HomeSecurity4 tips for recognizing a Social Engineering attack

4 tips for recognizing a Social Engineering attack

In general, as humans we want to help our fellow beings. Unfortunately, this very fact is exploited by attacks known as Social Engineering. Scammers who use Social Engineering attacks try to manipulate people to obtain things they want. What does a hacker want on the internet? The two basics: passwords and, more generally, personal information that will help them learn more about their victim.

Social-Engineering

Social engineering is not a simple trick, there is a very well-defined framework for this type of attacks that is extremely detailed and contains specific attack methods. More details about all aspects of social engineering can be found in Chris Hadnagy's book.

Naturally, no one wants to be the victim of a Social engineering attack, which is why it is important that you can recognize the attack while it is still in progress, so that you can respond appropriately.

1. If someone from Technical Support calls you

How many times have you called technical support and been on hold for a long time? How many times has it happened that they called you from technical support to solve a problem you perhaps didn't even know about? The answer is probably: none.

If you receive such a phone call from someone claiming to be technical support, you should immediately think of a huge red flag warning you of a Social engineering attack. The technical support of a company receives many inbound calls and it is almost impossible for it to start looking for problems on its own. Hackers, on the other hand, when they try to obtain information such as passwords or try to get the victim to visit malicious links containing malware, will try to disguise themselves as people you trust.

Request the “technical support” to visit you at your location. Check their history, call them at a number that can be verified. If they are in an office, call them using their internal number.

2. Caution during Emergency Inspections

Social Engineers often disguise themselves as inspectors. They can hold a block, and wear some form. Their goal is usually to gain access to restricted zones, in order to extract information or install software, such as key loggers on computers within the targeted company.

Check with the company's supervisors to see if someone who claims to have come to inspect something is a real person. Call security and do not let them be near any company system.

3. Do not fall into the trap of messages “Act Now” or “Urgent”

One thing that all Social Engineers do, in order to bypass your rational thinking process, is to create a false sense of urgency.

The pressure to act quickly can override your ability to think about what is actually happening. Never make hasty decisions when someone you don't know is pressuring you too much. Tell them that you will get back later because you are leaving now, or that you will call them back when you have verified their story with third parties.

4. Watch out for intimidation tactics such as “Help me or the boss will kill me”

Fear is another emotion – a tool used by Social Engineers and other scammers to take advantage of the situation. They will use fear, whether it is fear that comes from a problem, or the fear of a deadline that is expiring, etc.

Fear, combined with a false sense of urgency, can short-circuit your thinking processes and make you vulnerable to the requests of Social Engineers.

Source: secnews.gr

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS