from these attacks. However, there are some things you can do to mitigate many of these potential threats. The Cybersecurity & Infrastructure Security Agency, lists the following 4 steps to protect yourself:

    • Implement multi-factor authentication on your accounts and make it significantly less likely you’ll get hacked.
    • Update your software. Turn on automatic updates.
    • Think before you click. More than 90% of successful cyber-attacks start with a phishing email.
    • Use strong passwords, and ideally a password manager to generate and store unique passwords.

Most if not, all social engineering attacks will attempt to trigger some emotion such as urgency, fear, greed, or curiosity. Criminals want to suspend your critical thinking so that you will take an action that you normally would not. Remember, between stimulus and response, you have the freedom to choose which action to take. So, if some messaging produces an emotional response remember to stop and take a minute to think about the request before taking any action.

Stay educated, implement security recommendations, stay safe.

Rosa Rowles

At Social-Engineer LLC, our purpose is to bring education and awareness to all users of technology. For a detailed list of our services and how we can help you achieve your information/cybersecurity goals please visit:

https://www.Social-Engineer.com/Managed-Services/.

View Details

Social engineering has become a larger threat to the healthcare industry in recent years. So much so that the Federal Bureau of Investigation (FBI) has taken note. In a 2022 report they state that they have “received multiple reports of cyber criminals increasingly targeting healthcare payment processors to redirect victim payments.” In one case, $3.1 million was redirected from victims’ payments. Clearly, we need to take notice of how social engineering attacks are targeting our vital healthcare systems. So, what exactly is social engineering? How does it affect healthcare? Why should we be concerned? Let’s dive into each of these questions in today’s newsletter.

What is Social Engineering?We define social engineering as “Any act that influences a person to take an action that may or may not be in their best interest.” Like many things, social engineering is something that can be used for good or bad. Unfortunately, we see many malicious actors taking advantage of social engineering techniques via SMiShing, Phishing, Vishing, and Impersonation attacks. According to Carahsoft’s 2021 HIMSS Healthcare Cybersecurity Survey, phishing attacks were the most common threat to healthcare systems, accounting for 45% of security incidents.

Why is the Healthcare Industry at Risk?As we saw at the start of this article, the payoff for malicious attackers is potentially huge. There is a plethora of personal information available to successful malicious attackers, including (but not limited to) credit card information and social security numbers. This is one of the reasons why the healthcare industry is at such a high risk for social engineering attacks. According to the Office of Information Security, the following 5 reasons are why healthcare workers are at risk:

  • People are naturally trusting
  • People have a desire to help
  • Some people take short cuts
  • People do not want to get in trouble
  • People want to look intelligent

Interestingly, some of those facts are admirable traits. Malicious attackers are not above leveraging these traits to their advantage. This is especially true during times of crisis, such as with the COVID-19 pandemic. Reports say there was a 6000% increase in phishing attacks during this time, with healthcare establishments often being the target.

How Can the Healthcare Industry Become More Secure?There are many things that the healthcare industry can do to become more secure. Enabling and enforcing multifactor authentication on all logins and implementing anti-virus and anti-malware services are all great places to start. However, arguably the most important step that healthcare facilities can take is to ensure that their employees are properly trained. The FBI recommends that these businesses “implement training for employees on how to identify and report phishing, social engineering, and spoofing attempts.”

Engaging social engineering training is a must. Having simulated social engineering tests is the best way to get your employees used to the various tactics that malicious social engineers may use. It is important to keep this training positive and ethical. For example, when we train people in phishing at Social-Engineer, we will usually test the employee. Then if they clicked a link, we let them know it was a phishing test. We will then point out where the signs of phishing were and how to properly report suspected phishing emails in their organization. Testing in this way is vitally important. You want your employees to feel secure reporting any potential threats to your company. With our healthcare systems increasingly under attack, we need to work together to increase security measures.

For a detailed list of our services and how we can work with you to achieve your cybersecurity goals please visit:

https://www.Social-Engineer.com/Managed-Services/

Written by Shelby Dacko

Images
https://www.getfoundquick.com/healthcare-providers-should-leverage-new-covid-19-google-my-business-tools/
https://techcrunch.com/2020/09/15/replace-legacy-healthcare-staffing-with-a-vertical-marketplace-for-workers/

View Details

As 2022 comes to a close, stress can be at an all-time high. This time of year, many have planned holiday vacation time, relatives may be coming in from out of town, or there may be end-of-year time crunches at work. Due to these stressors, we may become lax in our judgement when it comes to how we view security. However, we must be wary of scammers during the holiday season and not let our guard down. These conditions are the perfect storm for malicious actors. In 2021, the FBI and CISA saw an increase in highly impactful ransomware attacks occurring on holidays and weekends. We should not expect things to be any different at the end of this year either.

In October, Cybersecurity Awareness Month taught us the importance of safe practices such as the use of multifactor authentication, strong passwords, and VPNs. Even though that month has since passed, the holiday season is perhaps one of the most crucial times to keep those same practices at the forefront of our mind, along with other useful tips to keep ourselves safe. Let us consider a few of them.

Caution on VacationMany find themselves travelling during this time of the year. We may be very excited to finally get some time off after a very busy twelve months. However, never let yourself become too comfortable when letting people know that you’re away! One instance to be careful of is when posting on social media. If we were to post too much about going on holiday mentioning dates away, destinations, etc., we could run the risk of being targeted by a malicious actor. How so? They could pose as your hotel or airline by sending you convincing phishing emails. Or even worse, plan out when you will be away so as to gain access to your personal estate.

When on vacation, the last thing you want to worry about is work emails, right? You may set up “Out of Office” automatic replies to let people know you are not available, and to reach out to someone else. Though these may be useful, they may be more of a security risk if they are not worded properly. It is recommended that “Out of Office” replies should NOT include the following:

  • Specific dates of your vacation (e.g., December 23-27)
  • Corporate information you would normally include on a regular email (e.g., job title, company roles, chain of command details, etc.)
  • Personal contact information such as a cell number

What would happen if an employee were to include all this information in their “out of office” automatic replies? A malicious actor could use this information to impersonate the employee while they are away! An attacker can easily find these types of automatic replies by means of mass phishing campaigns.

Deals and PromotionsThis time of year also brings a surge of promotional scams. With the increase of malware related scams mentioned at the outset, it is important to be on guard when searching through our inbox. Scammers may include details about “jaw-dropping” holiday discounts to entice their victims. These may come in the form of phishing emails, text messages or advertisements while online shopping. Also, beware of fake in-app purchases or shared links on social media.

ALWAYS be wary of any links found in emails or text messages from unknown or unexpected senders. The link may have misspellings of a brand or have nontraditional characters embedded in it. If it is believed to lead to a reputable website, visit the site directly yourself instead of using the link. You can also try using free link checkers on the web to see if it is in fact malicious.

