What is: Social Engineering
- by mr.p.clarke
- in Security
- on 19 October 2022
Cyber criminals don’t always need to hack a computer. Sometimes it is much easier to hack the person sitting in front of it.
Imagine somebody calls you claiming to be from IT support. They know your name, the company you work for and perhaps even the name of one of your colleagues.
They tell you there is an urgent problem with your Microsoft 365 account and they need you to approve a login request.
Everything sounds perfectly plausible.
There is just one problem.
They aren’t from IT.
This is social engineering.
So, what exactly is social engineering?
Social engineering is the use of psychological manipulation to persuade somebody to reveal information, perform an action or bypass normal security procedures.
Instead of attacking a firewall or trying to break encryption, the attacker targets something much more complicated: people.
Phishing is one of the most common forms of social engineering, but attacks can also happen through telephone calls, text messages, social media, Microsoft Teams, QR codes and even face-to-face conversations.
Why does social engineering work?
Social engineering attacks exploit perfectly normal human behaviour.
Urgency
“Your account will be disabled in 30 minutes.”
Creating urgency gives you less time to stop and think.
Authority
“This is the Managing Director. I need this payment made immediately.”
People are naturally reluctant to challenge somebody who appears to have authority.
Fear
“We’ve detected suspicious activity on your bank account.”
Fear encourages people to react before verifying whether the situation is genuine.
Trust
An attacker may pretend to be a colleague, supplier, customer or member of the IT department.
Curiosity
“Confidential salary information attached.”
Sometimes curiosity alone is enough to persuade somebody to click.
Helpfulness
Most people genuinely want to help somebody who appears to have a problem. Attackers know this and exploit it.
How an attacker prepares
A good social engineering attack may begin long before the victim receives a message or telephone call.
Attackers can collect surprising amounts of information from publicly available sources.
Company websites and social networks can reveal:
- employee names and job titles
- senior managers and directors
- suppliers and business partners
- email address formats
- office locations
- projects and events
- technology used by the organisation
- employees who have recently joined
This information helps an attacker create a believable story.
⚠️ The attacker may know more about you than you expect
If somebody knows your name, company, manager or supplier, that does not automatically prove they are genuine. Much of this information may be publicly available.
Common social engineering attacks
Phishing
Fraudulent emails attempt to persuade you to click a link, open an attachment, reveal information or enter your password.
Fake IT support
An attacker phones claiming to be from IT and asks for passwords, MFA codes, remote access or approval of a login request.
Payment fraud
An attacker impersonates a director or supplier and requests an urgent payment or change of bank details.
Smishing
Fraudulent text messages claim to come from banks, delivery companies or other trusted organisations.
QR phishing
A QR code sends you to a malicious website designed to steal login credentials or payment information.
Teams and messaging scams
Attackers may use collaboration platforms or compromised accounts to impersonate colleagues and request information or action.
The fake IT support call
This is a particularly effective attack because IT departments genuinely do contact users about technical problems.
The caller might say:
The authentication request may actually be the attacker attempting to sign into your account.
If you approve it, you may have just given them access.
Business email compromise
Another particularly dangerous form of social engineering involves impersonating senior staff or suppliers.
Imagine receiving this email:
I’m in a meeting and can’t talk. I need an urgent payment made to a new supplier before 3pm. Can you deal with this for me?
I’ll send the bank details shortly.
The message creates urgency while using the apparent authority of a senior member of staff.
In other cases, attackers compromise a genuine supplier’s mailbox and wait for a real invoice conversation. They then send replacement bank details at exactly the right moment.
Because the email comes from a genuine account and forms part of a genuine conversation, these attacks can be extremely convincing.
What about AI and deepfakes?
Artificial intelligence has made it easier for criminals to create convincing messages quickly and in almost any language.
AI can also help attackers imitate writing styles, create convincing fake identities and produce realistic audio or video.
This means a telephone call that appears to sound like somebody you know should not automatically override normal security procedures.
Urgency should never bypass verification
An unusual payment request should still be independently verified even if the email, message or voice sounds completely genuine.
How can you protect yourself?
Slow things down
Social engineers often manufacture urgency specifically to stop you thinking clearly.
Verify independently
Contact the person or organisation using a telephone number, website or communication method you already trust.
Never share passwords
A legitimate IT support technician should not need to know your Microsoft 365 password.
Don’t approve unexpected MFA requests
If you aren’t actively signing in, reject the request and report it.
Verify financial changes
Changes to supplier bank details should always be confirmed independently using an established contact method.
Report suspicious behaviour
Tell your IT department or IT support provider. Somebody else in the organisation may be receiving the same attack.
Social engineering and phishing
Phishing is one of the most common social engineering techniques, but the two terms are not quite the same thing.
Social engineering describes the manipulation of people.
Phishing is one method attackers use to perform that manipulation.
A phishing email may therefore be just one part of a much larger attack involving research, impersonation, telephone calls and fake websites.
If you’d like to understand phishing in more detail, take a look at my What is Phishing? guide.
Technology can help
Security technology can make social engineering attacks significantly more difficult.
Useful protections include:
- multi-factor authentication
- phishing-resistant authentication and passkeys
- Microsoft 365 email security
- Conditional Access
- endpoint protection
- web filtering
- email impersonation protection
- security awareness training
But technology cannot completely remove the human element.
People still need to feel comfortable questioning something that doesn’t look right.
Stop. Check. Verify.
If somebody unexpectedly asks for a password, MFA approval, payment, confidential information or access to a computer, there is nothing wrong with checking who they really are.
A genuine colleague or IT technician won’t mind you verifying their identity. A social engineer probably will.
