Introduction to Security ยท 1.1

๐ŸŽญ Social Engineering

How attackers hack people, not computersโฑ ~2 min

๐ŸŽฃSocial engineering is fishing for people

A hacker breaking through a firewall is like trying to pick a bank vault lock โ€” it's hard and takes skill. Social engineering is like walking up to the vault manager, showing a fake badge, and asking them to open it for you. It's almost always easier to trick a person than to break a technical system. This is why social engineering is the #1 attack vector โ€” it bypasses all your security software instantly.

Why It Works โ€” The Six Triggers

  • โ€ขAuthority โ€” 'I'm from IT, I need your password to fix your account.' We're trained to comply with authority figures.
  • โ€ขUrgency โ€” 'Your account will be deleted in 10 minutes!' Panic kills critical thinking.
  • โ€ขFear โ€” 'You've been hacked โ€” act now or lose everything.' Fear stops rational evaluation.
  • โ€ขTrust โ€” 'Your friend Sarah sent this link.' We lower our guard with familiar names.
  • โ€ขGreed โ€” 'You've won a $500 gift card โ€” click to claim!' The reward seems worth the risk.
  • โ€ขHelpfulness โ€” 'Can you hold the door? My hands are full.' We're socially conditioned to help.

Common Social Engineering Attack Types

AttackWhat It IsExample Red Flag
PhishingFraudulent email pretending to be a trusted sourceSender is support@paypa1.com (note the '1')
VishingPhone call scam โ€” voice phishing'This is the IRS โ€” you owe $2,400, pay now or be arrested'
SmishingSMS text message phishingText: 'Your package is delayed โ€” verify here: bit.ly/abc'
PretextingFabricated story/scenario to extract informationCaller claims to be an auditor needing your employee ID
TailgatingFollowing an authorized person through a secured doorPerson behind you says 'forgot my badge, can you hold it?'
Shoulder SurfingWatching someone type a PIN or passwordPerson standing too close at an ATM or coffee shop
HoaxFalse alarming message spread to cause panic or bad decisions'Forward this warning to everyone โ€” new virus destroying phones!'
TyposquattingFake website with a URL similar to a real onearnazon.com instead of amazon.com

Practice: Spot the Red Flags

๐Ÿ” Scenario: Email received at school

FROM: helpdesk@school-it-support.net SUBJECT: URGENT: Your school account will be suspended in 2 hours! Dear Student, Our security system detected unusual activity on your account. You MUST verify your identity immediately or your account will be permanently suspended. Click here to verify: school-verify-now.com. This is your FINAL WARNING.

Red flags
  • โš‘Sender domain is 'school-it-support.net' โ€” not your school's real domain
  • โš‘Extreme urgency: '2 hours' and 'FINAL WARNING' โ€” designed to prevent you from thinking carefully
  • โš‘The link goes to 'school-verify-now.com' โ€” not your school's actual website
  • โš‘Threatening language: 'permanently suspended' creates fear
  • โš‘Legitimate IT departments never ask for password verification this way
โ˜… FactAccording to Verizon's 2024 Data Breach Investigations Report, 68% of all data breaches involved a human element โ€” social engineering, errors, or misuse of access. Technical hacking was the minority. Attackers figured out long ago that it's easier to manipulate people than to crack systems.
๐Ÿ”’ SecurityImpact on victims goes beyond stolen passwords: identity theft can take years to resolve; companies lose millions (the 2023 MGM Resorts breach started with a 10-minute phone call to the help desk โ€” cost: $100 million in damages). For individuals, a single successful phishing attack can result in financial loss, account takeovers across multiple services (password reuse), and reputational damage.
๐Ÿง Quick Checkfirst try = +5 XP

An employee receives a call: 'Hi, this is David from corporate IT. We've detected ransomware spreading on your network right now. I need your login credentials immediately to lock down your account before it's compromised. Every second counts.' Which social engineering triggers is the attacker using?

โญ 0 XP๐Ÿ”ฅ 0 days