When deals seem too good to be true, it’s likely because they are. If you’re not sure whether an offer or deal is legitimate or not, always search and fact check first before taking any action. Always make sure you are shopping on the correct website as well. If you mistype a website by accident, there may be a scam website deliberately misspelled to catch accidental web traffic.

Beware of Delivery Scams! With the increased traffic of online shopping and package shipping, scammers are given another avenue to take advantage of. They may send out phishing emails and texts disguised as reputable companies like UPS, FedEx or Amazon. The message may claim to be a notification about incoming or missed deliveries. However, links attached to the phony messages may lead to sign-in pages asking for personal information or may be infested with malware.

Fake CharitiesScammers will exploit any possible situation and circumstance. They do not “play nice” or fair, regardless of what time of year it is. December is the most popular month for charitable giving. Scammers are aware of this and take advantage of it by creating fake charities, GoFundMe campaigns, and other charitable activities. These types of scams may also use current events, such as the war in Ukraine, to trigger an emotional response and click on a link.

In some cases, a charity may not be fake at all, however scammers can make a passable “lookalike” website to trick users. Because of this, always check the URL and charity name before donating. Be wary if a charity seems to be pressure you into a specific dollar amount, or if the details on how the money will be spent are vague. These may be signs of something nefarious taking place behind the scenes.

Securing Your BusinessIf you own or manage a business, what steps can you take to ensure that you and your employees navigate safely through the holiday season?

As mentioned previously, phishing emails are rampant throughout the holidays. Remind your employees to be extra careful about any emails promoting holiday offers and deals. Remind them of the added risk that comes with using a work computer for non-work-related activities such as online shopping or reading personal emails. This is especially the case for remote workers. Such actions put the security of a company at higher risk, more than the employee may realize.

With high stress and mental fatigue that comes with closing out a work year, it is important that no corners are cut when it comes to security infrastructure. This includes making sure all company software and applications are updated, scanned, and patched. Vulnerability assessments and testing are crucial all the time and should be no different even in the holiday season.

Implementing an Identity and Access Management (IAM) system will also help mitigate the chances of undetected cyber-attacks. It may be hard to keep tabs on all staff at once. During a time that mental fatigue may affect many, IAM systems will help manage your user access ecosystem.

Lastly, it may be very important to have on-call IT Security staff. With holiday breaks or general IT staff on vacation, there may be fewer eyes to attend to all systems and possible anomalies. Therefore, it would be worthwhile to have IT staff on call in the event a security incident occurs.

Moving Forward with Peace of MindWe have learned about many ways scammers can take advantage of the holiday season to deceive their victims. We also considered ways to keep ourselves safe, whether we’re vacationing, online shopping from home, or looking after our company.

Of course, all these tips are not ONLY applicable to this time of year. In fact, they heighten our senses and can help us spot scammers well through the new year and the years to come. Only through learning about the tactic’s scammers use can we truly continue to improve our own personal security.

At Social Engineer LLC, our purpose is to bring education and awareness to all users of technology. For a detailed list of our services and how we can help you achieve your information/cybersecurity goals please visit:

https://www.Social-Engineer.com/Managed-Services/.

Images:
https://www.hippopx.com/en/banking-buy-computer-credit-card-keyboard-macbook-online-shopping-355474
https://unsplash.com/@frantic

View Details

Many people assume that as professional social engineers (SE) we use EVERY method possible to achieve our objective. I have been asked, “If you’re acting like the bad guys, why do you need to have rules?” and “how will it be realistic if you apply ethics in your training?” This raises an important question. Are ethics and social engineering compatible? To answer that, let’s explore a couple of scenarios. First, an engagement with no code of ethics in place. Second, an engagement which implements a code of ethics. This will allow us to determine which will provide the best results. In each scenario we will also see how the person being tested and the person doing the testing are affected.

No Code of EthicsIn our first scenario, let’s pretend a client just hired us to do phishing and vishing to test their corporation’s employees. They have asked us to come up with real life pretexts. They want the testing to be as realistic as possible. We get into our attacker perspective. What would the bad guys do? They would exploit a person’s fear to get them to act in a way they usually would not. We then come up with an extreme fear-based pretext: An email from the boss asking the employee to enter their credentials in a “new HR portal” or else they won’t get paid that month.

Many people work paycheck to paycheck and are facing financial hardship. Consider the single parent depending on that paycheck to pay the rent. They click the link and enter their information, what will they remember from this exercise? How will they feel afterwards? More importantly, what was the lesson learned? It is very likely that upon finding out that they failed this test, the employees will feel resentment towards their company and distrust towards the IT security department.

The exploitation of someone’s visceral fear of not being able to provide for their family is not very effective when it comes to providing a lasting learning experience.

Applying the Code of EthicsIn our second scenario, the idea behind the testing is the same: to execute a realistic phishing and vishing simulated attack and improve the security posture of the corporation. Again, we step into attacker mode. The idea of using a fear-based pretext is the first thing that comes to mind. We then stop and think, how would this make the intended target feel? What would the repercussions be if we threatened a person with losing their job? And would we have provided a lasting learning experience? As we consider these questions, we conclude that we need to think a little harder to come up with pretext ideas that are realistic but ethical.

Applying ethics enables us to be empathic. Being empathic allows us to put ourselves in the shoes of the employees being tested and ask ourselves: how would I feel if I was promised a much-needed bonus only to find out it was just a phishing test? More than likely, we would not think of the lesson to be learned but how we felt deceived.

Using pretexts that don’t take an emotional toll on the person enables us to provide a teachable moment that’s focused on the education we’re providing.

The Social Engineering Code of Ethics Accomplishes Important GoalsThe Social Engineering Code of Ethics accomplishes these three important goals:

  • Promotes professionalism in the industry.
  • Establishes ethics and policies that dictate how to be a professional SE.
  • Provides guidance on how to conduct a social engineering business.

Clients Benefit from the Code of EthicsHaving a code of ethics as our guide benefits our clients and their employees. They have peace of mind knowing that we will not subject their employees to tests that involve emotionally damaging or demoralizing pretexts. The target (employee) also benefits as we provide a realistic and safe learning experience.

Social Engineers Benefit from the Code of EthicsThe SE doing the work also benefits when applying ethics. Shelby Dacko, one of the most experienced members of our vishing team had this to say:

“I’ve applied ethics in various ways on my vishing calls. For example, sometimes we get people on the line who are having a really bad day. On those occasions, I like to focus on just making them feel better. While they’re still my target, the flags become secondary. We are here to make people more secure and feel better for having met us, not tear them down while they’re already down. It makes them feel better and gives them some relief to have someone to talk to. It also benefits me because although my job is to test them, and I must follow through with that, I’m not doing it in a way that is going to affect the person in a negative way. That helps me feel good about the work that I do.”

Ethics Make Us Better ProfessionalsAre ethics and social engineering compatible? We unreservedly say yes! Being ethical makes us better professionals. It is easier to get a compromise or a “click” by using the scariest pretexts. But it takes ingenuity and the use of techniques such as elicitation and rapport building (among others) to extract information and influence people in a way that leaves them feeling better for having met us.

