Skip to content

Security

Social Engineering: People as security vulnerabilities

How cybercriminals manipulate people to steal money or data.

Ein maskierter Betrüger angelt mit einer Rute verschiedene Gegenstände wie Sparschwein, Kreditkarte und Software-Lizenz von einem Laptop. Illustriert umfassende Cyberkriminalität und Datendiebstahl.

13 February 2020

At first glance, the Ministry of Foreign Affairs in Austria, the automotive supplier Gedia and the Court of Appeal in Berlin don’t have muich in common – except that they’ve all recently been the victims of cyber-attacks. At the Potsdam City Council, it was only in January that hackers managed to slip through a security loophole in the server software. And yet, cyber criminals are increasingly exploiting human failings in their attempts to get their hands on security data. Security expert Tobias Kippert from TÜViT explains which manipulation methods are particularly widespread and how companies can heighten the awareness of their staff of what has become known as social engineering.

 

The Human Factor

#explore: How big a risk do people, as a security vulnerability, pose as possible gateways for cyber criminals, in comparison to other risk factors?
Tobias Kippert: No matter how effective the technical protection we can now provide, at the end of the day, it’s down to people to use these technical measures properly - and, of course, people don’t just deal in zeroes and ones. What’s more, people can themselves be the target of an attack. There’s ample statistical evidence to show that this is one of the biggest weaknesses in security management.

What is social engineering?
Social engineering refers to manipulation by social means. Human characteristics like curiosity, helpfulness and trust are exploited to lure staff into disclosing information which can then be used in attacks. For instance, you might take an apparently harmless call from someone who wants to speak to your colleague. And you might easily then be tempted just to say that the person concerned is currently off sick or away on holiday for a couple of weeks. But as well as breaching data protection law, you might also be disclosing important information to a potential burglar.

Ein maskierter Betrüger angelt mit einer Rute verschiedene Gegenstände wie Sparschwein, Kreditkarte und Software-Lizenz von einem Laptop. Illustriert umfassende Cyberkriminalität und Datendiebstahl.
© AdobeStock

Social Engineering Tactics

So, social engineering is not just a purely digital phenomenon?
In fact, attackers often operate in the real world as well, although they usually make use of digital tools. For example, they search social networks such as LinkedIn or Xing to find colleagues of a target and use them to gather information. Most of us are also familiar with phishing emails that try to trick people into clicking on a link. Doing so can allow criminals to steal login credentials for services such as Amazon or online banking. The number of these attacks—and especially their sophistication—has increased significantly. Attackers have become more professional and are much more selective in choosing their victims. For example, expensive products may be offered on online marketplaces with the goal of convincing buyers to make an advance payment to a bank account outside the EU. The product, of course, is never delivered. Attackers are investing more time in these targeted scams. They build a convincing story and establish trust through email communication to persuade victims to transfer money. Recently, there has also been a growing number of cases involving Emotet malware. Criminals send fake emails that appear to come from real friends or colleagues. Opening an infected attachment or clicking a malicious link can then cause serious damage.

Eine Person mit schwarzer Augenmaske hält eine Angelrute, an deren Haken ein geöffneter gelber Briefumschlag hängt. Stellt E-Mail-Phishing und betrügerische Nachrichten dar.
© AdobeStock
Eine Hand hält eine Angelrute, die eine rote Kreditkarte von einem Computer-Monitor angelt. Veranschaulicht Cyberkriminalität und das Abfischen von Zahlungsdaten.
© AdobeStock

Building Human Defenses

What are some other common manipulation techniques in the workplace?

One of the most well-known examples is CEO fraud, also known as business email compromise (BEC). In this scam, the accounting department receives what appears to be an email from the CEO or another senior executive instructing them to transfer a large sum of money to an overseas account. Once again, the human factor plays a key role. Employees may hesitate to question the request because they fear embarrassing themselves by challenging senior management, so they proceed with the transfer. Another classic tactic involves a USB flash drive that has been deliberately infected with malware and then "accidentally" left in an office hallway or company restroom. Most people who find it plug it into their computer—either out of curiosity or in an attempt to identify the owner. In many organizations, employees still lack awareness of this risk, and companies often do not have proper procedures in place to ensure that a found USB drive is safely examined or the incident is reported before anyone attempts to use it.

How can employees be made more aware of social engineering?

Ideally, awareness initiatives should be supported by senior management and carried out by an information security officer. In general, companies should communicate openly about the potential risks and use real-world examples to demonstrate possible attack scenarios. This can have a lasting impact, especially on employees with less technical experience. The goal is not to make employees suspicious of every email they receive, but to help them develop an awareness of potential attacks. Companies should also establish clear reporting procedures so employees know exactly whom to contact if they receive a suspicious email or encounter another possible security incident. Most importantly, employees must not be afraid to report a potential security issue. They should never feel that they are causing trouble or worry that reporting a false alarm could have negative consequences for them. To achieve this, organizations need to foster a culture of openness and make it clear that every report is valuable and appreciated, regardless of whether the suspicion ultimately proves to be justified. In addition, companies should build a foundation of trust, since some reports may involve sensitive information and require confidential handling.

In addition to conducting penetration tests, you also assess how vulnerable companies are to social engineering. How do you go about this?

Our experts carry out simulated attacks such as making fake phone calls, sending phishing emails, and distributing malicious USB flash drives. To evaluate employees' security awareness, they do not limit themselves to attack methods that are currently popular among cybercriminals and therefore widely recognized. Instead, they also use less familiar techniques to assess how people respond. Afterwards, the experts analyze the results—for example, how often employees clicked on a phishing link or plugged a found USB drive into their computer. The evaluation is, of course, anonymized. The goal is not to single out or blame individuals, but to raise security awareness across the entire organization.

Ein Laptop mit gelbem Hintergrund, aus dessen Bildschirm ein Angelhaken ein Login-Formular mit Benutzerprofil herausangelt. Symbolisiert Phishing-Angriffe, die versuchen, Anmeldedaten zu stehlen.
© AdobeStock

Creating a Security Culture

How aware are German companies today of the risks posed by social engineering?

Until a few years ago, data protection was something that many people associated only with the workplace, and even there it often received limited attention. Today, however, data protection and cybersecurity have become part of everyday life. Whether it is signing a privacy consent form at the doctor's office or protecting the data on our smartphones, people encounter these issues regularly. This has had a positive effect: people increasingly bring this awareness from their private lives into the workplace. Fortunately, during security audits today, it is rare to find the infamous sticky note with a password attached underneath a keyboard. Overall, awareness of social engineering has improved, but there is still considerable room for progress. Most companies continue to invest primarily in technical safeguards such as IT security systems and access controls. While these measures are essential, they represent only one pillar of security and cannot replace employees' security awareness. Appointing a dedicated information security officer has been shown to have a positive impact. Such a person can promote security through onboarding sessions for new employees and ongoing awareness initiatives within the organization. As a result, what may initially seem like an inconvenient security requirement gradually becomes a normal part of everyday work. At the same time, employees should understand that major security incidents can, in some cases, put jobs at risk. Everyone has a responsibility to help protect their workplace—that is a crucial message.

#explore - The Online Magazine by TÜV NORD

This is an article from #explore. #explore is a digital journey of discovery into a world that is rapidly changing. Increasing connectivity, innovative technologies, and all-encompassing digitalization are creating new things and turning the familiar upside down. However, this also brings dangers and risks: #explore shows a safe path through the connected world.