Social engineering attacks are everywhere.
They are one of the most common
types of attacks because they are simple and effective, and technology alone cannot
stop them.
Social engineering is the art of human manipulation. Attackers trick you into doing
something you should not do, such as opening an infected email attachment,
clicking on a malicious link, sharing your password, or exposing sensitive
information. Because these attacks can take any form, including phone calls, text
messages, emails, social media, or even in person, you need to be on alert. Let’s
look at two examples of a social engineering attack.
You receive a phone call from someone claiming to be from the government. They
inform you that your taxes are overdue and that you will be fined or arrested if you
do not pay them right away. They pressure you to pay over the phone with a credit
card, gift card, or wire transfer, warning you that if you don’t pay, you could go to
jail. The call is not really from the government, but instead from an attacker
attempting to trick you into giving them money. Attacks like these are generic; the
cyber attacker does not know who will fall victim. All they know is that the more
people they call, the more people they can potentially victimize.
Cyber attackers can also specifically target people and create more customized
attacks by researching their intended victims. For example, you receive an email
that appears to be from your supervisor. The email is short and urgent. It says that
law enforcement is conducting a secret investigation of our organization and that
people may have to go to jail. The email then states that you will receive a phone
call in 15 minutes from our legal team and that you are to answer any questions
they ask. However, the email is not really from your supervisor. It’s a fake. The
person who calls you 15 minutes later is not really from our legal team, but the
same cyber attacker pretending to be a lawyer. They are simply attempting to get
you to give up as much sensitive information as possible.
So how can you protect yourself from social engineering attacks? Spot them before
they happen. Some of the most common clues include someone:
Creating a tremendous sense of urgency, often through fear, intimidation, a crisis,
or an important deadline. They are trying to rush you into making a mistake.
Pressuring you to bypass or ignore our security procedures or policies. Sometimes
the easiest way for a cyber attacker to get around our security is to ask you to help
them.
Asking you for information they should not have access to, such as your password.
An email or message from a friend or coworker that you know, but the message
does not sound like them, perhaps the wording is odd or the signature is wrong.
Playing on your sense of curiosity or promoting something too good to be true. No,
you did not actually win the lottery.
If you feel you are under such an attack, ignore the message or hang up the phone
and report the incident right away. We are here to help you.