Some may say that the bad actors don’t display empathy, so why should we? The answer is simple: we are not the bad guys. As exhilarating as it may be to have the ability to influence and/or manipulate others, our goal is to train and educate our clients so that they can be safer in their workplace, as well as in their personal lives. An ethical social engineer would never show off their skills at the expense of someone else’s dignity. When we have empathy, we study and impersonate the bad guys, but never become them.

A Code of Ethics Anchored in EmpathyOur code of ethics is anchored in empathy. When we imagine how our target would feel, we can create a true learning experience. If we leave our target extremely upset or disappointed, they will focus on how terrible they feel instead of the lesson we want them to learn. On the other hand, using empathy when planning and executing an adversarial simulation attack ensures that we leave the target with a positive mindset. This results in a more effective testing method and training.

Do you want to make your business more secure? Our managed services identify risk and assess vulnerability within your organization’s human network. For more information on the services we offer, visit our website Social-Engineer.com.

At Social Engineer LLC, our purpose is to bring education and awareness to all users of technology. For a detailed list of our services and how we can help you achieve your information/cybersecurity goals please visit:

https://www.Social-Engineer.com/Managed-Services/

Written by Rosa Rowles

Images
https://www.wired.com/story/how-we-learn-computer-science-ethics/
https://www.tabb.org/code_of_ethics.php

View Details

Do you believe in psychics? Many people turn to psychics and mediums for advice or to communicate with dead loved […]

View Details

A threat actor or “malicious actor” is defined as either a person or a group of people that take part […]

View Details

Employment scams have been around for quite some time. Whether you fell for one or not, you have likely come […]

View Details

When you read this title maybe you think of yourself “I know nothing about computers.” Or, perhaps you think, “I’m […]

View Details

In today’s technologically forward world, online scams have become both common and effective. The Internet Crimes Complaint Center (IC3) states […]

View Details

During a routine visit to the doctor, he asked what I did for a living. I explained that my work […]

View Details

What comes to mind when you hear the word interrogation? Perhaps, the typical movie scene where someone is sitting in […]

View Details

Human beings are social animals. We like to stay connected with friends, family and even workmates via social media. It […]

View Details

When you think about a scam, what comes to mind? Perhaps you think about receiving a poorly drafted email saying […]

View Details

As I enter my fourth year in the social engineering world, I have been reflecting on what I’ve learned so […]

View Details

“Look me in the eyes.” People often use phrases like this to determine if someone is lying. We may think […]

View Details

June is National Internet Safety Month! The Department of Homeland Security in coordination with The National Cybersecurity Alliance created a […]

View Details

Password security is extremely important. No doubt, this is something you have heard before. In fact, it may be something […]

View Details

As a child, I was obsessed with card tricks, sleight of hand, you name it. I enjoyed watching street magicians […]

View Details

Can you think of people that have made a difference in your life? Perhaps your parents or maybe a teacher […]

View Details

What do an ASL interpreter, web developer, professional actor, billing coordinator, and a call center employee all have in common? […]

View Details

Our favorite time of the year is upon us again, tax season. This magical time brings stress and anxiety for […]

View Details

As social engineers, we may wear different hats (sometimes literally) when it comes to getting into character for our pretexts. […]

View Details

As many of you are aware, DEF CON recently announced that they were banning me from their conference. It’s important […]

View Details

At Social-Engineer, LLC (SECOM), we define social engineering as “any act that influences a person to take an action that […]

View Details

Rapport. What is it? It is defined as “A relationship characterized by agreement, mutual understanding, or empathy that makes communication […]

View Details

Imagine this: It’s 9 o’clock at night, the house is quiet, and you’re in bed getting comfortable. Suddenly, you hear […]

View Details

Part of the job of a social engineer is creating a good pretext or a good story, that you tell others to influence them to take a certain action. I have learned that one of the most important aspects of pretexting is impersonation.

Impersonation is acting like or exhibiting the behavior of the person you are pretending to be. Impersonation can come naturally to some, but it did not for me. I have become accustomed to doing impersonations over the phone as part of my job. However, doing in-person impersonation was not something I was familiar with (not to mention not comfortable with). Attending APSE class (Advanced Practical Social Engineering) pushed me to get out of my comfort zone. Part of the homework involved crafting a good pretext and impersonation. I realized that the best way for me to elicit information was to get into character as I was impersonating. This proved to be very effective and made me wonder: could I use the same principles of impersonation to improve certain skills in real life? If so, would this make me inauthentic?

Be Authentic The media is constantly bombarding us with messages like “be authentic,” “be yourself,” and “do what makes you feel good.” These messages may be well intentioned or part of an advertising campaign. The truth is, there are many facets that make up who we are. We are the sum of all our experiences, thoughts, and feelings. The human brain tends to continue to repeat old patterns and avoid anything that seems unfamiliar, which would make us uncomfortable. What if your familiar “authentic self” is a limited version of who you could be?

Authentically Inauthentic You’ve always wanted to be a good public speaker, but you feel that it’s just not who you are. So, you don’t even try. Or perhaps you have tried to do something that is out of your comfort zone, but you end up feeling like a complete fraud. We can reason: if it’s uncomfortable, that must mean it’s not authentic.

It is quite easy to retract and get back to the most comfortable version of ourselves. While we want to feel true to “who we are,” staying within our comfort zone and not testing our capabilities may be doing us a great disservice. Some things feel inauthentic because they may be difficult or uncomfortable. However, the more we do them, the easier it will be and the more authentic it will feel. Using the previous example, if you want to be a great speaker, imagine what a great speaker looks like and how they behave on stage. As you emulate that image, you may feel uncomfortable since it may be something you’re not used to. Being uncomfortable for some time is the price to pay to achieve your goal.

Being Authentic Outside Your Comfort Zone In addition to feeling inauthentic, many people may feel that they lack the ability to be successful, in turn, they feel anxious and insecure. I find it interesting that many successful performers were able to find a way to turn a situation they feared into success. According to Castingfrontier.com, actor Al Pacino said: “My first language was shy. It’s only by having been thrust into the limelight that I have learned to cope with my shyness.”

Granted, being “thrust into the limelight” may be enough to put us off completely. But you may be able to develop the ability to tweak or adjust your behavior in a slight but meaningful way. For example, you may wish to be more outgoing, but your idea of mingling at a party is waving hello from a distant corner. While it may be unnatural for you to approach everyone at the party with jokes and laughs, you could set a goal to approach one person whom you have not met and introduce yourself. Then, next time you find yourself in another gathering, expand the number of people you approach and talk to. Incrementally adopting a desired behavior will help you to feel more comfortable as you reach your goal.

