Aaron Hayden is an information systems analyst at CliftonLarsonAllen, a large public accounting firm. He is also an “ethical” hacker, one of the organization’s 40. And they have a 100% success rate in hacking any company except banks.
Various businesses hire the company to hack their information systems. An internal auditor at each company will know about the upcoming attack, but no other employee will know until the hack is done and the results are presented.
In an era of heightened privacy and security concerns, CliftonLarsonAllen has conducted over 4,000 penetration tests across a variety of industries. As Aaron said, if a hacker is really good at phishing, which is the art of tricking unsuspecting people into easily gaining access to their credentials, then they will be 100% successful. Hayden recently fooled a company executive by sending an email purporting to be from the company's finance manager, and after opening it, he easily took control of his computer.
Once a hacker takes control of a computer, they can easily guess the identity of the person being attacked. If they are the administrator of the PC, Hayden can easily install software and read the database passwords as well as passwords from other computers.
Another secret: Once he takes control of the computer, Hayden can send a fake announcement supposedly from HR saying that there is a change in the company's health insurance and employees need to fill out a new form with their information and at the end they will receive a gift card from Starbucks .The card of course doesn't work but the hacker has taken control.
Guessing passwords is one of the easiest ways for someone to initially break into a network. Believe it or not, if it's August 2015, someone might have a password from August 2015. So everyone should be using complex passwords.
Hacking techniques work very well in the healthcare sector for several reasons, the hacker says. Employees are easily fooled and need more training. There are too many passwords to manage, and employees (especially doctors) often get bored of changing passwords
Hackers also take their time by slowly pulling small pieces of data and encrypting them so they cannot be detected. Over time, the hacker can amass a large amount of data.
Hayden suggests that employers properly train all employees to become more vigilant with their network security.

