Emily Williams is not a real person. She was created by two hackers as a social media profile. The photo was real and belonged to a woman who had given her consent to the two hackers who wanted to use her.
The hackers used two fake profiles, one on Facebook and one on LinkedIn, to send greeting cards to civil servants in the department where Emily Williams supposedly worked .
As reported by ZDNet , the two researchers used hacked greeting cards to gain administrator privileges, obtain passwords, install applications, and steal files from their victims' computers.
Miss Emily Williamswas the front person for security researchers Aamir Lakhani and Joseph Muniz. They even convinced a security team member to click on a javascript hidden in a birthday card.
Lakhani presented the attack at the RSA Europe 2013 conference, on Wednesday, October 30 .
Mr. Lakhani presented the research findings at RSA Europe 2013 in a talk titled “Social Media Deception.” The results concerned Project “Emily Williams,” a penetration test on a U.S. government agency conducted in late 2012.
Lakhani declined to identify the US government agency that was breached in Ms Williams' name. But he told the RSA conference audience that his team's attack was on a highly secure service that specializes in cyberattacks and privacy protection. In the past, those who had tried had only had success with zero-day attacks.
Download PDF: RSA presentation slides for Social Media Deception
Mr. Lakhani explained that his team had tried the same attack with fake male profiles, but they were not successful.