Tap Into the Feeling If the behavior you are trying to impersonate feels inauthentic, tap into the feeling of it. Find an aspect of the behavior that feels more familiar to you. For example, one pretext that I often use at work involves impersonation as an IT Specialist. The idea of pretending to be an IT Specialist makes me uncomfortable, however the feeling of being helpful is something that I’m very familiar with. So I tap into the feeling of “helpfulness” to become the person I’m impersonating. In my experience, once you find a way to connect with the character, the rest somehow unfolds in a way to allow you to gradually become that person.

“Fake It ‘Till You Make IT” Psychologist and bestselling author Amy Cuddy, who will be a speaker at the Human Behavior Conference, says: “fake it till you make it… it may not be you today but eventually it will be you.” By going outside of our comfort zone and being “inauthentic,” you’re testing the extent of your abilities. When you’re testing a different behavior to achieve your outcome and it starts to become difficult, think about what body language expert Mark Bowden said on an episode of The Social-Engineer Podcast: “Am I willing to pay the price? …If you do want to keep paying the price (because you want the goal) keep going.” Think about the outcome and try it out, even if you’re uncomfortable. Think about your goal and ask yourself, is it worth feeling uncomfortable? That will dictate if you want to continue.

Trying inauthentic things to expand your capabilities will not turn you into a different person, but it will help you become a better version of yourself.

Written by Rosa Rowles

Sources

https://www.social-engineer.org/framework/influencing-others/pretexting/

https://www.social-engineer.org/framework/attack-vectors/impersonation/

https://www.social-engineer.org/newsletter/my-experience-in-apse/

https://castingfrontier.com/blog/actors-who-struggle-with-shyness/

https://www.social-engineer.org/podcasts/ep-129-should-you-be-inauthentic-with-mark-bowden/

*Image:

https://www.buzzfeed.com/jamiejones/can-you-spot-the-real-artwork-from-the-fake*

View Details

After a long day, you ask your child or significant other how their day was. Very likely, they will respond with a vague “good.” In another instance, you ask your boss when you’ll be getting promoted, yet he/she dismisses your question. Or you’re a social engineer and need to extract vital information for an in-person adversary simulation. In all the above scenarios, elicitation can play a key role in obtaining information.

Elicitation is not new. Since the beginning of time, people have been using this method to obtain information. For example, concerned parents and nosy neighbors use elicitation. Imposters also use elicitation when attempting to gain access you your personal information. As you can see, elicitation is a two-sided coin; on one hand we can use it to our advantage. On the other hand, we can be targeted by malicious attackers with the same techniques. What are some useful elicitation techniques? And what can we do if we feel we are targets of malicious elicitation?

What is Elicitation? What is elicitation? FBI.Gov describes elicitation as “a technique used to collect information that is not readily available and do so without raising suspicion.” In other words, elicitation is a discrete way to obtain information. It is a conversation with intent. During successful elicitation, the person we’re seeking to obtain information from (or our target) should provide this information casually and willingly. A simple example of elicitation would be planning a surprise party and needing to find out details such as the person’s schedule, wish list, list of friends and favorite foods, without raising suspicion. To obtain this information without raising any flags, it’s important to think of how to start the conversation. What specific items of information need to be obtained? How would you go about obtaining the information in a casual way to not raise any questions? The following are some steps for successful elicitation.

Set Your Goal Set your goal before the conversation takes place. Be specific and write down the items of information you’re seeking to gain from the conversation, as well as the overall goal. It is helpful to start the conversation with something not related to your objective. Start by selecting a topic that interests your target. Next, create a pretext or story that makes sense. And then think about how you will ask the questions, will they be direct or indirect?

In the Advanced Practical Social Engineering Class (APSE), a student was asked to go out and collect personal information from different strangers such as family information, full name, date of birth, and where they lived. On one occasion, the student went to a hardware store and approached a man to ask for advice on which drill to get her husband for their anniversary. In this instance, the student asked the questions indirectly, as part of a casual conversation. On the second occasion, the student’s pretext involved posing as a hotel clerk doing a survey. In this case, the questions were asked directly. Both instances were successful because the goals were preset and the pretext made sense to the targets.

Observation and Research We don’t always know who our target will be, as in the case of a social engineering engagement. Therefore, observing how staff operate and doing research in advance will be necessary to find the best way to start the conversation. Doing research also helps to know which information the target considers sensitive. Keeping this in mind will help us to be tactful as we are trying to elicit information. A brief observation of our targets can help us determine certain aspects of their personality or mood. Are they outgoing or reserved? Are they rushing or do they seem relaxed? Once we have determined this, we can adapt our pace and tone of voice, as well body language, to make our target feel at ease as we start the conversation.

Open the Door Usually, if someone opens the door for you, you feel obliged to open the next door for them. This “quid pro quo” or “this for that” principle can be a very effective elicitation technique. This involves giving information about yourself, business, etc., in hopes that the person will reciprocate. For example, “Our company’s security guards are not very effective, they usually sleep at night. Are yours any better?” By sharing information and showing a certain level of vulnerability, you seem less of a threat to the target. This also helps them feel more comfortable sharing similar information with you.

Active Listening Active listening involves more than just hearing a person speak. Instead of listening with the intent to reply, listen with the intent to understand. If you’re thinking about what you’ll say next, you may miss important details of the conversation. When you’re actively listening, show that you’re trying to understand by asking questions and/or repeating some of the target’s statement. For example, if the target says they’ve working over 50 hours a week on a project, you could say “Wow, you’re working over 50 hours a week!” Validating a person’s feelings will make them feel that they can confide in you and will motivate them to share more information. While you’re listening actively, you can classify the information to see how you can use it.

Plan an Exit If you don’t plan your exit, you may be in an awkward situation when you don’t know when the conversation should end. This may lead you to have to give additional explanations, which may cause your target to start thinking critically and question your conversation. The target should never feel “hacked” in any way. The conversation should end as casually as it was started, and the target should walk away without having “second thoughts” about the conversation.

Protect Yourself from Malicious Elicitation We have considered how to use some elicitation techniques. What if we feel we are being targeted? Giving and obtaining information is part of life, but it is important to identify which information we feel is private and off-limits (whether personal or business). If we feel we are targets of elicitation with a malicious intent, or we’re simply not comfortable sharing certain information, we can deflect the conversation by doing the following:

  • Ignoring any question or statement you think is improper and changing the topic;
  • Deflecting a question with one of your own;
  • Responding with “Why do you ask?”
  • Giving a nondescript answer;
  • Stating that you do not know;
  • Stating that you would have to clear such discussions with your supervisor;
  • Referring then to a business website; or
  • Stating that you cannot discuss the matter.

If you feel you are the target of malicious elicitation at work, it is important to report it to your security department at once. If you want to protect your company from malicious attacks, find out about the services we offer by visiting our website https://www.social-engineer.com/services/.

