Rachel Tobac. (2022 Sep 28). Inside the mind of an ethical hacker

Social engineering is a fraudulent technique used by attackers to manipulate individuals into divulging confidential information, providing access to systems, or performing actions that compromise security. These psychological techniques can be used via telephone in frauds and scams or via computer in cybercrimes​. Scammers are highly skilled and cunning when capitalizing on deeply ingrained motivations, as described in Influence.

  • Requests for sensitive information via email, phone, or social media
  • Urgency or fear tactics to prompt immediate action
  • Unsolicited messages with suspicious links or attachments
  • Attempts by strangers to establish trust or familiarity to gain access
  • Inconsistencies in communication or requests
  • Verify requests for sensitive information through alternate channels
  • Avoid clicking on links or downloading attachments from unknown sources
  • Take security awareness training to understand new attack methods and techniques. 
  • Use strong, unique passwords and enable multi-factor authentication. See Cybercrime Prevention.
  • Keep software and security patches up to date. 

If you suspect you've fallen victim to a social engineering attack, take immediate action:

  • Report the incident to local law enforcement, your security team or IT department.  See How to Report Fraud
  • Change compromised passwords and revoke access as necessary
  • Inform relevant parties, such as financial institutions, the attacker pretended to represent. 
  • Conduct a security review to identify vulnerabilities and implement additional safeguards. 

References: