Hacking Humans: Defending Against Social Engineering Attacks

If you’re like most organizations, you have invested heavily in protecting your organization from cyber threats. Gartner projects that the spending on cybersecurity will exceed 124 Billion dollars in 2019 alone. Gartner projects that the spending on cybersecurity will exceed 124 Billion dollars in 2019 alone. This market has attracted a constantly growing list of new technology offerings from cyber defense companies that leverage AI and machine learning that seek to identify and defend against modern security threats. The marketplace is flooded with these offerings to solve the increasingly complex and rapidly adapting capabilities of cybercriminals. But if we measure the success of the effort and money that industries have spent on securing data, would we consider them successful? Just the Facts…

  • Per Gemalto’s Breach Level Index, roughly 74 records are compromised a second based on reported breached records since 2013
  • According to RBS, over 5 billion records were reported compromised in 2018 alone.
  • In 2018, 12 breaches exposed over 100 million records versus 13 in 2017

It seems we are spending money and allocating budgets, yet billions of records are still being compromised each year despite our security efforts. One might ask, what are we missing? Here are two more facts that may help us get to the bottom of this conundrum:

  • According to a 2018 Verizon study, Social engineering attacks account for 93% of successful breaches
  • According to RBS, in 2018 the threat vector that exposed the most records (over 2 billion) was human error by internal resources

As the data above shows, our people represent the biggest risk to the security of our organizations. It is not that having advanced defenses isn’t necessary, as this is really just the cost of doing business online – but it’s not quite enough. Businesses should also have a security strategy that deeply connects to and trains our people to defend against social engineering attacks as well. Let’s take a minute to review what social engineering is and why it is so effective.

Social Engineering

Social engineering can be defined as the art of convincing or manipulating someone (hacking human psychology) to gain unauthorized access to buildings, systems or data. Defeating a cyber technology control like a firewall or even cracking a strong password can be extraordinarily difficult – but convincing an employee to share information like a password or to click on a link or visit a website is much easier.

How Social Engineering Works

The reason why social engineering attacks are so successful is that human psychology wires us in ways that make us vulnerable. Three common psychological traits that help social engineers succeed are:

  1. Our desire to be helpful
  2. Our tendency to trust people we don’t know
  3. Our fear of getting into trouble

If you pair these traits with something called Pretexting, you create a context that can be very persuasive. Pretexting is the act of creating and using an invented/made-up scenario to engage a target victim in a way that increases the likelihood they will perform actions or divulge information that would be unlikely under normal circumstances. Social Engineers are masterful at creating a pretext that relies on the 6 principles of influence established by psychologist Dr. Robert Cialdini. Cialdini’s research describes six principles that are highly effective at persuading people:

  1. Reciprocity – The requester gives or promises something of value in return. An example could be the Nigerian prince scheme, where the victim is promised a great sum of money for a small fee.
  2. Commitment and consistency – In this case, the target has publicly endorsed the requester in some way. For these attacks, the social engineer may reach out initially and gather public information from a victim and then call back and ask for progressively more sensitive data since the victim has already provided information in the past.
  3. Social proof – The requester convinces the target that complying with the request is the popular thing to do. In this type of attack, an email could be utilized to communicate that 8 out of 10 market leaders know this secret and you can too with a comprised attachment that you need to open.
  4. Authority – The requester establishes a position of authority over their target. This is a popular avenue of attack; an attacker will send an email as a boss or senior executive requesting information.
  5. Liking – The requester establishes rapport with their target. The attacker may call and illicit sympathy or empathy using pretext to convince the victim to provide confidential or privileged information.
  6. Scarcity – The requester is making a limited time offer or offering something in short supply. In this type of attack, there could be an email stating that there are a limited number of prizes that require that the victim click on a compromised web link that infects their system.

Social engineers spend a great deal of time researching your company and your employees through their social media profiles on Linkedin, Facebook, and other popular platforms. By gathering this data they can create a more persuasive pretext and attack vectors, or styles of attack.

Common Social Engineering Attack Vectors

There are 4 primary vectors that Social engineers use to attack their victims:

  1. Phishing – This is the most popular vector of attack, with 98% of successful breaches coming through email. Phishing is the use of email to pretend to be a legitimate organization or person that attempts to fraudulently obtain private information.
  2. Vishing – Also known as voice phishing, is the criminal practice of using the telephone system to convince a victim to provide access to personal or financial information.
  3. Smishing – This vector utilizes SMS text messages to convince the victim to take an action that compromises their information or device. A common attack is an SMS message that claims to be from your bank but needs to confirm your credit card information to re-activate it.
  4. Impersonation – This vector involves the attacker pretending to be someone else with the goal of gaining physical access to a target location or system.

The Human Firewall, your first line of defense

Considering the success of the social engineering vector and the fact that our human psychology is working against us, it may feel like defeating social engineering is an almost impossible task. Thankfully it is not. There are 3 key steps that an organization can take to defend against these attacks that have proven to be successful.

  1. Implement Security Awareness Training for EVERYONE in the organization and market it heavily. It is essential that every person in your organization realize that they are a key piece in defending your business and sensitive and privileged information. Comprehensive security awareness training:
    • Is based on real threats they are likely to see
    • Contains simulated attacks are implemented to test retention and adherence
    • Has consistent testing and messaging that are provided on a regular basis that outlines additional types of attack your industry is seeing
    • Test employees for retention to ensure that key learning objectives are effective
    • Occurs on a regular basis to ensure it stays top of mind
  2. Implement a Security-aware culture. This requires that the highest levels of the organization push and enforce the need for individual security accountability. This can be done by:
    • Adding measurable objectives to yearly performance reviews
    • Ensuring policies that address security are in the employee handbook and that they are reviewed at regular intervals
    • Implementing a reward system (gamification) for being security evangelists across the organization
  3. Implement a random Social Engineering Penetration Test at least once a year. It’s optimistic to believe that our employees will always act in a way that is consistent with our policies and processes, but it is important to verify in practice and can act as a litmus test for how effective, or ineffective, steps 1 and 2 have been on your company culture.

Social Engineering continues to be one of the most successful tools in the arsenals of cybercriminals. When you are devising your defensive strategy ensure that you do not miss the opportunity to build out the defenses of your own employees because the attackers will not miss the opportunity to find and take advantage of weaknesses. Contact us to learn more about Primacy's cybersecurity services.