*Sources

https://www.fbi.gov/file-repository/elicitation-brochure.pdf/view

https://www.social-engineer.org/framework/influencing-others/pretexting/

https://www.social-engineer.com/apse-a-practical-course-in-a-virtual-world/

https://www.social-engineer.org/social-engineering/active-listening-the-secret-to-any-successful-negotiation/

https://www.social-engineer.com/services/

https://humanbehaviorcon.com/training/#saturday

https://humanbehaviorcon.com/*

Image

https://ideas.ted.com/4-tips-for-talking-to-people-you-disagree-with/

View Details

It is Monday morning and 9am has come too early. You did not sleep well; that unfinished client report weighed heavily on your mind. There is still sleep in your eyes as you log on, hoping that morning coffee will kick in soon. You worked through the weekend, there was just no way around it. Even so, you find you have 85 unread emails, the missed messages light on your phone is blinking, and there was more than one note left on your desk. All those messages have one resounding need: they need to be addressed ASAP. You already know you are in for a long day; the stress has already settled on your shoulders.

While we wish that this scenario was only fictional, we know that for many, this is an all too real description of their work life. And while we recognize this is a problem that affects everyone in all professions, this type of burnout is severely affecting the cybersecurity community.

The Statistics of the Burnout Pandemic According to the Chartered Institute of Information Security (CIIS) 2020/21 State of the Profession report, job stress keeps 51% of cybersecurity professionals up at night. Of the hundreds of security professionals surveyed, the majority mentioned that stress and burnout have become a major issue during the COVID-19 pandemic. 47% said that partly this was due to overwork, with most working over 41 hours a week, and some working up to 90. 65% said that the pandemic made security reviews, audits, and overseeing processes more difficult. 66% said that the cancellation of events such as training sessions widened the skills gap.

How bad is burnout in the cybersecurity community? 54% of those interviewed by CIIS admitted that they had either left a job due to overwork or burnout, or have worked with someone who has. While the internal concerns were mounting, there were other things to worry about as well.

The Security Impact of Burnout While a lot of the world came to a halt during the pandemic, cybercriminals did not. In fact, cybercrime was reported as “thriving during the pandemic,” especially driven by a surge in phishing attacks and ransomware. For companies, the average cost of a data breach soared to over $21,000 per incident during the pandemic and 5% of them cost businesses $1 million or more. 85% of successful data breaches involved defrauding humans rather than exploiting flaws in computer code. Schemes tied to phishing attacks comprise 61% of all data breaches.

This thought weighed heavy on the majority of employees across organizations. According to CIIS, 80% said that staff across organizations have been more anxious or stressed during the pandemic. In a recent UK survey, one in five workers report feeling more vulnerable to cybercrime since the start of the COVID-19 pandemic. 35% cite stress or fatigue as the most common factor, followed by 19% who contribute it to lack of skills and training to stay safe from cybercrime while working from home. With this a major concern, it did not help that 57% of cybersecurity professionals said their budgets are rising but not enough to keep up with their organization’s threats and needs.

These numbers and statistics are overwhelming but paint a very real picture of the current state of cybersecurity. So, are you completely lost and hopeless if you are feeling the effects of burnout? No, certainly not. But first it’s important to recognize the symptoms of burnout.

The 5 Stages of Burnout

Burnout is caused by many factors, such as overworking, unclear job expectations, and even workplace dysfunction. Since, unfortunately, these things are often common in the workplace it is imperative that we are able to spot and identify burnout symptoms before they progress.

  1. The Honeymoon Phase When we are assigned a new task, we often start by experiencing a huge surge of job satisfaction, commitment, energy, and creativity. In this first phase of burnout, you can begin to experience stress that is based around your new task.
  2. Onset of Stress The second stage of burnout begins with an awareness that some days are starting to become harder than others. You might find that your optimism is waning, and you notice common stress symptoms that affect you physically, mentally, and emotionally. Common symptoms can include anxiety, inability to focus, fatigue, irritability, and even high blood pressure.
  3. Chronic Stress The third stage of burnout is chronic stress. This is a marked change in your stress levels, going from motivation to experiencing stress on an incredibly frequent basis. This will be a more intense experience than in stage two. Some common symptoms are feeling pressured and out of control, chronic exhaustion, anger or aggressive behavior, and can include physical illness.
  4. Burnout Stage four is burnout itself and where the symptoms become critical. At what point you reach burnout is unique to you. We all have our own individual limits of tolerance, and no two cases are ever the same. You know you’ve reached burnout when trying to act like things are “normal” is often not possible. It will now become too difficult to cope with your feelings. Common symptoms in this stage can include behavioral changes, feeling empty inside, and obsession over problems at work or in life.
  5. Habitual Burnout The fifth and final stage of burnout is habitual burnout. This indicates that the symptoms of burnout, like the ones we discussed in the previous points, are so embedded in your life that things have increased and do not stop. You are more likely to experience mental, physical or emotional problems as opposed to occasionally experiencing stress or burnout. Common symptoms can include chronic sadness, mental fatigue and physical fatigue. Burnout also tends to create or increase feelings of depression.

Take Action The wisest course to prevent burnout is proactively taking action. Whether you are currently experiencing burnout or not, the best thing to do is to take up self-care practices and build your mental resilience. The Mayo Clinic has a list of things they recommend to help you conquer burnout.

  • Evaluate your options – Discuss your concerns and feelings with your supervisor. Work together to change expectations and reach compromises or solutions. Try to set a goal for what must get done and what can wait.
  • Seek support – Reach out to talk to someone – co-workers, friends, loved ones, family members. If you have access to an employee assistance program, take advantage of these services. Virtual or in-person therapists also allow a professional to help you work through burnout.
  • Get exercise and sleep – Regular physical activity can help you deal with stress and take your mind off work, while sleep restores your well-being and helps protect your health. Both are very important to take action against burnout.
  • Mindfulness – Mindfulness is the act of focusing on your breath flow and being aware of what you are feeling at the moment, without judgement. By taking time each day to practice mindfulness, you can help face situations with openness and patience.

Don’t Suffer in Silence There are other things that you can do to help yourself work through and take action against burnout. On the Social-Engineer Podcast, we have a series called the Security Awareness series. In that series, we interview C-level professionals and many have given their advice for conquering burnout. In a recent episode with Ed Skoudis, he mentioned that he personally has rituals that help keep him focused. For instance, every Saturday he calls his mom, eats a good bagel, and goes for a morning walk. While these things may not seem like they are anything big, the little things are often what keeps us focused in the hardest times.

Please note: if you ever feel that the weight of burnout is becoming too much, there are organizational hotlines that are set up to help you in an emergency. If you are in the U.S., sites like mentalhealth.gov have a list of several numbers you can call to immediately speak with someone.

If you are in the UK, please reach out to the NHS Hotlines.

