EN
Get the appGet the app
Miqo editors · 2 sources

What it relies on

  • Urgency. There's no time to check: the account will be blocked, access will disappear, and your manager is waiting right now.
  • Authority. The caller says they're from security, management, or a supplier, and you're not expected to argue with them.
  • Reciprocity. It starts with a small favor, followed by a request, and after receiving a favor, it's psychologically harder to refuse.
  • A believable story. The attacker gathers details in advance: colleagues' names, project titles, and recent events.

The fourth point explains why these calls seem real. The details for the story come from public sources: the company's website, employees' social media, and job postings. You can compile a dossier on an organization in one evening.

A classic scenario is a call to tech support from someone claiming to be an employee who has lost access. Persistence and knowledge of a couple of internal details often seem more convincing than any verification procedure.

Why technology can't save you

Every security measure assumes that a legitimate user can get in. Social engineering exploits exactly this path: it doesn't break the lock, but gets the key from the person who has it.

That's the catch: strengthening technical measures helps very little and sometimes makes things worse. The more complicated the procedures, the more often employees look for workarounds, and those workarounds become the entry point.

  • Verify through a different channel: call back using a known number, not the one provided.
  • Treat urgency as a warning sign: real procedures can withstand a pause.
  • Never share codes from messages or your full password with any department.
  • Treat a request to keep the conversation secret from colleagues as almost always a sign of an attack.
  • Make sure reporting a suspicious call is safe and free of blame.

The last point matters more than technical measures. If an employee is afraid of being punished for a mistake, they'll stay silent, and the organization may not learn about the attack for weeks. A culture of incident reporting protects better than instructions do.

It's also worth remembering that the target isn't always a password. Often, the request is for something small: confirm a colleague's position, give an internal extension, or forward a file. Those small details can be used to build the next, already convincing story.

Test yourself1 / 2

What does social engineering hack?

Sources

  1. Social engineering uses urgency, authority, reciprocity, and believable stories assembled from public sources
  2. verification through an independent channel is considered the primary protective measure

Next in the “Cybercrime” series

2 articles in full on the site, 3 more in the app

All articles

3 more articles in this series are in the app

They are under “Crime → Cybercrime”. Free.

Quiz · 12 questionsHow well do you know “Cybercrime”?