Category
Security Culture
Topic
Social Engineering & Human Hacking
Audience
Organisations & employees
Reading time
approx. 6 minutes

Social Engineering is not a new phenomenon. Yet it has never been more relevant or dangerous. Whilst firewalls, antivirus software and password managers are constantly improving, people remain the biggest vulnerability. Social Engineering exploits precisely that: our psychology. It’s not about technical exploits, but about emotional tricks. And it works better than ever. 

What is Social Engineering?

Social Engineering refers to methods whereby attackers attempt to manipulate people in a targeted manner, for example to gain access to IT systems, steal data or swindle money. This can happen via Phishing emails, fake phone calls (also known as voice phishing) or face-to-face conversations (also known as creating a pretext). The technique is often simple, but psychologically sophisticated.

“In many cases, the attackers’ motto is: ‘Boldness wins!’ And that’s exactly how it is.” 

Simple attack methods

Tailgating

Many attackers gain access to the company premises after following employees as they take a walk during their lunch break.

When large crowds enter a building at the same time, it is unlikely that an employee would close the door behind them and expect the person behind them to open it again with their keycard.

People tend not to want to stand out in a negative way. So, in most cases, the door is held open for almost anyone and everyone.

Consequently, an attacker may well have complete access to internal data. Unlocked computers, letters on desks, discarded documents, files and much more. If an ‘employee’ is already inside the building, there is a significant level of trust in that person.

Social Engineering im Büroumfeld

Pretexting

A very underhand but also highly effective method is to single out what is arguably the ‘weakest’ link in the chain. In most cases, attackers therefore target young and/or new employees, who are often still unsure in their roles and keen to avoid making any mistakes.

It is therefore common for attackers to send an email to new employees very early in the day, purporting to be from their supposed line manager. In this message, employees are urgently asked to upload document X, password X or vouchers to a fake website, or to send them to the attacker by other means.

For many people, even a trick that seems so trivial is enough, when in doubt, to gain access to valuable data or money.

Social Engineering per Telefon

Dumpster diving

Probably the most unhygienic form of Social Engineering is what is known as ‘dumpster diving’. In this method, attackers search through rubbish bins – which may be located outside company premises – or generally discarded information and data to obtain sensitive or useful details.

It can be just as effective for attackers to buy up old company equipment in order to recover files that may have been deleted. For example, there have been cases where local authorities sold their IT systems, after which the data could be accessed using data recovery tools.

Recommendation: Given the ever-evolving attack vectors in cyber security – and particularly in the field of Social Engineering – it is essential to provide ongoing training for employees, raise awareness through live hacking demonstrations, and also undergo regular physical Pentests.

This is the only way to back up theoretical training with practical results. Theory merely creates a false sense of security. With the help of a physical Pentest, you have tangible evidence and can encourage employees to be even more vigilant. Ultimately, this makes it more difficult for attackers. 

How Mint Secure supports you in this

Technology alone does not protect against Social Engineering; what is crucial is a security culture that is actively practised within the organisation. We support you in this with the following services:

🎭

Live Hacking & Awareness

We demonstrate to your team live how Social Engineering attacks unfold, thereby fostering lasting security awareness.

🚪

Physical Penetration Testing

We conduct real-world tests of access controls, tailgating protection and physical security measures at your sites.

🎣

Phishing Simulations

We simulate Phishing and pretexting attacks to realistically test your employees’ ability to respond.

Ready to get started? We offer a free initial consultation. Get in touch now.

Conclusion

Whether it’s tailgating, pretexting or dumpster diving: Social Engineering attackers deliberately exploit human psychology rather than technical vulnerabilities. This is precisely why purely technical security controls such as firewalls or password managers are not enough.

It is only the combination of continuous training, live hacking awareness sessions and regular physical Pentests that makes it noticeably more difficult for attackers.

Mint Secure supports you in building a resilient security culture within your organisation. Get in touch with us.