“When you reach the end of your rope, tie a knot in it and hang on.” — Franklin D. Roosevelt

Written by: Amanda Marchuck

*Sources:

https://www.ciisec.org/

https://www.cbsnews.com/news/ransomware-phishing-cybercrime-pandemic/

https://www.infosecurity-magazine.com/news/uk-workers-vulnerable-cybercrime/

https://www.social-engineer.org/social-engineering/the-impact-of-covid-19-on-security/

https://www.mayoclinic.org/healthy-lifestyle/adult-health/in-depth/burnout/art-20046642

https://www.social-engineer.org/podcasts/ep-154-security-awareness-series-whispering-sweet-security-nothings-with-ed-skoudis/*

Images:

https://www.eatthis.com/signs-drinking-too-much-coffee/

https://www.researchgate.net/figure/Simplified-5-stage-model-for-the-development-of-burnout-which-is-most-frequently-used_fig3_346432309

View Details

What do you think are some of the biggest causes for charity? Natural disaster relief, terrorist attack relief, world hunger, health care funding, and suicide prevention are just a few of the biggest subjects for charities. Unfortunately, these are also some of the largest areas for charity fraud. Since the beginning of COVID-19, cybersecurity firm “DomainTools” has flagged more than 100,000 sites with COVID-19-related domains as “high risk” for fraud. Keeping this in mind, it’s important for us to understand what charity fraud is. We also need to know why and how it happens, and how we can avoid and detect fraudulent charities.

Image: Amaya Hadnagy What is Charity Fraud Charity fraud can be described as using deception to receive money from people who believe they are supporting useful charities. An Fbi.gov article states that, “while these scams can happen at any time, they are especially prevalent after high-profile disasters. Criminals often use tragedies to exploit you and others who want to help.” From the eye of an attacker, people are more vulnerable and likely to give money during tragedies and times of crisis.

Scammers in any field love to play with your emotions to get their desired result. This is especially true for charity fraud. Imagine this: You just scrolled past at least 5 posts on Instagram about the terrible fires, floods, and hurricanes happening in areas where you have friends and family. All you can think about are the lives that have been lost and the houses that have been destroyed. The next post you see is an ad that reads, “Disaster relief funding for those in need. Every dollar you donate goes to a family without a home.” Empathy and sadness are very powerful emotions that could easily lead you to donating without checking your sources.

Charity Fraud Scam Vectors and Social Engineering Techniques Scammers use a lot of tactical techniques to deceive and motivate you into donating as well. Some of these include phishing, vishing, social media, and crowdfunding platforms. Let’s look into detail on why these tactics may be used for charity scams.

Phishing Phishing attacks are done over email and are one of the most popular vectors for scammers and cyber criminals. During the 2018 Camp and Woosley fires in California, attackers took the opportunity to target businesses. They would send emails posing as a company’s CEO to employees instructions to buy gift cards to help clients who were fire victims. The scammers used the tactic of urgency and authority over the targeted employee, and since they were posing as CEO’s, employees were more likely to comply without question.

Social Media A statistic from July, 2021 shows that over 4.48 billion people use social media worldwide. Considering how many people from almost every part of the world are using social media, it makes sense why scammers would have so much success in fraudulent charities. For example, there is a popular scam going around on Facebook where “friends” will message you claiming to be raising money for a charity or organization in need because of the COVID-19 pandemic. They’ll try to convince you to donate via link to a faux charity website or through gift cards. Since these messages are coming from supposed friends and familiar profiles, you’re more likely to trust them.

Crowdfunding Platforms Back in 2017, there was a viral story about a homeless veteran who gave all his money to a woman on the side of the road with no gas. Once she got home, her boyfriend posted about the story and started a GoFundMe to raise money for the homeless man. This campaign was so successful it raised over $400,000 and was featured on Good Morning America. Unfortunately, in 2020, the couple pleaded guilty to wire fraud, money laundering, and more. In short, the campaign was a scam. What made this scam successful? First, feeling compassion for the homeless man. Second, trusting in a believable and detailed story. And third, social proof, from the story becoming viral were all keys to this successful scam.

Vishing What about phone scams? I’m sure we’ve all gotten the “we’re calling about your car’s extended warranty” or even “The IRS needs your SSN to confirm your identity.” But what about phone scams involving charities? In March 2021, the FTC ended a vishing scam that stole over $110 million from citizens who thought they were giving to charities. The FTC states that, “Defendants duped Americans into donating tens of millions of dollars to nonprofit organizations that they claimed helped breast cancer patients, the families of children with cancer, homeless veterans, fire victims, and more. – In reality, almost no money went to charitable purposes described to donors.” At least 90% of these calls involved pre-recorded messages. The operators would listen in and select specific audio clips to play in response to people’s questions.

Protect Yourself from Charity Fraud and Give Wisely While this may seem scary or overwhelming to think about, there are ways we can protect ourselves from charity fraud and detect red flags.

Red Flags:

  1. Pressure to donate immediately. Many charity scams will pressure you or use a sense of urgency to get your money as fast as possible with little time to think. A legitimate charity will not pressure you to donate and will welcome whatever donation you choose to make.
  2. Only accepting payment by gift cards, cash, or wire transfer. Scammers love these payment methods because the money can be difficult or even impossible to trace.
  3. Be aware of organizations with copycat/similar names to well-known organizations, especially new organizations that pop up during high-profile disasters.

What You Can Do:

  1. Always do your research and search for reputable organizations. The FTC suggests searching for a charity’s name or a cause you want to support with terms such as “highly rated charity,” “complaints” and “scam.”
  2. Don’t give personal and financial information like your SSN, date of birth, or bank account number to anyone asking for a donation. Scammers use that data to steal your money and identity.
  3. Never click on or open links from people you don’t know. Fraudulent links can steal your information and release malware onto your device.
  4. Use websites like CharityNavigator.org to check the validity and reputation of a charity before donating or giving out any information.

In summary, always check your sources, and do your own research. It’s equally important to never click on unknown links. In addition, don’t send money to any “organization” you don’t know using gift cards or wire transfers. And finally, be sure to check out our numerous blogs and newsletters about scams, online safety, and other topics such as these on social-engineer.org

Sources

https://www.domaintools.com/

https://www.fbi.gov/scams-and-safety/common-scams-and-crimes/charity-and-disaster-fraud

https://www.social-engineer.org/framework/attack-vectors/phishing-attacks-2/

https://www.social-engineer.org/framework/attack-vectors/vishing/

https://www.agari.com/email-security-blog/hostile-landscape-of-email-threats-leverages-california-wildfire-tragedy/

https://www.bbb.org/article/news-releases/22110-bbb-scam-alert-dont-be-fooled-into-thinking-thats-your-friend-on-facebook

https://www.charitynavigator.org/?c_src=WPAIDSEARCH&gclid=EAIaIQobChMIuPP5jo718gIVFtdMAh0gPAVUEAAYASAAEgJOBPD_BwE

View Details

Picture this; you’re sitting in a restaurant with five of your friends. Two of them are Sam and Alex. When Alex’s order comes, it’s wrong. Alex mentions this to Sam but decides to eat the meal anyways, rather than send it back. Sam, however, wants to help. Sam tells the waiter about the mistake and ensures it gets corrected. When Alex asks Sam why he did it, Sam says “I can’t help it, I’m such an ENFJ.”

