Why asking is easier than cracking
Bypassing security directly takes time, equipment, and rare expertise. Bypassing it through a person takes a phone and a believable story. The technique is called social engineering, and it's older than the internet: the same schemes worked when access credentials were kept in paper files rather than an app.
It works not because the people on the other end are stupid. The request hits workplace reflexes: help out, don't slow things down, don't seem like a pain to someone in a hurry. Saying no means a small conflict right now; saying yes takes a second. The weak spot isn't your character, but the situation you're put in.
Amateurs hack systems, professionals hack people.
Kevin Mitnick, the most famous hacker of the 1990s, later described the same thing: he got access more often through conversation than code. Since then, the setting has changed, not the mechanism: instead of a call to reception, there's an email from "support" and a message "from your bank."
What this kind of conversation is made of
Preparation usually takes longer than the conversation itself. A name, job title, who reports to whom, what the company calls its internal systems - all of this is gathered in advance from public sources: social media, email signatures, job postings. Then the attempt follows a familiar pattern, and the moves are almost always in the same order.
- BeforeDetails about the organization and its people are collected from what's already out in the open.
- OpeningThe caller mentions these details and sounds like an insider: a colleague, contractor, or bank employee.
- PressureUrgency appears: access is about to be blocked, it has to be handled now, there's no time to think.
- RequestInstead of a password, they ask for something small: read out a code, tap approve, open a link.
The key move is the last one. They almost never ask directly for your password: they ask you to do something that looks harmless on its own. A code from a message, an "it's me" button in an app, a "check your login" page. You agree to something small, but hand over access to everything.
All versions have one sign in common: they rush you while steering you away from your usual channel - to another messenger, another page, or a conversation right now. Doubt comes a minute after you hang up, and that's normal: the whole calculation was based on speed. Real support will calmly tolerate a pause and your callback.
Why do scammers usually ask for an action, not a password?
What should you do if "support" rushes you on a call?
Sources
- Kevin Mitnick, "The Art of Deception" (2002) - a firsthand breakdown of the techniques. The same sequence of steps is described by phone fraud prevention services and annual data breach investigation reports
Next in the “Social Engineering” series
3 articles in full on the site, 4 more in the app
