What it relies on
The fourth point explains why these calls seem real. The details for the story come from public sources: the company's website, employees' social media, and job postings. You can compile a dossier on an organization in one evening.
A classic scenario is a call to tech support from someone claiming to be an employee who has lost access. Persistence and knowledge of a couple of internal details often seem more convincing than any verification procedure.
Why technology can't save you
Every security measure assumes that a legitimate user can get in. Social engineering exploits exactly this path: it doesn't break the lock, but gets the key from the person who has it.
That's the catch: strengthening technical measures helps very little and sometimes makes things worse. The more complicated the procedures, the more often employees look for workarounds, and those workarounds become the entry point.
- Verify through a different channel: call back using a known number, not the one provided.
- Treat urgency as a warning sign: real procedures can withstand a pause.
- Never share codes from messages or your full password with any department.
- Treat a request to keep the conversation secret from colleagues as almost always a sign of an attack.
- Make sure reporting a suspicious call is safe and free of blame.
The last point matters more than technical measures. If an employee is afraid of being punished for a mistake, they'll stay silent, and the organization may not learn about the attack for weeks. A culture of incident reporting protects better than instructions do.
It's also worth remembering that the target isn't always a password. Often, the request is for something small: confirm a colleague's position, give an internal extension, or forward a file. Those small details can be used to build the next, already convincing story.
What does social engineering hack?
What protection works against any story?
Sources
- Social engineering uses urgency, authority, reciprocity, and believable stories assembled from public sources
- verification through an independent channel is considered the primary protective measure
Next in the “Cybercrime” series
2 articles in full on the site, 3 more in the app