I don’t know about you, but I’ve heard dozens of conversations and comments like this throughout the years. Maybe you have too, or maybe you have no idea what an “ENFJ” is. (Honestly, I had to google it before writing this article.) What was Sam referring to? He was discussing the famed Myers-Briggs type indicator test. This is by far the most well-known personality test of our day. Based on Carl G. Jung’s theory of psychological types, it aims to break down tendencies in personality and perception. The goal is to better understand how your personality lends itself to different careers, patterns of behavior, and so on. It is one of the many attempts humans have made to better understand ourselves; both how we behave and how we communicate.

An Underpinning of Society This understanding is absolutely worth seeking. Communication, after all, is an underpinning of our society. Almost everything we do, from forming friendships to deciding who leads the country, can be traced back to communication. Why not, then, focus on communication styles, rather than personality tests, when seeking to understand behavior? Of course, behavior is a multi-faceted and extremely in-depth topic that can’t always be dissected cleanly. So, before we dive into the discussion of communication, it’s important that I give a couple of disclaimers.

First, I am not saying that personality tests (both the Myers-Briggs and others) don’t have a place in discussions on behavior. They are certainly interesting to investigate, and I would encourage you to do so for yourself. Second, I am not a psychologist. I have, however, spent years seeking to understand communication, both as an ASL interpreter and as a student of neurolinguistics. With those disclaimers having been proclaimed, let’s look into one of the main communication tools I enjoy.

DiSC My personal favorite communication model is DiSC. I enjoy this model because it identifies communication styles and preferences. I feel that when I look at communication rather than personality, I am able to draw conclusions that are less emotional or judgmental. By taking biases out of the equation, it helps me make clearer connections and communicate with people more effectively. Let’s look at the basics of this model and some ways I’ve made application of it.

The DISC model describes four basic styles of communication: Dominance, Influence, Conscientiousness, and Steadiness. Let’s look at an overview of these categories with definitions from https://www.discprofile.com/:

    • D = Dominance: A person primarily in this DISC quadrant places emphasis on accomplishing results and “seeing the big picture.” They are confident, sometimes blunt, outspoken, and demanding.
    • I= influence: A person in this DISC quadrant places emphasis on influencing or persuading others. They tend to be enthusiastic, optimistic, open, trusting, and energetic.
    • S = Steadiness: A person in this DISC quadrant places emphasis on cooperation, sincerity, loyalty, and dependability. They tend to have calm, deliberate dispositions, and don’t like to be rushed.
    • C = Conscientiousness: A person in this DISC quadrant places emphasis on quality and accuracy, expertise and competency. They enjoy their independence, demand the details, and often fear being wrong.

Communication Types Applied These definitions are great, but how do we apply it in our day-to-day life? How do these styles really affect our mental processes? Well, I am a conscientiousness type. This means that when I have a job assigned to me, my mind goes straight to what I need to get done in order to accomplish the task. I immediately start to analyze the job and make a mental (or physical) list of what I need to do to complete it. Someone who is a steadiness type may have a different initial reaction. Their mind might go to what they can do to lessen the load on others working on the project. Now, this doesn’t mean that I don’t care about others on my team. It also doesn’t mean that a steadiness type doesn’t care about accomplishing the task. It just means that our priorities and first thoughts may be different.

This is how our communication profiles affect us daily. Each of us, depending on our type, have unique responses to how we process information. Let’s look at some examples of this, both in the workplace and in social situations.

In the Workplace DISC profiling has proved immensely useful for me in workplace communication. My boss, Chris Hadnagy, is a D type. He is very direct and doesn’t generally focus on details. Ironically, my communication profile says this is the style I, a C, work the least well with in management. This is due to my need for details and to ensure that I have completed a task correctly.

I remember one occasion where I moderated a panel. After it was over, Chris told me that I did well, and gave an example of something he liked. Later, when we were in a group conversation with a colleague, Chris was discussing DISC with them. He said that normally he would have only given me feedback if I’d had something to improve upon. Normally, he wouldn’t focus on the small details or on reassurance. However, his knowing my communication profile enabled him to realize that I would need some feedback on the assignment. He was correct!

In Social Situations I don’t know about you, but occasionally when I’m in a social setting that isn’t my norm, I will experience some level of social anxiety. This is especially true if it’s a large group of people that I don’t know very well. I’ve found that stepping back and trying to determine people’s preferred communication style helps me get out of my head. This works for two reasons. First, it takes the focus off me. It enables me to turn my attention elsewhere. Second, by attempting to speak to people in the way they prefer, it makes our interactions more meaningful.

Perhaps you’re on the opposite side of the communication spectrum from me. Maybe you’re an I or a D type; someone who is naturally more confident or enthusiastic. In this case, analyzing communication styles will still help you. For example, imagine you’re communicating with an S type. S types do not usually like being rushed and tend to be calm. Someone who is an I may be a little too energetic or enthusiastic for that person. While none of these traits are better or worse than the others, we can adjust to make people more comfortable. If the I type can determine that someone prefers S-style communications, they can perhaps speak a little more calmly. They can ask questions, seeking to show the support and sincerity S-style communicators value.

I would encourage you to investigate DISC a little more and try this out in the coming weeks! See if you can learn to determine people’s preferred communication styles. If you do, be sure to let me know your experiences!

What Makes Humans, Human No matter our preference on how each of us prefers to assess communication and personalities, the effort is worth making. If you have looked into the DISC communication model yourself, please share your experiences! I would love to hear how you have benefited from deepening your understanding of communication styles. No matter the method used, let’s keep digging into what makes humans human, and learn from each other.

Written by Shelby Dacko

*Sources:

https://www.16personalities.com/enfj-personality

https://www.myersbriggs.org/my-mbti-personality-type/mbti-basics/

https://www.myersbriggs.org/my-mbti-personality-type/mbti-basics/c-g-jungs-theory.htm

https://resourcesunlimited.com/new-to-disc-assessments/

https://www.discprofile.com/*

*Image:

https://resourcesunlimited.com/new-to-disc-assessments/*

View Details

As security professionals, we are conditioned by consistent exposure to adversarial simulation training. This immersive form of education allows us to develop and maintain a secure environment outside of the workplace, as well as in it. This begs the question, could a bank teller do the same if given some basic exposure to this training? What about a C-level executive? Approaching the question from a broader perspective, could the average individual identify and protect themselves against an attacker? Expert Chris Hadnagy advises us, “Unless you’re in the security business or law enforcement, you won’t be familiar with every new scam that pops up. But you can still reduce your chances of becoming a victim by understanding more deeply how scammers manipulate people, regardless of their specific scheme.”

Regardless of the attack vector, understanding the attacker’s methods when eliciting information could decrease your chances of becoming a victim. You see, manipulation is just one tool in an attacker’s seemingly endless toolbox. Protecting yourself from each tool can be as simple as owning your role in security, developing a deeper understanding of the existing attack vectors, and learning how to shut down or deter a potential attacker. That is why, for this October’s Cybersecurity Awareness Month, we encourage you to Do Your Part #BeCyberSmart! Because whether you are an average worker, a stay-at-home parent, or a C-level executive, you too have a vital role in ensuring that you, your family, and your job remain secure.

Cybersecurity First at Work

Owning your role in cybersecurity can seem cumbersome when approached by someone outside the security industry. However, this first step simply requires you to identify what information or device within their realm of access needs protection.

The Cybersecurity & Infrastructure Security Agency (CISA) recommends these 5 simple tips to increase your cybersecurity at work:

  • Treat business information as personal information.
  • Don’t make passwords easy to guess.
  • Ensure software and security settings are up to date.
  • Watch what you post on social media; cybercriminals often use them to gather Personal Identifying Information (PII) and corporate information.
  • Remain vigilant. Don’t click on unknown links. Instead, report and delete suspicious emails.

The National Cyber Security Alliance (NCSA) recommends these 8 simple tips for remote workers:

  • Think before clicking.
  • Lock down your login.
  • Connect to a secure network and use a company-issued Virtual Private Network (VPN).
  • Keep your personal and corporate devices on separate Wi-Fi networks.
  • Keep devices with you at all times or stored in a secure location.
  • Limit access to the device you use for work.
  • Use company-approved/vetted devices and applications.
  • Update your software.

Build a Human Firewall Securing your work environment requires you to create what is referred to among security professionals as a human firewall. A human firewall is made up of the defenses the target presents to the attacker during a request for information. In use, a human firewall could be an employee who visited the named organization’s direct website instead of clicking on the link received via email. Or an employee who called their HR Department to verify that an emailed request for sensitive information was legitimate. Furthermore, the key to the human firewall’s effectiveness is the human’s ability to “spread the word” or report on suspicious activity.

The verification process, coupled with reporting, is what makes human firewalls a top defense against attackers. Remember, these requests can appear as emails, phone calls, text messages and even impersonation attempts from what you believe to be a reputable source. It is important to apply proper suspicion and your internal verification process to all attack vectors that malicious actors may use to compromise employees.

It’s no surprise that consistency and practice allow security professionals to react effectively when faced with a malicious actor. So, how do we expose employees to practice without compromising the security of the company we’re aiming to protect? The answer is simple; with simulated attacks and subsequent training. Social-Engineer, LLC saw an almost 350% increase in recognition of phishing emails when using a similar training platform in 2020. It is to these carefully crafted campaigns that Social-Engineer, LLC can attribute their success. These campaigns are heavily reliant on teachable moments designed to build muscle memory in preparation for the real attacks. These managed services coupled with their commitment to “leave them better for having met us”, ensures employees do their part not once but always.

Cybersecurity First at Home

In today’s world, whether you are on the go, at home, or at work, personal devices play a huge role in daily activity. In fact, the IoT market was due to reach 31 billion connected devices in 2020 and is estimated to reach 75 billion IoT devices by 2025.

It speaks to reason that, to #BeCyberSmart at home, we’d need to account for this increase in connectivity by applying basic security practices to all connected devices. Typically, corporate networks are equipped with firewalls, a Chief Security Officer (CSO), and a whole cybersecurity department to keep them safe. It is for this reason that CISA recommends we take a page out of the company playbook. Next time you’re considering home network safety, appoint an in-home Chief Security Officer to monitor security settings on all devices, ensure protective software is up to date, and above all, ensure everyone in the family is connecting carefully.

Know Your Device Accessibility and convenience are at our fingertips with each connected device we add to the home. Unfortunately, with accessibility comes vulnerability. Most consumers don’t realize that your device is connected to millions of other computers once it’s connected to Wi-Fi. Nor that attackers will use an insecure network connection as a means to access your device remotely. Don’t let them; preventing an attacker from access requires researching a device or online product prior to purchase. So, remember, know your device. When investing in a new product to streamline your life, research the product’s security features, recent privacy/security concerns, and reviews of the product prior to purchase. This way, you may reap the benefits of the interconnected world without risking the privacy and security of your home.

Privacy and Security Settings Ensuring the security of your home is no small feat. Start by changing default passwords and the privacy/security settings on all devices.

An ideal time to configure these privacy/security settings on your device is when the device is first turned on. Some smart devices even prompt consumers to configure privacy and security settings when activating a device for the first time. However, if your device doesn’t prompt you or you are altering the settings after the device has been in use, do not skip this. Do not allow the device to configure to a default setting. Instead, ensure you take a moment to configure privacy and security settings to your comfort level. Furthermore, secure your online accounts with long, unique passphrases and a multi-factor authentication system (MFA) wherever applicable. Because whether you are a stay-at-home parent or a college student during the recent COVID-19 pandemic, the responsibility to build a cyber-secure home falls on you.

Cybersecurity Should Never be an Afterthought Social-Engineer, LLC said, “From the top leadership to the newest employee, cybersecurity requires the vigilance of everyone to keep data, customers, and capital safe and secure.” We’ve since learned that accountability is required of all looking to be cybersecure,. whether that be at home or at the office. If you are looking to Do Your Part #BeCyberSmart, start by utilizing Social-Engineer’s free educational resources to keep yourself familiar with the latest security practices. And remember, if you are interested in partnering with Social-Engineer to #BeCyberSmart, please contact Social-Engineer, LLC for a personalized quote. Because it is only by working together that we can truly achieve a cybersecure environment.

Sources

https://www.social-engineer.com/social-engineer-team/christopher-hadnagy/

https://staysafeonline.org/wp-content/uploads/2020/04/Own-Your-Role-in-Cybersecurity_-Start-with-the-Basics-.pdf

https://www.social-engineer.org/framework/attack-vectors/

https://staysafeonline.org/cybersecurity-awareness-month/theme/

https://staysafeonline.org/

https://www.cisa.gov/sites/default/files/publications/NCSAM_WorkSecure_2020.pdf

https://staysafeonline.org/wp-content/uploads/2020/03/NCSA-Remote-Working-Tipsheet.pdf

https://www.social-engineer.org/framework/attack-vectors/phishing-attacks-2/

https://www.social-engineer.org/framework/attack-vectors/vishing/

https://www.social-engineer.org/framework/attack-vectors/smishing/

https://www.social-engineer.org/framework/attack-vectors/impersonation/

https://www.nist.gov/video/what-internet-things-iot-and-how-can-we-secure-it

https://www.prnewswire.com/news-releases/the-world-will-store-200-zettabytes-of-data-by-2025-301072627.html

https://us-cert.cisa.gov/ncas/tips/ST04-003

https://us-cert.cisa.gov/ncas/tips/ST04-006

https://us-cert.cisa.gov/ncas/tips/ST15-002

https://staysafeonline.org/wp-content/uploads/2020/04/IoT-At-Home_-Cyber-Secure-Your-Smart-Home.pdf

https://www.social-engineer.org/

Images

https://staysafeonline.org/cybersecurity-awareness-month/theme/

https://www.peoplesbanknet.com/creating-a-cyber-secure-home/